kernel Panic with RIP up_write+0x11/0x20 (Doc ID 2273063.1)

Last updated on JULY 14, 2017

Applies to:

Linux OS - Version Oracle Linux 6.0 and later
Information in this document applies to any platform.

Symptoms

A server crashed unexpectedly. The following call trace was found in a core dump (vmcore from the system):

$ CRASH vmcore
kernel version = 2.6.32-573.el6.x86_64.x86_64
arch = x86_64
Starting: crash64 /share/linuxrpm/vmlinux_repo/64/2.6.32-573.el6.x86_64/vmlinux vmcore
...
...
KERNEL: /share/linuxrpm/vmlinux_repo/64/2.6.32-573.el6.x86_64/vmlinux
DUMPFILE: vmcore [PARTIAL DUMP]
CPUS: 40
DATE: Mon May 22 09:50:04 2017
UPTIME: 289 days, 01:17:02
LOAD AVERAGE: 4.82, 7.70, 7.66
TASKS: 2008
NODENAME: cnsz081585
RELEASE: 2.6.32-573.el6.x86_64
VERSION: #1 SMP Thu Jul 23 03:43:06 PDT 2015
MACHINE: x86_64 (2297 Mhz)
MEMORY: 255.9 GB
PANIC: "BUG: unable to handle kernel NULL pointer dereference at 00000000000003d0"
PID: 33341
COMMAND: "cgclassify"
TASK: ffff88400400e040 [THREAD_INFO: ffff8837dc68c000]
CPU: 6
STATE: TASK_RUNNING (PANIC)

crash64> bt
PID: 33341 TASK: ffff88400400e040 CPU: 6 COMMAND: "cgclassify"
#0 [ffff8837dc68f9a0] machine_kexec at ffffffff8103d1ab
#1 [ffff8837dc68fa00] crash_kexec at ffffffff810cc4f2
#2 [ffff8837dc68fad0] oops_end at ffffffff8153c840
#3 [ffff8837dc68fb00] no_context at ffffffff8104e8cb
#4 [ffff8837dc68fb50] __bad_area_nosemaphore at ffffffff8104eb55
#5 [ffff8837dc68fba0] bad_area at ffffffff8104ec7e
#6 [ffff8837dc68fbd0] __do_page_fault at ffffffff8104f483
#7 [ffff8837dc68fcf0] do_page_fault at ffffffff8153e78e
#8 [ffff8837dc68fd20] page_fault at ffffffff8153bb35
[exception RIP: up_write+17]
RIP: ffffffff810a6b31 RSP: ffff8837dc68fdd8 RFLAGS: 00010202
RAX: 00000000000003d0 RBX: ffff88401a8df000 RCX: 0000000000000034
RDX: 00000000ffffffff RSI: ffff8809d5163520 RDI: 00000000000003d0
RBP: ffff8837dc68fdd8 R8: 0000000000000000 R9: 3f00000000000000
R10: f800000000000000 R11: f000000000000000 R12: ffff8809d5163520
R13: 0000000000008180 R14: 0000000000000000 R15: ffff8809d93fe500
ORIG_RAX: ffffffffffffffff CS: 0010 SS: 0018
#9 [ffff8837dc68fde0] attach_task_by_pid at ffffffff810d5432
#10 [ffff8837dc68fe30] cgroup_tasks_write at ffffffff810d5543
#11 [ffff8837dc68fe40] cgroup_file_write at ffffffff810d124a
#12 [ffff8837dc68fef0] vfs_write at ffffffff81191ad8
#13 [ffff8837dc68ff30] sys_write at ffffffff81192611
#14 [ffff8837dc68ff80] system_call_fastpath at ffffffff8100b0d2
RIP: 0000003cd4adb6d0 RSP: 00007ffdf08eb0c0 RFLAGS: 00010206
RAX: 0000000000000001 RBX: ffffffff8100b0d2 RCX: 00007f6cbff7e005
RDX: 0000000000000005 RSI: 00007f6cbff7e000 RDI: 0000000000000003
RBP: 00007f6cbff7e000 R8: 00000000ffffffff R9: 0000000000000000
R10: 00000000ffffffff R11: 0000000000000246 R12: 0000000000000005
R13: 0000000001411d80 R14: 0000000000000005 R15: 0000000001411d80
ORIG_RAX: 0000000000000001 CS: 0033 SS: 002b

crash64> dmesg
...
...
BUG: unable to handle kernel NULL pointer dereference at 00000000000003d0
IP: [<ffffffff810a6b31>] up_write+0x11/0x20
PGD 9dcaac067 PUD 3d51289067 PMD 0
Oops: 0002 [#1] SMP
last sysfs file: /sys/devices/system/cpu/online
CPU 6
Modules linked in: joydev nfs lockd fscache auth_rpcgss nfs_acl sunrpc bridge ip_vs libcrc32c iptable_filter ip_tables nfnetlink_queue nfnetlink_log nfnetlink bluetooth rfkill 8021q garp stp llc cpufreq_ondemand freq_table pcc_cpufreq bonding ipv6 i40evf(U) ipmi_devintf sg microcode serio_raw iTCO_wdt iTCO_vendor_support power_meter acpi_ipmi ipmi_si ipmi_msghandler hpilo hpwdt igb i2c_algo_bit i40e(U) configfs ptp pps_core sb_edac edac_core i2c_i801 i2c_core lpc_ich mfd_core ioatdma dca shpchp ext4 jbd2 mbcache sd_mod crc_t10dif xhci_hcd hpsa wmi dm_mirror dm_region_hash dm_log dm_mod [last unloaded: scsi_wait_scan]

Pid: 33341, comm: cgclassify Not tainted 2.6.32-573.el6.x86_64 #1 HP ProLiant DL380 Gen9/ProLiant DL380 Gen9
RIP: 0010:[<ffffffff810a6b31>] [<ffffffff810a6b31>] up_write+0x11/0x20
RSP: 0018:ffff8837dc68fdd8 EFLAGS: 00010202
RAX: 00000000000003d0 RBX: ffff88401a8df000 RCX: 0000000000000034
RDX: 00000000ffffffff RSI: ffff8809d5163520 RDI: 00000000000003d0
RBP: ffff8837dc68fdd8 R08: 0000000000000000 R09: 3f00000000000000
R10: f800000000000000 R11: f000000000000000 R12: ffff8809d5163520
R13: 0000000000008180 R14: 0000000000000000 R15: ffff8809d93fe500
FS: 00007f6cbff6fb20(0000) GS:ffff8801968c0000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00000000000003d0 CR3: 00000009d1b6d000 CR4: 00000000001407e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400
Process cgclassify (pid: 33341, threadinfo ffff8837dc68c000, task ffff88400400e040)
Stack:
ffff8837dc68fe28 ffffffff810d5432 ffff8837dc68fe68 00007f6cfffffffd
<d> ffff8837dc68fe38 ffffffff81ab6c60 ffff88401a8df000 00007f6cbff7e000
<d> ffff8837dc68fe68 0000000000001000 ffff8837dc68fe38 ffffffff810d5543
Call Trace:
[<ffffffff810d5432>] attach_task_by_pid+0xa2/0x160
[<ffffffff810d5543>] cgroup_tasks_write+0x13/0x20
[<ffffffff810d124a>] cgroup_file_write+0x2ba/0x320
[<ffffffff81159775>] ? do_mmap_pgoff+0x335/0x380
[<ffffffff81191ad8>] vfs_write+0xb8/0x1a0
[<ffffffff81192fc6>] ? fget_light_pos+0x16/0x50
[<ffffffff81192611>] sys_write+0x51/0xb0
[<ffffffff8100b0d2>] system_call_fastpath+0x16/0x1b
Code: c1 10 79 05 e8 a1 67 1f 00 c9 c3 66 66 66 66 66 66 2e 0f 1f 84 00 00 00 00 00 55 48 89 e5 0f 1f 44 00 00 ba ff ff ff ff 48 89 f8 <f0> 48 0f c1 10 74 05 e8 73 67 1f 00 c9 c3 90 55 48 89 e5 0f 1f
RIP [<ffffffff810a6b31>] up_write+0x11/0x20
RSP <ffff8837dc68fdd8>
CR2: 00000000000003d0
crash64>

 

 

 

Changes

 

Cause

Sign In with your My Oracle Support account

Don't have a My Oracle Support account? Click to get started

My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms