[RHEL 8] System crashed at m/slub.c:380 which is related to falcon_lsm_serviceable

https://access.redhat.com/solutions/7130042

Solution Unverified - Updated August 27 2025 at 2:19 AM - English Environment

Red Hat Enterprise Linux 8.10

Issue

System crashed at m/slub.c:380 which is related to falcon_lsm_serviceable

Raw

[ 2729.120419] kernel BUG at mm/slub.c:380! [ 2729.134209] Hardware name: Microsoft Corporation Virtual Machine/Virtual Machine, BIOS Hyper-V UEFI Release v4.1 08/23/2024 [ 2729.141466] RIP: 0010:set_freepointer.part.57+0x0/0x10 [ 2729.144819] Code: 83 ef 70 e9 a2 5e fa ff 66 90 0f 1f 44 00 00 41 54 55 53 48 8b 06 48 85 c0 0f 85 a6 8b 00 00 5b 5d 41 5c c3 cc cc cc cc 66 90 <0f> 0b 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 53 48 89 fb e8 37 [ 2729.156668] RSP: 0018:ff2084271ea53a58 EFLAGS: 00010246 [ 2729.160552] RAX: ff12c11aeb2804e0 RBX: ff12c11aeb2804e0 RCX: ff12c11aeb2804f0 [ 2729.165214] RDX: 000000000002f504 RSI: 0000000000000000 RDI: ff12c03a00004700 [ 2729.169863] RBP: ff8e3f3a47aca000 R08: 0000000080000000 R09: ff2084271ea53b9e [ 2729.174489] R10: ffffffffc0cb5628 R11: ff12c03a10caa920 R12: ff12c03a00004700 [ 2729.179144] R13: ff12c11aeb2804e0 R14: ffffffffc0c17548 R15: ff12c03a0e946b10 [ 2729.184102] FS: 0000000000000000(0000) GS:ff12c0b1d8880000(0000) knlGS:0000000000000000 [ 2729.189748] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 2729.193307] CR2: 00007ffff7196974 CR3: 000000ca09610003 CR4: 0000000000371ee0 [ 2729.197817] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 2729.202416] DR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400 [ 2729.207072] Call Trace: [ 2729.208711] ? __die_body+0x1a/0x60 [ 2729.210992] ? die+0x2a/0x50 [ 2729.212949] ? do_trap+0xe7/0x110 [ 2729.215154] ? print_track+0x20/0x20 [ 2729.217587] ? do_invalid_op+0x36/0x40 [ 2729.220125] ? print_track+0x20/0x20 [ 2729.222543] ? invalid_op+0x14/0x20 [ 2729.224825] ? cshook_security_ptrace_access_check+0x140d8/0x1be60 [falcon_lsm_serviceable] [ 2729.230264] ? print_track+0x20/0x20 [ 2729.232563] kfree+0x238/0x250 [ 2729.234604] cshook_security_ptrace_access_check+0x140d8/0x1be60 [falcon_lsm_serviceable] [ 2729.239978] cshook_systemcalltable_pre_compat_sys_ioctl+0xa6da/0x22030 [falcon_lsm_serviceable] [ 2729.245369] cshook_systemcalltable_pre_compat_sys_ioctl+0xaa3e/0x22030 [falcon_lsm_serviceable] [ 2729.251501] _ZdlPvmSt11align_val_t+0x34621/0x8f320 [falcon_lsm_serviceable] [ 2729.256251] cshook_security_inode_free_security+0x146dc/0x17450 [falcon_lsm_serviceable] [ 2729.261497] ? cshook_security_inode_free_security+0x14521/0x17450 [falcon_lsm_serviceable] [ 2729.266851] cshook_security_inode_free_security+0x130d8/0x17450 [falcon_lsm_serviceable] [ 2729.272144] _ZdlPvmSt11align_val_t+0x78674/0x8f320 [falcon_lsm_serviceable] [ 2729.276739] _ZdlPvmSt11align_val_t+0x790ab/0x8f320 [falcon_lsm_serviceable] [ 2729.281737] _ZdlPvmSt11align_val_t+0x792a7/0x8f320 [falcon_lsm_serviceable] [ 2729.286720] cshook_systemcalltable_pre_compat_sys_ioctl+0x11bd0/0x22030 [falcon_lsm_serviceable] [ 2729.292476] ? cshook_systemcalltable_pre_compat_sys_ioctl+0x7949/0x22030 [falcon_lsm_serviceable] [ 2729.298177] ? kmem_cache_free+0x2d6/0x300 [ 2729.300922] _ZdlPvmSt11align_val_t+0x7583e/0x8f320 [falcon_lsm_serviceable] [ 2729.305410] ? cshook_security_ptrace_access_check+0x143d0/0x1be60 [falcon_lsm_serviceable] [ 2729.310750] _ZdlPvmSt11align_val_t+0x758d7/0x8f320 [falcon_lsm_serviceable] [ 2729.315221] cshook_network_ops_inet6_sockraw_release+0x173a9/0x20e30 [falcon_lsm_serviceable] [ 2729.320917] ? cshook_network_ops_inet6_sockraw_release+0x17390/0x20e30 [falcon_lsm_serviceable] [ 2729.326614] cshook_security_ptrace_access_check+0x14400/0x1be60 [falcon_lsm_serviceable] [ 2729.331957] kthread+0x134/0x150 [ 2729.334127] ? set_kthread_struct+0x50/0x50 [ 2729.336997] ret_from_fork+0x35/0x40 [ 2729.339376] Modules linked in: … [ 2729.380794] —[ end trace fa225db7ecbeeb10 ]— [ 2729.383855] RIP: 0010:set_freepointer.part.57+0x0/0x10 [ 2729.387298] Code: 83 ef 70 e9 a2 5e fa ff 66 90 0f 1f 44 00 00 41 54 55 53 48 8b 06 48 85 c0 0f 85 a6 8b 00 00 5b 5d 41 5c c3 cc cc cc cc 66 90 <0f> 0b 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 53 48 89 fb e8 37 [ 2729.399314] RSP: 0018:ff2084271ea53a58 EFLAGS: 00010246 [ 2729.402724] RAX: ff12c11aeb2804e0 RBX: ff12c11aeb2804e0 RCX: ff12c11aeb2804f0 [ 2729.407400] RDX: 000000000002f504 RSI: 0000000000000000 RDI: ff12c03a00004700 [ 2729.412126] RBP: ff8e3f3a47aca000 R08: 0000000080000000 R09: ff2084271ea53b9e [ 2729.416693] R10: ffffffffc0cb5628 R11: ff12c03a10caa920 R12: ff12c03a00004700 [ 2729.421241] R13: ff12c11aeb2804e0 R14: ffffffffc0c17548 R15: ff12c03a0e946b10 [ 2729.425801] FS: 0000000000000000(0000) GS:ff12c0b1d8880000(0000) knlGS:0000000000000000 [ 2729.431064] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 2729.434873] CR2: 00007ffff7196974 CR3: 000000ca09610003 CR4: 0000000000371ee0 [ 2729.439638] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 2729.444359] DR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400 [ 2729.448933] Kernel panic - not syncing: Fatal exception [ 2729.453629] Kernel Offset: 0x2f800000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff)

Resolution

Since falcon_lsm_serviceable is a 3rd party module, we are unable to continue. Please engage with the module vendor to debug further for root cause analysis.

Root Cause

The kernel hit a deliberate BUG() at mm/slub.c:380, in SLUB’s set_freepointer(). The faulting instruction is UD2 (invalid opcode). This was triggered on the free path (kfree) invoked from cshook_security_ptrace_access_check() within the falcon_lsm_serviceable module’s call chain.

Updated: