This is a new bug first seen with the 570.124.04
Production Branch driver release.
I’ve about 30 instances over the past few days,.
Mar 02 16:47:17 kernel: ==================================================================
Mar 02 16:47:17 kernel: BUG: KFENCE: use-after-free read in _nv000177kms+0x439/0x2a10 [nvidia_modeset]
Mar 02 16:47:17 kernel: Use-after-free read at 0x00000000e7c09e3f (in kfence-#113):
Mar 02 16:47:17 kernel: _nv000177kms+0x439/0x2a10 [nvidia_modeset]
Mar 02 16:47:17 kernel: _nv002879kms+0x663/0x9c0 [nvidia_modeset]
Mar 02 16:47:17 kernel: _nv000392kms+0x1e1/0x400 [nvidia_modeset]
Mar 02 16:47:17 kernel: _nv002878kms+0xf1a/0x11e0 [nvidia_modeset]
Mar 02 16:47:17 kernel: _nv002988kms+0x79c/0xd30 [nvidia_modeset]
Mar 02 16:47:17 kernel: nvKmsIoctl+0xf7/0x270 [nvidia_modeset]
Mar 02 16:47:17 kernel: nvkms_ioctl_from_kapi_try_pmlock+0x64/0xb0 [nvidia_modeset]
Mar 02 16:47:17 kernel: _nv000023kms+0x56b/0xbc0 [nvidia_modeset]
Mar 02 16:47:17 kernel: nv_drm_atomic_apply_modeset_config+0x4bc/0x810 [nvidia_drm]
Mar 02 16:47:17 kernel: nv_drm_atomic_commit+0x18f/0x490 [nvidia_drm]
Mar 02 16:47:17 kernel: drm_mode_atomic_ioctl+0xa69/0xcb0
Mar 02 16:47:17 kernel: drm_ioctl_kernel+0xad/0x100
Mar 02 16:47:17 kernel: drm_ioctl+0x277/0x4e0
Mar 02 16:47:17 kernel: __x64_sys_ioctl+0x94/0xc0
Mar 02 16:47:17 kernel: do_syscall_64+0x82/0x190
Mar 02 16:47:17 kernel: entry_SYSCALL_64_after_hwframe+0x76/0x7e
Mar 02 16:47:17 kernel:
Mar 02 16:47:17 kernel: kfence-#113: 0x000000003756a051-0x00000000be2c3ddd, size=328, cache=kmalloc-512
Mar 02 16:47:17 kernel: allocated by task 1220 on cpu 16 at 16213.163360s (0.425901s ago):
Mar 02 16:47:17 kernel: nvkms_alloc+0x50/0xa0 [nvidia_modeset]
Mar 02 16:47:17 kernel: _nv003020kms+0x22/0x40 [nvidia_modeset]
Mar 02 16:47:17 kernel: _nv002842kms+0x266/0x740 [nvidia_modeset]
Mar 02 16:47:17 kernel: _nv000719kms+0x40/0x60 [nvidia_modeset]
Mar 02 16:47:17 kernel: nvKmsIoctl+0xf7/0x270 [nvidia_modeset]
Mar 02 16:47:17 kernel: nvkms_ioctl_from_kapi+0x73/0xe0 [nvidia_modeset]
Mar 02 16:47:17 kernel: _nv000096kms+0x19d/0x240 [nvidia_modeset]
Mar 02 16:47:17 kernel: nv_drm_internal_framebuffer_create+0x270/0x400 [nvidia_drm]
Mar 02 16:47:17 kernel: nv_drm_framebuffer_create+0x99/0xc0 [nvidia_drm]
Mar 02 16:47:17 kernel: drm_internal_framebuffer_create+0x3e2/0x570
Mar 02 16:47:17 kernel: drm_mode_addfb2+0x42/0xf0
Mar 02 16:47:17 kernel: drm_ioctl_kernel+0xad/0x100
Mar 02 16:47:17 kernel: drm_ioctl+0x277/0x4e0
Mar 02 16:47:17 kernel: __x64_sys_ioctl+0x94/0xc0
Mar 02 16:47:17 kernel: do_syscall_64+0x82/0x190
Mar 02 16:47:17 kernel: entry_SYSCALL_64_after_hwframe+0x76/0x7e
Mar 02 16:47:17 kernel:
Mar 02 16:47:17 kernel: freed by task 1220 on cpu 14 at 16213.185042s (0.404316s ago):
Mar 02 16:47:17 kernel: _nv000801kms+0x49/0x60 [nvidia_modeset]
Mar 02 16:47:17 kernel: nvKmsIoctl+0xf7/0x270 [nvidia_modeset]
Mar 02 16:47:17 kernel: nvkms_ioctl_from_kapi+0x73/0xe0 [nvidia_modeset]
Mar 02 16:47:17 kernel: _nv000110kms+0x4b/0x60 [nvidia_modeset]
Mar 02 16:47:17 kernel: nv_drm_framebuffer_destroy+0x3b/0x50 [nvidia_drm]
Mar 02 16:47:17 kernel: drm_mode_closefb_ioctl+0x6b/0x90
Mar 02 16:47:17 kernel: drm_ioctl_kernel+0xad/0x100
Mar 02 16:47:17 kernel: drm_ioctl+0x277/0x4e0
Mar 02 16:47:17 kernel: __x64_sys_ioctl+0x94/0xc0
Mar 02 16:47:17 kernel: do_syscall_64+0x82/0x190
Mar 02 16:47:17 kernel: entry_SYSCALL_64_after_hwframe+0x76/0x7e
Mar 02 16:47:17 kernel:
Mar 02 16:47:17 kernel: CPU: 4 UID: 1000 PID: 1250 Comm: KMS thread Tainted: P OE 6.13.5-1-arch1 #1 d667fe2c15e9cb1c797b8fe1d4e1b79a4d106a8e
Mar 02 16:47:17 kernel: Tainted: [P]=PROPRIETARY_MODULE, [O]=OOT_MODULE, [E]=UNSIGNED_MODULE
Mar 02 16:47:17 kernel: Hardware name: Micro-Star International Co., Ltd. MS-7D31/MPG Z690 EDGE WIFI DDR4 (MS-7D31), BIOS 1.J0 08/13/2024
Mar 02 16:47:17 kernel: ==================================================================
Please find attached bug report:
nvidia-bug-report.log (15.7 MB)