Info

Permalink
Function
vmw_user_surface_base_release
First occurrence
2022-04-29
Last occurrence
2022-09-24
State
NEW
Components
kernel
Quality
-27

Graphs

Statistics

Operating system Count
Fedora 36 2,557
Fedora 37 43
Fedora 38 18
Fedora 34 1
Architecture Count
x86_64 2,619
Related packages Count
kernel-core 25
 0:6.2.15-300.fc38 17
 0:5.17.5-300.fc36 7
 0:6.2.13-300.fc38 1

Packages names with count less than the total count of reports are most probably not the cause of the problem.

History

Daily:

Weekly:

Monthly:

No reports in the last 20 days.

No reports in the last 20 weeks.

Report backtrace


Complete report #734595
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x7e
2
vmw_user_surface_base_release
vmwgfx 0x7e
3
vmw_user_surface_base_release
vmwgfx 0x7e
4
vmw_user_surface_base_release
vmwgfx 0x7e
5
vmw_user_surface_base_release
vmwgfx 0x7e
6
vmw_user_surface_base_release
vmwgfx 0x7e
7
drm_ioctl_kernel
vmlinux 0xc6
8
drm_ioctl_kernel
vmlinux 0xc6
9
drm_ioctl_kernel
vmlinux 0xc6
10
drm_ioctl_kernel
vmlinux 0xc6
11
drm_ioctl_kernel
vmlinux 0xc6
12
drm_ioctl_kernel
vmlinux 0xc6
13
drm_ioctl_kernel
vmlinux 0xc6
14
? drm_ioctl_kernel
vmlinux 0xc6
15
? drm_ioctl_kernel
vmlinux 0xc6
16
drm_ioctl_kernel
vmlinux 0xc6
WARNING: CPU: 0 PID: 5193 at lib/refcount.c:28 refcount_warn_saturate+0xba/0x110
Modules linked in: uinput isofs snd_seq_dummy snd_hrtimer nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set nf_tables rfkill nfnetlink qrtr sunrpc snd_intel8x0 snd_ac97_codec ac97_bus snd_seq snd_seq_device intel_rapl_msr binfmt_misc intel_rapl_common snd_pcm kvm_amd snd_timer ccp snd kvm soundcore irqbypass pcspkr joydev i2c_piix4 loop zram crct10dif_pclmul crc32_pclmul crc32c_intel polyval_clmulni polyval_generic ghash_clmulni_intel vmwgfx sha512_ssse3 e1000 drm_ttm_helper ttm vboxguest(OE) video wmi serio_raw ata_generic pata_acpi ip6_tables ip_tables fuse
CPU: 0 PID: 5193 Comm: pingsender Tainted: G           OE      6.2.15-300.fc38.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:refcount_warn_saturate+0xba/0x110
Code: 01 01 e8 d9 d9 92 ff 0f 0b e9 92 df 79 00 80 3d 03 a3 ae 01 00 75 85 48 c7 c7 90 a7 8d 84 c6 05 f3 a2 ae 01 01 e8 b6 d9 92 ff <0f> 0b e9 6f df 79 00 80 3d e1 a2 ae 01 00 0f 85 5e ff ff ff 48 c7
RSP: 0018:ffffa2ab462dbd00 EFLAGS: 00010286
RAX: 0000000000000000 RBX: ffffa2ab462dbd28 RCX: 0000000000000000
RDX: 0000000000000002 RSI: 0000000000000027 RDI: 00000000ffffffff
RBP: ffff9510c3a20008 R08: 0000000000000000 R09: ffffa2ab462dbb90
R10: 0000000000000003 R11: ffffffff851447c8 R12: ffff95109c0bd060
R13: ffff951074c40000 R14: ffff95105e6336d0 R15: dead000000000100
FS:  0000000000000000(0000) GS:ffff9510f9800000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fff0808bbd9 CR3: 000000001e7be000 CR4: 00000000000506f0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x7e/0x90 [vmwgfx]
 ttm_prime_refcount_release+0x3d/0x60 [vmwgfx]
 ttm_release_base+0x85/0xd0 [vmwgfx]
 ttm_ref_object_release+0xb6/0xd0 [vmwgfx]
 ttm_object_file_release+0x39/0x90 [vmwgfx]
 vmw_postclose+0x15/0x20 [vmwgfx]
 drm_file_free.part.0+0x207/0x250
 drm_release+0x64/0xd0
 __fput+0x91/0x250
 task_work_run+0x59/0x90
 exit_to_user_mode_prepare+0x1de/0x1f0
 syscall_exit_to_user_mode+0x17/0x40
 do_syscall_64+0x68/0x90
 ? switch_fpu_return+0x5b/0xe0
 ? exit_to_user_mode_prepare+0x13a/0x1f0
 entry_SYSCALL_64_after_hwframe+0x72/0xdc
RIP: 0033:0x7f74037563b0
Code: Unable to access opcode bytes at 0x7f7403756386.
RSP: 002b:00007fff0808b7d0 EFLAGS: 00000200 ORIG_RAX: 000000000000003b
RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000000
R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
 </TASK>
Complete report #731741
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x7e
2
vmw_user_surface_base_release
vmwgfx 0x7e
3
vmw_user_surface_base_release
vmwgfx 0x7e
4
vmw_user_surface_base_release
vmwgfx 0x7e
5
vmw_user_surface_base_release
vmwgfx 0x7e
6
vmw_user_surface_base_release
vmwgfx 0x7e
7
? vmw_user_surface_base_release
vmwgfx 0x7e
8
vmw_user_surface_base_release
vmwgfx 0x7e
9
? vmw_user_surface_base_release
vmwgfx 0x7e
10
drm_ioctl_kernel
vmlinux 0xc6
11
drm_ioctl_kernel
vmlinux 0xc6
12
? vmw_user_surface_base_release
vmwgfx 0x7e
13
? drm_ioctl_kernel
vmlinux 0xc6
14
vmw_user_surface_base_release
vmwgfx 0x7e
15
drm_ioctl_kernel
vmlinux 0xc6
16
drm_ioctl_kernel
vmlinux 0xc6
17
? drm_ioctl_kernel
vmlinux 0xc6
18
? drm_ioctl_kernel
vmlinux 0xc6
19
drm_ioctl_kernel
vmlinux 0xc6
WARNING: CPU: 0 PID: 2910 at drivers/gpu/drm/vmwgfx/vmwgfx_cmdbuf.c:414 vmw_cmdbuf_ctx_process+0x229/0x260 [vmwgfx]
Modules linked in: uinput ntfs3 isofs snd_seq_dummy snd_hrtimer nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc binfmt_misc snd_intel8x0 snd_ac97_codec ses enclosure scsi_transport_sas ac97_bus snd_seq snd_seq_device snd_pcm intel_rapl_msr intel_rapl_common kvm_amd ccp snd_timer kvm snd soundcore irqbypass i2c_piix4 uas usb_storage pcspkr joydev loop zram crct10dif_pclmul crc32_pclmul crc32c_intel polyval_clmulni polyval_generic vmwgfx drm_ttm_helper ghash_clmulni_intel e1000 ttm sha512_ssse3 vboxguest(OE) video wmi serio_raw ata_generic pata_acpi ip6_tables ip_tables fuse
CPU: 0 PID: 2910 Comm: vlc.bin Tainted: G           OE      6.2.15-300.fc38.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:vmw_cmdbuf_ctx_process+0x229/0x260 [vmwgfx]
Code: 03 83 03 01 48 83 c4 28 5b 5d 41 5c 41 5d 41 5e 41 5f e9 aa 99 bb f0 48 c7 c7 88 40 3e c0 c6 05 a7 94 03 00 01 e8 d7 93 d4 ef <0f> 0b 4c 89 e7 e8 6d fb ff ff e9 a5 fe ff ff 48 c7 c7 64 0d 3e c0
RSP: 0018:ffffb85f05a6fa20 EFLAGS: 00010282
RAX: 0000000000000000 RBX: 0000000000000002 RCX: 0000000000000000
RDX: 0000000000000003 RSI: 0000000000000027 RDI: 00000000ffffffff
RBP: ffff91a974d45400 R08: 0000000000000000 R09: ffffb85f05a6f8b0
R10: 0000000000000003 R11: ffffffffb21447c8 R12: ffff91a943347600
R13: ffff91a943347618 R14: ffff91a988288300 R15: ffff91a974d45488
FS:  00007fe9650fe640(0000) GS:ffff91a9f9a00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f0c4f9cf000 CR3: 000000007b340000 CR4: 00000000000506f0
Call Trace:
 <TASK>
 vmw_cmdbuf_man_process+0x59/0x100 [vmwgfx]
 __vmw_cmdbuf_cur_flush+0xad/0xf0 [vmwgfx]
 vmw_cmdbuf_reserve+0xb2/0x170 [vmwgfx]
 vmw_cmd_send_fence+0x31/0x160 [vmwgfx]
 vmw_execbuf_fence_commands+0x58/0x110 [vmwgfx]
 vmw_execbuf_process+0x817/0x1160 [vmwgfx]
 ? __pfx_vmw_execbuf_ioctl+0x10/0x10 [vmwgfx]
 vmw_execbuf_ioctl+0x151/0x280 [vmwgfx]
 ? __pfx_vmw_execbuf_ioctl+0x10/0x10 [vmwgfx]
 drm_ioctl_kernel+0xc9/0x170
 drm_ioctl+0x235/0x410
 ? __pfx_vmw_execbuf_ioctl+0x10/0x10 [vmwgfx]
 ? __pfx_drm_ioctl+0x10/0x10
 vmw_generic_ioctl+0xa7/0x110 [vmwgfx]
 __x64_sys_ioctl+0x90/0xd0
 do_syscall_64+0x5c/0x90
 ? syscall_exit_to_user_mode+0x17/0x40
 ? do_syscall_64+0x68/0x90
 entry_SYSCALL_64_after_hwframe+0x72/0xdc
RIP: 0033:0x7fe96bd0dbdd
Code: 04 25 28 00 00 00 48 89 45 c8 31 c0 48 8d 45 10 c7 45 b0 10 00 00 00 48 89 45 b8 48 8d 45 d0 48 89 45 c0 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 1a 48 8b 45 c8 64 48 2b 04 25 28 00 00 00
RSP: 002b:00007fe9650fd4c0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000028 RCX: 00007fe96bd0dbdd
RDX: 00007fe9650fd580 RSI: 000000004028644c RDI: 0000000000000021
RBP: 00007fe9650fd510 R08: 0000000000000078 R09: 00007fe9650fd618
R10: 5f2c56df6cb73146 R11: 0000000000000246 R12: 00007fe9650fd580
R13: 000000004028644c R14: 0000000000000021 R15: 00007fe9650fd618
 </TASK>
Complete report #729575
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x7e
2
vmw_user_surface_base_release
vmwgfx 0x7e
3
vmw_user_surface_base_release
vmwgfx 0x7e
4
vmw_user_surface_base_release
vmwgfx 0x7e
5
vmw_user_surface_base_release
vmwgfx 0x7e
6
vmw_user_surface_base_release
vmwgfx 0x7e
7
drm_ioctl_kernel
vmlinux 0xc6
8
drm_ioctl_kernel
vmlinux 0xc6
9
drm_ioctl_kernel
vmlinux 0xc6
10
drm_ioctl_kernel
vmlinux 0xc6
11
drm_ioctl_kernel
vmlinux 0xc6
12
drm_ioctl_kernel
vmlinux 0xc6
13
drm_ioctl_kernel
vmlinux 0xc6
14
drm_ioctl_kernel
vmlinux 0xc6
15
drm_ioctl_kernel
vmlinux 0xc6
16
drm_ioctl_kernel
vmlinux 0xc6
17
drm_ioctl_kernel
vmlinux 0xc6
WARNING: CPU: 7 PID: 95462 at lib/refcount.c:28 refcount_warn_saturate+0xba/0x110
Modules linked in: tun overlay uinput snd_seq_dummy snd_hrtimer nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set nf_tables nfnetlink qrtr snd_seq_midi snd_seq_midi_event bnep vsock_loopback vmw_vsock_virtio_transport_common vmw_vsock_vmci_transport vsock sunrpc intel_rapl_msr intel_rapl_common kvm_amd snd_ens1371 btusb snd_ac97_codec ccp btrtl snd_rawmidi btbcm vmw_balloon binfmt_misc btintel gameport btmtk ac97_bus kvm snd_seq bluetooth vfat snd_seq_device snd_pcm fat irqbypass snd_timer rfkill pcspkr snd soundcore i2c_piix4 vmw_vmci joydev loop zram crct10dif_pclmul crc32_pclmul crc32c_intel polyval_clmulni polyval_generic vmwgfx ghash_clmulni_intel sha512_ssse3 mptspi scsi_transport_spi mptscsih e1000 drm_ttm_helper mptbase ttm serio_raw ata_generic pata_acpi ip6_tables ip_tables fuse
CPU: 7 PID: 95462 Comm: .NET Tiered Com Tainted: G        W          6.2.15-300.fc38.x86_64 #1
Hardware name: VMware, Inc. VMware7,1/440BX Desktop Reference Platform, BIOS VMW71.00V.18452719.B64.2108091906 08/09/2021
RIP: 0010:refcount_warn_saturate+0xba/0x110
Code: 01 01 e8 d9 d9 92 ff 0f 0b e9 92 df 79 00 80 3d 03 a3 ae 01 00 75 85 48 c7 c7 90 a7 8d 91 c6 05 f3 a2 ae 01 01 e8 b6 d9 92 ff <0f> 0b e9 6f df 79 00 80 3d e1 a2 ae 01 00 0f 85 5e ff ff ff 48 c7
RSP: 0018:ffffb0a2e00f3c40 EFLAGS: 00010286
RAX: 0000000000000000 RBX: ffffb0a2e00f3c68 RCX: 0000000000000000
RDX: 0000000000000002 RSI: 0000000000000027 RDI: 00000000ffffffff
RBP: ffff9db5c69e8008 R08: 0000000000000000 R09: ffffb0a2e00f3ad0
R10: 0000000000000003 R11: ffff9db73fec14a8 R12: ffff9db460112420
R13: ffff9db40ff00000 R14: ffff9db62358f2d0 R15: dead000000000100
FS:  0000000000000000(0000) GS:ffff9db72dfc0000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000564318c12530 CR3: 00000001df4e0000 CR4: 0000000000350ee0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x7e/0x90 [vmwgfx]
 ttm_prime_refcount_release+0x3d/0x60 [vmwgfx]
 ttm_release_base+0x85/0xd0 [vmwgfx]
 ttm_ref_object_release+0xb6/0xd0 [vmwgfx]
 ttm_object_file_release+0x39/0x90 [vmwgfx]
 vmw_postclose+0x15/0x20 [vmwgfx]
 drm_file_free.part.0+0x207/0x250
 drm_release+0x64/0xd0
 __fput+0x91/0x250
 task_work_run+0x59/0x90
 do_exit+0x33e/0xb20
 do_group_exit+0x2d/0x80
 get_signal+0x9b0/0x9f0
 arch_do_signal_or_restart+0x3a/0x280
 exit_to_user_mode_prepare+0x18d/0x1f0
 irqentry_exit_to_user_mode+0x5/0x30
 asm_exc_page_fault+0x22/0x30
RIP: 0033:0x561bc576ec85
Code: Unable to access opcode bytes at 0x561bc576ec5b.
RSP: 002b:00007f7e94c8d068 EFLAGS: 00010202
RAX: 0000000000000001 RBX: 0000000000010200 RCX: 0000000000045800
RDX: 00000000000259b4 RSI: 00000000000259b4 RDI: 00000000000259b4
RBP: 0000561b4edf08c8 R08: 0000561b4edf08c8 R09: 00000000fffffe00
R10: 0000561b4edf0740 R11: 0000561b4edf0940 R12: 0000000000000007
R13: 0000561b4ee8c661 R14: 00000000fffefdff R15: 00000000000001ff
 </TASK>
Complete report #723592
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x7e
2
vmw_user_surface_base_release
vmwgfx 0x7e
3
vmw_user_surface_base_release
vmwgfx 0x7e
4
vmw_user_surface_base_release
vmwgfx 0x7e
5
? vmw_user_surface_base_release
vmwgfx 0x7e
6
vmw_user_surface_base_release
vmwgfx 0x7e
7
? vmw_user_surface_base_release
vmwgfx 0x7e
8
drm_ioctl_kernel
vmlinux 0xc6
9
drm_ioctl_kernel
vmlinux 0xc6
10
? vmw_user_surface_base_release
vmwgfx 0x7e
11
? drm_ioctl_kernel
vmlinux 0xc6
12
vmw_user_surface_base_release
vmwgfx 0x7e
13
drm_ioctl_kernel
vmlinux 0xc6
14
drm_ioctl_kernel
vmlinux 0xc6
15
? drm_ioctl_kernel
vmlinux 0xc6
16
? vmw_user_surface_base_release
vmwgfx 0x7e
17
? drm_ioctl_kernel
vmlinux 0xc6
18
? drm_ioctl_kernel
vmlinux 0xc6
19
? drm_ioctl_kernel
vmlinux 0xc6
20
drm_ioctl_kernel
vmlinux 0xc6
WARNING: CPU: 4 PID: 2192 at drivers/gpu/drm/vmwgfx/vmwgfx_cmdbuf.c:414 vmw_cmdbuf_ctx_process+0x229/0x260 [vmwgfx]
Modules linked in: uinput snd_seq_dummy snd_hrtimer nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 rfkill ip_set nf_tables nfnetlink qrtr sunrpc snd_intel8x0 snd_ac97_codec ac97_bus snd_seq snd_seq_device snd_pcm snd_timer intel_rapl_msr snd intel_rapl_common vboxguest pcspkr soundcore joydev i2c_piix4 loop zram crct10dif_pclmul crc32_pclmul crc32c_intel polyval_clmulni polyval_generic vmwgfx ghash_clmulni_intel e1000 sha512_ssse3 drm_ttm_helper ttm video wmi serio_raw ata_generic pata_acpi ip6_tables ip_tables fuse
CPU: 4 PID: 2192 Comm: Xwayland Not tainted 6.2.15-300.fc38.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:vmw_cmdbuf_ctx_process+0x229/0x260 [vmwgfx]
Code: 03 83 03 01 48 83 c4 28 5b 5d 41 5c 41 5d 41 5e 41 5f c3 cc cc cc cc 48 c7 c7 88 80 44 c0 c6 05 a7 94 03 00 01 e8 d7 53 ce cb <0f> 0b 4c 89 e7 e8 6d fb ff ff e9 a5 fe ff ff 48 c7 c7 64 4d 44 c0
RSP: 0018:ffffb46381ebfa08 EFLAGS: 00010282
RAX: 0000000000000000 RBX: 0000000000000002 RCX: 0000000000000000
RDX: 0000000000000003 RSI: 0000000000000027 RDI: 00000000ffffffff
RBP: ffff9d2a8403d800 R08: 0000000000000000 R09: ffffb46381ebf898
R10: 0000000000000003 R11: ffffffff8e1447c8 R12: ffff9d2ac506ea00
R13: ffff9d2ac506ea18 R14: ffff9d2ac506e100 R15: ffff9d2a8403d888
FS:  00007fb28a915a00(0000) GS:ffff9d2d78300000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fb2895358c0 CR3: 000000014a658000 CR4: 00000000000506e0
Call Trace:
 <TASK>
 vmw_cmdbuf_man_process+0x59/0x100 [vmwgfx]
 __vmw_cmdbuf_cur_flush+0xad/0xf0 [vmwgfx]
 vmw_cmdbuf_commit+0x29/0xd0 [vmwgfx]
 vmw_execbuf_process+0x768/0x1160 [vmwgfx]
 ? __pfx_vmw_execbuf_ioctl+0x10/0x10 [vmwgfx]
 vmw_execbuf_ioctl+0x151/0x280 [vmwgfx]
 ? __pfx_vmw_execbuf_ioctl+0x10/0x10 [vmwgfx]
 drm_ioctl_kernel+0xc9/0x170
 drm_ioctl+0x235/0x410
 ? __pfx_vmw_execbuf_ioctl+0x10/0x10 [vmwgfx]
 ? __pfx_drm_ioctl+0x10/0x10
 vmw_generic_ioctl+0xa7/0x110 [vmwgfx]
 __x64_sys_ioctl+0x90/0xd0
 do_syscall_64+0x5c/0x90
 ? __pfx_drm_ioctl+0x10/0x10
 ? vmw_generic_ioctl+0xa7/0x110 [vmwgfx]
 ? __x64_sys_ioctl+0x90/0xd0
 ? syscall_exit_to_user_mode+0x17/0x40
 ? do_syscall_64+0x68/0x90
 entry_SYSCALL_64_after_hwframe+0x72/0xdc
RIP: 0033:0x7fb28b2a1edd
Code: 04 25 28 00 00 00 48 89 45 c8 31 c0 48 8d 45 10 c7 45 b0 10 00 00 00 48 89 45 b8 48 8d 45 d0 48 89 45 c0 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 1a 48 8b 45 c8 64 48 2b 04 25 28 00 00 00
RSP: 002b:00007ffdb2c0bad0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000028 RCX: 00007fb28b2a1edd
RDX: 00007ffdb2c0bb90 RSI: 000000004028644c RDI: 000000000000000c
RBP: 00007ffdb2c0bb20 R08: 0000000000000034 R09: 00007ffdb2c0bc28
R10: 0000000000000000 R11: 0000000000000246 R12: 00007ffdb2c0bb90
R13: 000000004028644c R14: 000000000000000c R15: 00007ffdb2c0bc28
 </TASK>
Complete report #721136
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x7e
2
vmw_user_surface_base_release
vmwgfx 0x7e
3
vmw_user_surface_base_release
vmwgfx 0x7e
4
? vmw_user_surface_base_release
vmwgfx 0x7e
5
vmw_user_surface_base_release
vmwgfx 0x7e
6
? vmw_user_surface_base_release
vmwgfx 0x7e
7
drm_ioctl_kernel
vmlinux 0xc6
8
drm_ioctl_kernel
vmlinux 0xc6
9
? vmw_user_surface_base_release
vmwgfx 0x7e
10
? drm_ioctl_kernel
vmlinux 0xc6
11
vmw_user_surface_base_release
vmwgfx 0x7e
12
drm_ioctl_kernel
vmlinux 0xc6
13
drm_ioctl_kernel
vmlinux 0xc6
14
? drm_ioctl_kernel
vmlinux 0xc6
15
? drm_ioctl_kernel
vmlinux 0xc6
16
? drm_ioctl_kernel
vmlinux 0xc6
17
? drm_ioctl_kernel
vmlinux 0xc6
18
drm_ioctl_kernel
vmlinux 0xc6
general protection fault, probably for non-canonical address 0x898accab993a0: 0000 [#2] PREEMPT SMP PTI
CPU: 1 PID: 2246 Comm: gnome-software Tainted: G      D W  OE      6.2.15-300.fc38.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:mutex_lock+0x19/0x30
Code: 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 0f 1f 44 00 00 53 48 89 fb e8 02 d1 ff ff 31 c0 65 48 8b 14 25 c0 15 03 00 <f0> 48 0f b1 13 75 06 5b c3 cc cc cc cc 48 89 df 5b eb b4 0f 1f 40
RSP: 0018:ffffbdd3849efad0 EFLAGS: 00010246
RAX: 0000000000000000 RBX: 000898accab993a0 RCX: ffff98accab99338
RDX: ffff98ad0e1bce80 RSI: 0000000000000002 RDI: 000898accab993a0
RBP: 0000000000000002 R08: 0000000000000000 R09: 0000000080400036
R10: ffff98ad2d644028 R11: 0000000000000000 R12: 000898accab993a0
R13: ffff98accab99338 R14: dead000000000122 R15: dead000000000100
FS:  00007f3f5f477a80(0000) GS:ffff98add7c80000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f91135ff990 CR3: 000000012457e000 CR4: 00000000000006e0
Call Trace:
 <TASK>
 vmw_view_commit_notify+0x27/0x130 [vmwgfx]
 vmw_cmdbuf_res_commit+0xb5/0x130 [vmwgfx]
 vmw_execbuf_process+0x949/0x1160 [vmwgfx]
 ? __pfx_vmw_execbuf_ioctl+0x10/0x10 [vmwgfx]
 vmw_execbuf_ioctl+0x151/0x280 [vmwgfx]
 ? __pfx_vmw_execbuf_ioctl+0x10/0x10 [vmwgfx]
 drm_ioctl_kernel+0xc9/0x170
 drm_ioctl+0x235/0x410
 ? __pfx_vmw_execbuf_ioctl+0x10/0x10 [vmwgfx]
 ? __pfx_drm_ioctl+0x10/0x10
 vmw_generic_ioctl+0xa7/0x110 [vmwgfx]
 __x64_sys_ioctl+0x90/0xd0
 do_syscall_64+0x5c/0x90
 ? syscall_exit_to_user_mode+0x17/0x40
 ? do_syscall_64+0x68/0x90
 ? syscall_exit_to_user_mode+0x17/0x40
 ? do_syscall_64+0x68/0x90
 entry_SYSCALL_64_after_hwframe+0x72/0xdc
RIP: 0033:0x7f3f612dbedd
Code: 04 25 28 00 00 00 48 89 45 c8 31 c0 48 8d 45 10 c7 45 b0 10 00 00 00 48 89 45 b8 48 8d 45 d0 48 89 45 c0 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 1a 48 8b 45 c8 64 48 2b 04 25 28 00 00 00
RSP: 002b:00007ffdb0f57560 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000028 RCX: 00007f3f612dbedd
RDX: 00007ffdb0f57620 RSI: 000000004028644c RDI: 000000000000002f
RBP: 00007ffdb0f575b0 R08: 00000000000006e0 R09: 00007ffdb0f576b8
R10: 0000000000000001 R11: 0000000000000246 R12: 00007ffdb0f57620
R13: 000000004028644c R14: 000000000000002f R15: 00007ffdb0f576b8
 </TASK>
Modules linked in: uinput isofs snd_seq_dummy snd_hrtimer xt_CHECKSUM xt_MASQUERADE xt_conntrack ipt_REJECT nf_nat_tftp nf_conntrack_tftp bridge stp llc rfkill nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_tables ebtable_nat ebtable_broute ip6table_nat ip6table_mangle ip6table_raw ip6table_security iptable_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 iptable_mangle iptable_raw iptable_security ip_set nfnetlink ebtable_filter ebtables ip6table_filter ip6_tables iptable_filter ip_tables qrtr sunrpc snd_intel8x0 snd_ac97_codec ac97_bus snd_seq snd_seq_device snd_pcm snd_timer snd soundcore pcspkr i2c_piix4 joydev loop zram vmwgfx e1000 crc32c_intel video drm_ttm_helper wmi ttm sha512_ssse3 vboxguest(OE) serio_raw ata_generic pata_acpi scsi_dh_rdac scsi_dh_emc scsi_dh_alua fuse dm_multipath
Complete report #716855
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x7e
2
vmw_user_surface_base_release
vmwgfx 0x7e
3
? vmw_user_surface_base_release
vmwgfx 0x7e
4
vmw_user_surface_base_release
vmwgfx 0x7e
5
? vmw_user_surface_base_release
vmwgfx 0x7e
6
? vmw_user_surface_base_release
vmwgfx 0x7e
7
vmw_user_surface_base_release
vmwgfx 0x7e
8
? vmw_user_surface_base_release
vmwgfx 0x7e
9
drm_ioctl_kernel
vmlinux 0xc6
10
drm_ioctl_kernel
vmlinux 0xc6
11
? vmw_user_surface_base_release
vmwgfx 0x7e
12
? drm_ioctl_kernel
vmlinux 0xc6
13
vmw_user_surface_base_release
vmwgfx 0x7e
14
drm_ioctl_kernel
vmlinux 0xc6
15
drm_ioctl_kernel
vmlinux 0xc6
16
? drm_ioctl_kernel
vmlinux 0xc6
17
drm_ioctl_kernel
vmlinux 0xc6
general protection fault, probably for non-canonical address 0x893b8751e101d: 0000 [#2] PREEMPT SMP NOPTI
CPU: 0 PID: 1730 Comm: gnome-shell Tainted: G      D W          6.2.15-300.fc38.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:vmw_validation_add_resource+0x17f/0x270 [vmwgfx]
Code: 10 48 89 32 48 85 c0 74 04 48 89 70 08 48 89 ef e8 06 4f fe ff 48 89 43 28 48 85 c0 0f 84 cf 00 00 00 80 4b 40 04 48 8b 45 08 <80> b8 1d 10 00 00 00 74 16 48 89 ef e8 30 63 fe ff 83 f8 04 74 40
RSP: 0018:ffffa27f02da7a98 EFLAGS: 00010202
RAX: 000893b8751e0000 RBX: ffff93b845ae2580 RCX: 0000000000000002
RDX: 0000000000000003 RSI: ffff93b845ae2590 RDI: ffff93b8966e6810
RBP: ffff93b8966e6810 R08: ffffa27f02da7af8 R09: 0000000000000000
R10: 0000000000000006 R11: 0000000000000000 R12: 0000000000000000
R13: ffffa27f02da7af8 R14: ffffa27f02da7c30 R15: 0000000000000000
FS:  00007f5ef44a9600(0000) GS:ffff93b8bdc00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000027ef6a149000 CR3: 000000000896a000 CR4: 00000000000506f0
Call Trace:
 <TASK>
 vmw_execbuf_res_val_add+0x1f0/0x4a0 [vmwgfx]
 vmw_execbuf_res_val_add+0x1cd/0x4a0 [vmwgfx]
 ? __pfx_vmw_execbuf_ioctl+0x10/0x10 [vmwgfx]
 vmw_execbuf_process+0x438/0x1160 [vmwgfx]
 ? vmw_fence_wait+0xdd/0x230 [vmwgfx]
 ? __pfx_vmw_execbuf_ioctl+0x10/0x10 [vmwgfx]
 vmw_execbuf_ioctl+0x151/0x280 [vmwgfx]
 ? __pfx_vmw_execbuf_ioctl+0x10/0x10 [vmwgfx]
 drm_ioctl_kernel+0xc9/0x170
 drm_ioctl+0x235/0x410
 ? __pfx_vmw_execbuf_ioctl+0x10/0x10 [vmwgfx]
 ? __pfx_drm_ioctl+0x10/0x10
 vmw_generic_ioctl+0xa7/0x110 [vmwgfx]
 __x64_sys_ioctl+0x90/0xd0
 do_syscall_64+0x5c/0x90
 ? __irq_exit_rcu+0x3d/0x140
 entry_SYSCALL_64_after_hwframe+0x72/0xdc
RIP: 0033:0x7f5ef7b28edd
Code: 04 25 28 00 00 00 48 89 45 c8 31 c0 48 8d 45 10 c7 45 b0 10 00 00 00 48 89 45 b8 48 8d 45 d0 48 89 45 c0 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 1a 48 8b 45 c8 64 48 2b 04 25 28 00 00 00
RSP: 002b:00007ffd408280a0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000028 RCX: 00007f5ef7b28edd
RDX: 00007ffd40828160 RSI: 000000004028644c RDI: 000000000000000c
RBP: 00007ffd408280f0 R08: 0000000000000058 R09: 00007ffd408281f8
R10: 0000000000000049 R11: 0000000000000246 R12: 00007ffd40828160
R13: 000000004028644c R14: 000000000000000c R15: 00007ffd408281f8
 </TASK>
Modules linked in: uinput snd_seq_dummy snd_hrtimer nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 rfkill ip_set nf_tables nfnetlink qrtr sunrpc binfmt_misc snd_intel8x0 snd_ac97_codec ac97_bus snd_seq snd_seq_device snd_pcm intel_rapl_msr intel_rapl_common pcspkr snd_timer snd vboxguest i2c_piix4 soundcore joydev loop zram crct10dif_pclmul crc32_pclmul crc32c_intel polyval_clmulni polyval_generic vmwgfx ghash_clmulni_intel video drm_ttm_helper e1000 sha512_ssse3 ttm wmi serio_raw ata_generic pata_acpi ip6_tables ip_tables fuse
Complete report #715686
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x7e
2
vmw_user_surface_base_release
vmwgfx 0x7e
3
vmw_user_surface_base_release
vmwgfx 0x7e
4
? vmw_user_surface_base_release
vmwgfx 0x7e
5
vmw_user_surface_base_release
vmwgfx 0x7e
6
? vmw_user_surface_base_release
vmwgfx 0x7e
7
drm_ioctl_kernel
vmlinux 0xc6
8
drm_ioctl_kernel
vmlinux 0xc6
9
? vmw_user_surface_base_release
vmwgfx 0x7e
10
? drm_ioctl_kernel
vmlinux 0xc6
11
vmw_user_surface_base_release
vmwgfx 0x7e
12
drm_ioctl_kernel
vmlinux 0xc6
13
drm_ioctl_kernel
vmlinux 0xc6
14
? drm_ioctl_kernel
vmlinux 0xc6
15
? drm_ioctl_kernel
vmlinux 0xc6
16
? drm_ioctl_kernel
vmlinux 0xc6
17
? drm_ioctl_kernel
vmlinux 0xc6
18
drm_ioctl_kernel
vmlinux 0xc6
WARNING: CPU: 0 PID: 3350 at lib/refcount.c:28 refcount_warn_saturate+0xba/0x110
Modules linked in: uinput snd_seq_dummy snd_hrtimer xt_CHECKSUM xt_MASQUERADE xt_conntrack ipt_REJECT nf_nat_tftp nf_conntrack_tftp nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat ip6table_nat ip6table_mangle ip6table_raw ip6table_security iptable_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 iptable_mangle iptable_raw iptable_security bridge stp llc ip_set nf_tables rfkill nfnetlink ip6table_filter iptable_filter qrtr vsock_loopback vmw_vsock_virtio_transport_common vmw_vsock_vmci_transport vsock sunrpc binfmt_misc snd_seq_midi snd_seq_midi_event squashfs snd_ens1371 snd_ac97_codec snd_rawmidi vmw_balloon intel_rapl_msr gameport intel_rapl_common ac97_bus snd_seq snd_seq_device rapl snd_pcm pcspkr i2c_piix4 snd_timer snd soundcore vmw_vmci joydev loop zram dm_crypt crct10dif_pclmul crc32_pclmul crc32c_intel polyval_clmulni polyval_generic
 vmwgfx ghash_clmulni_intel e1000 mptspi sha512_ssse3 scsi_transport_spi mptscsih mptbase drm_ttm_helper ttm serio_raw ata_generic pata_acpi scsi_dh_rdac scsi_dh_emc scsi_dh_alua ip6_tables ip_tables dm_multipath fuse
CPU: 0 PID: 3350 Comm: Renderer Tainted: G        W          6.2.15-300.fc38.x86_64 #1
Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 11/12/2020
RIP: 0010:refcount_warn_saturate+0xba/0x110
Code: 01 01 e8 d9 d9 92 ff 0f 0b c3 cc cc cc cc 80 3d 03 a3 ae 01 00 75 85 48 c7 c7 90 a7 8d b1 c6 05 f3 a2 ae 01 01 e8 b6 d9 92 ff <0f> 0b c3 cc cc cc cc 80 3d e1 a2 ae 01 00 0f 85 5e ff ff ff 48 c7
RSP: 0018:ffffa7faa0223ac8 EFLAGS: 00010286
RAX: 0000000000000000 RBX: ffff985f4e2a11c0 RCX: 0000000000000000
RDX: 0000000000000002 RSI: 0000000000000027 RDI: 00000000ffffffff
RBP: ffff985f4e2a0000 R08: 0000000000000000 R09: ffffa7faa0223958
R10: 0000000000000003 R11: ffff985fbfec37a8 R12: ffff985fada024f8
R13: ffffa7faa0223b10 R14: 0000000000000000 R15: 0000000000000010
FS:  00007f979edbc6c0(0000) GS:ffff985fb8e00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f9789530774 CR3: 00000000182c6001 CR4: 00000000003706f0
Call Trace:
 <TASK>
 vmw_translate_mob_ptr+0x15e/0x170 [vmwgfx]
 vmw_cmd_res_switch_backup+0xa3/0xd0 [vmwgfx]
 vmw_execbuf_process+0x54b/0x1160 [vmwgfx]
 ? __pfx_vmw_execbuf_ioctl+0x10/0x10 [vmwgfx]
 vmw_execbuf_ioctl+0x151/0x280 [vmwgfx]
 ? __pfx_vmw_execbuf_ioctl+0x10/0x10 [vmwgfx]
 drm_ioctl_kernel+0xc6/0x170
 drm_ioctl+0x235/0x410
 ? __pfx_vmw_execbuf_ioctl+0x10/0x10 [vmwgfx]
 ? __pfx_drm_ioctl+0x10/0x10
 vmw_generic_ioctl+0xa4/0x110 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xd0
 do_syscall_64+0x59/0x90
 ? __x64_sys_ioctl+0xa8/0xd0
 ? syscall_exit_to_user_mode+0x17/0x40
 ? do_syscall_64+0x68/0x90
 ? exc_page_fault+0x78/0x180
 entry_SYSCALL_64_after_hwframe+0x72/0xdc
RIP: 0033:0x7f97c3d28edd
Code: 04 25 28 00 00 00 48 89 45 c8 31 c0 48 8d 45 10 c7 45 b0 10 00 00 00 48 89 45 b8 48 8d 45 d0 48 89 45 c0 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 1a 48 8b 45 c8 64 48 2b 04 25 28 00 00 00
RSP: 002b:00007f979edb9620 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000028 RCX: 00007f97c3d28edd
RDX: 00007f979edb96e0 RSI: 000000004028644c RDI: 000000000000002b
RBP: 00007f979edb9670 R08: 00000000000000bc R09: 00007f979edb9778
R10: 0000000000000001 R11: 0000000000000246 R12: 00007f979edb96e0
R13: 000000004028644c R14: 000000000000002b R15: 00007f979edb9778
 </TASK>
Complete report #714893
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x7e
2
vmw_user_surface_base_release
vmwgfx 0x7e
3
vmw_user_surface_base_release
vmwgfx 0x7e
4
vmw_user_surface_base_release
vmwgfx 0x7e
5
? vmw_user_surface_base_release
vmwgfx 0x7e
6
vmw_user_surface_base_release
vmwgfx 0x7e
7
? vmw_user_surface_base_release
vmwgfx 0x7e
8
drm_ioctl_kernel
vmlinux 0xc6
9
drm_ioctl_kernel
vmlinux 0xc6
10
? vmw_user_surface_base_release
vmwgfx 0x7e
11
? drm_ioctl_kernel
vmlinux 0xc6
12
vmw_user_surface_base_release
vmwgfx 0x7e
13
drm_ioctl_kernel
vmlinux 0xc6
14
drm_ioctl_kernel
vmlinux 0xc6
15
? drm_ioctl_kernel
vmlinux 0xc6
16
? drm_ioctl_kernel
vmlinux 0xc6
17
drm_ioctl_kernel
vmlinux 0xc6
general protection fault, probably for non-canonical address 0x4916fb4fd101d: 0000 [#2] PREEMPT SMP PTI
CPU: 1 PID: 3512 Comm: gnome-shell Tainted: G      D W          6.2.15-300.fc38.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:vmw_validation_add_resource+0x17f/0x270 [vmwgfx]
Code: 10 48 89 32 48 85 c0 74 04 48 89 70 08 48 89 ef e8 06 4f fe ff 48 89 43 28 48 85 c0 0f 84 cf 00 00 00 80 4b 40 04 48 8b 45 08 <80> b8 1d 10 00 00 00 74 16 48 89 ef e8 30 63 fe ff 83 f8 04 74 40
RSP: 0018:ffffb8c7c2a87a20 EFLAGS: 00010202
RAX: 0004916fb4fd0000 RBX: ffff916f86528090 RCX: 0000000000000002
RDX: 0000000000000003 RSI: ffff916f865280a0 RDI: ffff916f88d01210
RBP: ffff916f88d01210 R08: ffffb8c7c2a87a80 R09: 0000000000000000
R10: 0000000000000006 R11: 0000000000000000 R12: 0000000000000000
R13: ffffb8c7c2a87a80 R14: ffffb8c7c2a87bf8 R15: 0000000000000000
FS:  00007f4c4c13d600(0000) GS:ffff916ffdd00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f2cb39dd028 CR3: 0000000051c8a000 CR4: 00000000000406e0
Call Trace:
 <TASK>
 vmw_execbuf_res_val_add+0x1f0/0x4a0 [vmwgfx]
 vmw_view_bindings_add+0x92/0x1a0 [vmwgfx]
 vmw_cmd_dx_set_shader_res+0x55/0x80 [vmwgfx]
 vmw_execbuf_process+0x54e/0x1160 [vmwgfx]
 ? __pfx_vmw_execbuf_ioctl+0x10/0x10 [vmwgfx]
 vmw_execbuf_ioctl+0x151/0x280 [vmwgfx]
 ? __pfx_vmw_execbuf_ioctl+0x10/0x10 [vmwgfx]
 drm_ioctl_kernel+0xc9/0x170
 drm_ioctl+0x235/0x410
 ? __pfx_vmw_execbuf_ioctl+0x10/0x10 [vmwgfx]
 ? __pfx_drm_ioctl+0x10/0x10
 vmw_generic_ioctl+0xa7/0x110 [vmwgfx]
 __x64_sys_ioctl+0x90/0xd0
 do_syscall_64+0x5c/0x90
 ? switch_fpu_return+0x17/0xe0
 ? exit_to_user_mode_prepare+0x13a/0x1f0
 entry_SYSCALL_64_after_hwframe+0x72/0xdc
RIP: 0033:0x7f4c4f728edd
Code: 04 25 28 00 00 00 48 89 45 c8 31 c0 48 8d 45 10 c7 45 b0 10 00 00 00 48 89 45 b8 48 8d 45 d0 48 89 45 c0 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 1a 48 8b 45 c8 64 48 2b 04 25 28 00 00 00
RSP: 002b:00007fff4f802ab0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000028 RCX: 00007f4c4f728edd
RDX: 00007fff4f802b70 RSI: 000000004028644c RDI: 000000000000000c
RBP: 00007fff4f802b00 R08: 0000000000000a44 R09: 00007fff4f802c08
R10: 0000000000000001 R11: 0000000000000246 R12: 00007fff4f802b70
R13: 000000004028644c R14: 000000000000000c R15: 00007fff4f802c08
 </TASK>
Modules linked in: uinput snd_seq_dummy snd_hrtimer rfkill nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_tables ebtable_nat ebtable_broute ip6table_nat ip6table_mangle ip6table_raw ip6table_security iptable_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 iptable_mangle iptable_raw iptable_security ip_set nfnetlink ebtable_filter ebtables ip6table_filter iptable_filter qrtr snd_intel8x0 snd_ac97_codec ac97_bus snd_seq snd_seq_device snd_pcm intel_rapl_msr joydev snd_timer intel_rapl_common rapl snd sunrpc pcspkr soundcore vboxguest i2c_piix4 binfmt_misc loop zram crct10dif_pclmul vmwgfx crc32_pclmul crc32c_intel polyval_clmulni polyval_generic ghash_clmulni_intel drm_ttm_helper e1000 sha512_ssse3 video ttm wmi serio_raw ata_generic pata_acpi scsi_dh_rdac scsi_dh_emc scsi_dh_alua ip6_tables ip_tables dm_multipath fuse
Complete report #714800
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x7e
2
vmw_user_surface_base_release
vmwgfx 0x7e
3
vmw_user_surface_base_release
vmwgfx 0x7e
4
vmw_user_surface_base_release
vmwgfx 0x7e
5
vmw_user_surface_base_release
vmwgfx 0x7e
6
vmw_user_surface_base_release
vmwgfx 0x7e
7
drm_ioctl_kernel
vmlinux 0xc6
8
drm_ioctl_kernel
vmlinux 0xc6
9
drm_ioctl_kernel
vmlinux 0xc6
10
drm_ioctl_kernel
vmlinux 0xc6
11
drm_ioctl_kernel
vmlinux 0xc6
12
? drm_ioctl_kernel
vmlinux 0xc6
13
? drm_ioctl_kernel
vmlinux 0xc6
14
drm_ioctl_kernel
vmlinux 0xc6
15
drm_ioctl_kernel
vmlinux 0xc6
16
drm_ioctl_kernel
vmlinux 0xc6
17
drm_ioctl_kernel
vmlinux 0xc6
WARNING: CPU: 1 PID: 1797 at lib/refcount.c:28 refcount_warn_saturate+0xba/0x110
Modules linked in: uinput snd_seq_dummy snd_hrtimer snd_seq_midi snd_seq_midi_event intel_rapl_msr intel_rapl_common kvm_intel bnep kvm snd_ens1371 snd_ac97_codec uvcvideo snd_rawmidi gameport ac97_bus btusb snd_seq videobuf2_vmalloc videobuf2_memops btrtl btbcm videobuf2_v4l2 btintel btmtk snd_seq_device irqbypass rapl nf_conntrack_netbios_ns nf_conntrack_broadcast videobuf2_common nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib snd_pcm vmw_balloon nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct bluetooth nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 videodev ip_set pcspkr nf_tables nfnetlink snd_timer mc rfkill snd soundcore i2c_piix4 qrtr vsock_loopback vmw_vsock_virtio_transport_common vmw_vsock_vmci_transport vsock vmw_vmci sunrpc binfmt_misc vfat fat joydev loop zram crct10dif_pclmul crc32_pclmul crc32c_intel polyval_clmulni polyval_generic nvme ghash_clmulni_intel vmwgfx sha512_ssse3 nvme_core nvme_common vmxnet3 drm_ttm_helper ttm
 ata_generic pata_acpi serio_raw ip6_tables ip_tables fuse
CPU: 1 PID: 1797 Comm: Xwayland Tainted: G             L     6.2.15-300.fc38.x86_64 #1
Hardware name: VMware, Inc. VMware20,1/440BX Desktop Reference Platform, BIOS VMW201.00V.20904234.B64.2212051119 12/05/2022
RIP: 0010:refcount_warn_saturate+0xba/0x110
Code: 01 01 e8 d9 d9 92 ff 0f 0b c3 cc cc cc cc 80 3d 03 a3 ae 01 00 75 85 48 c7 c7 90 a7 8d a7 c6 05 f3 a2 ae 01 01 e8 b6 d9 92 ff <0f> 0b c3 cc cc cc cc 80 3d e1 a2 ae 01 00 0f 85 5e ff ff ff 48 c7
RSP: 0018:ffff9c14c2d0fd38 EFLAGS: 00010282
RAX: 0000000000000000 RBX: ffff9c14c2d0fd60 RCX: 0000000000000000
RDX: 0000000000000002 RSI: 0000000000000027 RDI: 00000000ffffffff
RBP: ffff8aea47190008 R08: 0000000000000000 R09: ffff9c14c2d0fbc8
R10: 0000000000000003 R11: ffff8aea7fec30a8 R12: ffff8ae9c4c79300
R13: ffff8aea4e5f0000 R14: ffff8aea755286d0 R15: dead000000000100
FS:  0000000000000000(0000) GS:ffff8aea79e40000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00005567c2784470 CR3: 0000000107044001 CR4: 00000000001706e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x7e/0x90 [vmwgfx]
 ttm_prime_refcount_release+0x3a/0x60 [vmwgfx]
 ttm_release_base+0x82/0xd0 [vmwgfx]
 ttm_ref_object_release+0xb6/0xd0 [vmwgfx]
 ttm_object_file_release+0x39/0x90 [vmwgfx]
 vmw_postclose+0x15/0x20 [vmwgfx]
 drm_file_free.part.0+0x204/0x250
 drm_release+0x64/0xd0
 __fput+0x8e/0x250
 task_work_run+0x56/0x90
 do_exit+0x33e/0xb20
 ? handle_mm_fault+0xff/0x2f0
 ? preempt_count_add+0x47/0xa0
 do_group_exit+0x2d/0x80
 __x64_sys_exit_group+0x14/0x20
 do_syscall_64+0x59/0x90
 entry_SYSCALL_64_after_hwframe+0x72/0xdc
RIP: 0033:0x7fdbb427644d
Code: Unable to access opcode bytes at 0x7fdbb4276423.
RSP: 002b:00007fff37461568 EFLAGS: 00000202 ORIG_RAX: 00000000000000e7
RAX: ffffffffffffffda RBX: 00007fdbb43712e8 RCX: 00007fdbb427644d
RDX: 00000000000000e7 RSI: fffffffffffffd20 RDI: 0000000000000000
RBP: 00007fff374615c0 R08: 00007fff37461510 R09: 0000000000000000
R10: 00007fff37461000 R11: 0000000000000202 R12: 0000000000000ab9
R13: 0000000000000000 R14: 0000000000000000 R15: 00007fdbb4371300
 </TASK>
Complete report #712944
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x7e
2
vmw_user_surface_base_release
vmwgfx 0x7e
3
? vmw_user_surface_base_release
vmwgfx 0x7e
4
vmw_user_surface_base_release
vmwgfx 0x7e
5
? vmw_user_surface_base_release
vmwgfx 0x7e
6
vmw_user_surface_base_release
vmwgfx 0x7e
7
? vmw_user_surface_base_release
vmwgfx 0x7e
8
drm_ioctl_kernel
vmlinux 0xc6
9
drm_ioctl_kernel
vmlinux 0xc6
10
? vmw_user_surface_base_release
vmwgfx 0x7e
11
? drm_ioctl_kernel
vmlinux 0xc6
12
vmw_user_surface_base_release
vmwgfx 0x7e
13
drm_ioctl_kernel
vmlinux 0xc6
14
drm_ioctl_kernel
vmlinux 0xc6
15
? drm_ioctl_kernel
vmlinux 0xc6
16
? drm_ioctl_kernel
vmlinux 0xc6
17
drm_ioctl_kernel
vmlinux 0xc6
general protection fault, probably for non-canonical address 0x1089448a2a101d: 0000 [#2] PREEMPT SMP NOPTI
CPU: 3 PID: 1771 Comm: gnome-shell Tainted: G      D W          6.2.15-300.fc38.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:vmw_validation_add_resource+0x17f/0x270 [vmwgfx]
Code: 10 48 89 32 48 85 c0 74 04 48 89 70 08 48 89 ef e8 06 4f fe ff 48 89 43 28 48 85 c0 0f 84 cf 00 00 00 80 4b 40 04 48 8b 45 08 <80> b8 1d 10 00 00 00 74 16 48 89 ef e8 30 63 fe ff 83 f8 04 74 40
RSP: 0018:ffffac2c445cfaa0 EFLAGS: 00010202
RAX: 001089448a2a0000 RBX: ffff8944cc011580 RCX: 0000000000000002
RDX: 0000000000000003 RSI: ffff8944cc011590 RDI: ffff8944a84e1e10
RBP: ffff8944a84e1e10 R08: ffffac2c445cfb00 R09: 0000000000000000
R10: 0000000000000006 R11: 0000000000000000 R12: 0000000000000000
R13: ffffac2c445cfb00 R14: ffffac2c445cfc38 R15: 0000000000000000
FS:  00007f83fe41c600(0000) GS:ffff894597d80000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00005573f55df350 CR3: 0000000101a20004 CR4: 00000000000706e0
Call Trace:
 <TASK>
 vmw_execbuf_res_val_add+0x1f0/0x4a0 [vmwgfx]
 vmw_execbuf_res_val_add+0x1cd/0x4a0 [vmwgfx]
 ? __pfx_vmw_execbuf_ioctl+0x10/0x10 [vmwgfx]
 vmw_execbuf_process+0x438/0x1160 [vmwgfx]
 ? __pfx_vmw_execbuf_ioctl+0x10/0x10 [vmwgfx]
 vmw_execbuf_ioctl+0x151/0x280 [vmwgfx]
 ? __pfx_vmw_execbuf_ioctl+0x10/0x10 [vmwgfx]
 drm_ioctl_kernel+0xc9/0x170
 drm_ioctl+0x235/0x410
 ? __pfx_vmw_execbuf_ioctl+0x10/0x10 [vmwgfx]
 ? __pfx_drm_ioctl+0x10/0x10
 vmw_generic_ioctl+0xa7/0x110 [vmwgfx]
 __x64_sys_ioctl+0x90/0xd0
 do_syscall_64+0x5c/0x90
 ? do_syscall_64+0x68/0x90
 ? do_syscall_64+0x68/0x90
 entry_SYSCALL_64_after_hwframe+0x72/0xdc
RIP: 0033:0x7f8401b04edd
Code: 04 25 28 00 00 00 48 89 45 c8 31 c0 48 8d 45 10 c7 45 b0 10 00 00 00 48 89 45 b8 48 8d 45 d0 48 89 45 c0 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 1a 48 8b 45 c8 64 48 2b 04 25 28 00 00 00
RSP: 002b:00007ffc2cbc3dc0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000028 RCX: 00007f8401b04edd
RDX: 00007ffc2cbc3e80 RSI: 000000004028644c RDI: 000000000000000c
RBP: 00007ffc2cbc3e10 R08: 0000000000000058 R09: 00007ffc2cbc3f18
R10: 000000000000006b R11: 0000000000000246 R12: 00007ffc2cbc3e80
R13: 000000004028644c R14: 000000000000000c R15: 00007ffc2cbc3f18
 </TASK>
Modules linked in: uinput snd_seq_dummy snd_hrtimer nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 rfkill ip_set nf_tables nfnetlink qrtr sunrpc binfmt_misc snd_intel8x0 snd_ac97_codec intel_rapl_msr intel_rapl_common ac97_bus snd_seq snd_seq_device snd_pcm snd_timer pcspkr snd soundcore i2c_piix4 vboxguest joydev loop zram crct10dif_pclmul crc32_pclmul crc32c_intel polyval_clmulni polyval_generic ghash_clmulni_intel vmwgfx sha512_ssse3 video wmi e1000 drm_ttm_helper ttm serio_raw ata_generic pata_acpi ip6_tables ip_tables fuse
Complete report #712766
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x7e
2
vmw_user_surface_base_release
vmwgfx 0x7e
3
vmw_user_surface_base_release
vmwgfx 0x7e
4
vmw_user_surface_base_release
vmwgfx 0x7e
5
vmw_user_surface_base_release
vmwgfx 0x7e
6
vmw_user_surface_base_release
vmwgfx 0x7e
7
drm_ioctl_kernel
vmlinux 0xc6
8
drm_ioctl_kernel
vmlinux 0xc6
9
drm_ioctl_kernel
vmlinux 0xc6
10
drm_ioctl_kernel
vmlinux 0xc6
11
drm_ioctl_kernel
vmlinux 0xc6
12
? drm_ioctl_kernel
vmlinux 0xc6
13
drm_ioctl_kernel
vmlinux 0xc6
14
drm_ioctl_kernel
vmlinux 0xc6
15
drm_ioctl_kernel
vmlinux 0xc6
16
? drm_ioctl_kernel
vmlinux 0xc6
17
drm_ioctl_kernel
vmlinux 0xc6
traps: gnome-shell[2170] general protection fault ip:7f919de20f25 sp:7ffd619cf460 error:0 in libgtk-4.so.1.1000.3[7f919dca4000+3fc000]
------------[ cut here ]------------
refcount_t: underflow; use-after-free.
WARNING: CPU: 6 PID: 2629 at lib/refcount.c:28 refcount_warn_saturate+0xba/0x110
Modules linked in: xt_CHECKSUM xt_MASQUERADE xt_conntrack ipt_REJECT nft_compat nf_nat_tftp nf_conntrack_tftp bridge stp llc exfat xfs uinput isofs snd_seq_dummy snd_hrtimer nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 vmnet(OE) ppdev parport_pc parport vmmon(OE) ip_set nf_tables nfnetlink qrtr vboxnetadp(OE) vboxnetflt(OE) vboxdrv(OE) bnep vsock_loopback vmw_vsock_virtio_transport_common vmw_vsock_vmci_transport vsock snd_seq_midi snd_seq_midi_event sunrpc intel_rapl_msr intel_rapl_common kvm_amd ccp kvm snd_ens1371 snd_ac97_codec snd_rawmidi btusb gameport ac97_bus btrtl btbcm vmw_balloon snd_seq btintel snd_seq_device btmtk snd_pcm bluetooth binfmt_misc irqbypass snd_timer rfkill pcspkr snd soundcore vmw_vmci i2c_piix4 joydev loop zram crct10dif_pclmul crc32_pclmul crc32c_intel polyval_clmulni
 polyval_generic ghash_clmulni_intel vmwgfx sha512_ssse3 mptspi scsi_transport_spi mptscsih e1000 drm_ttm_helper mptbase ttm serio_raw ata_generic pata_acpi ip6_tables ip_tables fuse
CPU: 6 PID: 2629 Comm: Xwayland Tainted: G        W  OE      6.2.15-300.fc38.x86_64 #1
Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 11/12/2020
RIP: 0010:refcount_warn_saturate+0xba/0x110
Code: 01 01 e8 d9 d9 92 ff 0f 0b c3 cc cc cc cc 80 3d 03 a3 ae 01 00 75 85 48 c7 c7 90 a7 8d bb c6 05 f3 a2 ae 01 01 e8 b6 d9 92 ff <0f> 0b c3 cc cc cc cc 80 3d e1 a2 ae 01 00 0f 85 5e ff ff ff 48 c7
RSP: 0018:ffffb7cdc750fd30 EFLAGS: 00010282
RAX: 0000000000000000 RBX: ffffb7cdc750fd58 RCX: 0000000000000000
RDX: 0000000000000002 RSI: 0000000000000027 RDI: 00000000ffffffff
RBP: ffff8b66badb8008 R08: 0000000000000000 R09: ffffb7cdc750fbc0
R10: 0000000000000003 R11: ffff8b687fec2fe8 R12: ffff8b66482613c0
R13: ffff8b664ef80000 R14: ffff8b66ab9170d0 R15: dead000000000100
FS:  0000000000000000(0000) GS:ffff8b6871f80000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f91cdf97000 CR3: 0000000140300000 CR4: 0000000000750ee0
PKRU: 55555554
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x7e/0x90 [vmwgfx]
 ttm_prime_refcount_release+0x3d/0x60 [vmwgfx]
 ttm_release_base+0x85/0xd0 [vmwgfx]
 ttm_ref_object_release+0xb6/0xd0 [vmwgfx]
 ttm_object_file_release+0x39/0x90 [vmwgfx]
 vmw_postclose+0x15/0x20 [vmwgfx]
 drm_file_free.part.0+0x207/0x250
 drm_release+0x64/0xd0
 __fput+0x91/0x250
 task_work_run+0x59/0x90
 do_exit+0x33e/0xb20
 ? handle_mm_fault+0xff/0x2f0
 do_group_exit+0x2d/0x80
 __x64_sys_exit_group+0x14/0x20
 do_syscall_64+0x5c/0x90
 ? exc_page_fault+0x78/0x180
 entry_SYSCALL_64_after_hwframe+0x72/0xdc
RIP: 0033:0x7f96e02fd44d
Code: Unable to access opcode bytes at 0x7f96e02fd423.
RSP: 002b:00007ffd77643b78 EFLAGS: 00000206 ORIG_RAX: 00000000000000e7
RAX: ffffffffffffffda RBX: 00007f96e03f82e8 RCX: 00007f96e02fd44d
RDX: 00000000000000e7 RSI: fffffffffffffd20 RDI: 0000000000000000
RBP: 00007ffd77643bd0 R08: 00007ffd77643b20 R09: 0000000000000000
R10: 00007ffd77643610 R11: 0000000000000206 R12: 0000000000000ab9
R13: 0000000000000000 R14: 0000000000000000 R15: 00007f96e03f8300
 </TASK>
Complete report #711231
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x7e
2
vmw_user_surface_base_release
vmwgfx 0x7e
3
vmw_user_surface_base_release
vmwgfx 0x7e
4
vmw_user_surface_base_release
vmwgfx 0x7e
5
vmw_user_surface_base_release
vmwgfx 0x7e
6
vmw_user_surface_base_release
vmwgfx 0x7e
7
drm_ioctl_kernel
vmlinux 0xc6
8
drm_ioctl_kernel
vmlinux 0xc6
9
drm_ioctl_kernel
vmlinux 0xc6
10
drm_ioctl_kernel
vmlinux 0xc6
11
drm_ioctl_kernel
vmlinux 0xc6
12
drm_ioctl_kernel
vmlinux 0xc6
13
drm_ioctl_kernel
vmlinux 0xc6
14
? drm_ioctl_kernel
vmlinux 0xc6
15
drm_ioctl_kernel
vmlinux 0xc6
WARNING: CPU: 0 PID: 1 at lib/refcount.c:28 refcount_warn_saturate+0xba/0x110
Modules linked in: uinput snd_seq_dummy snd_hrtimer nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 rfkill ip_set nf_tables nfnetlink qrtr vboxsf sunrpc binfmt_misc snd_intel8x0 snd_ac97_codec ac97_bus snd_seq snd_seq_device snd_pcm snd_timer intel_rapl_msr intel_rapl_common snd i2c_piix4 soundcore joydev pcspkr vboxguest loop zram crct10dif_pclmul crc32_pclmul crc32c_intel polyval_clmulni polyval_generic vmwgfx ghash_clmulni_intel e1000 drm_ttm_helper sha512_ssse3 ttm video wmi serio_raw ata_generic pata_acpi ip6_tables ip_tables fuse
CPU: 0 PID: 1 Comm: systemd Not tainted 6.2.15-300.fc38.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:refcount_warn_saturate+0xba/0x110
Code: 01 01 e8 d9 d9 92 ff 0f 0b e9 92 df 79 00 80 3d 03 a3 ae 01 00 75 85 48 c7 c7 90 a7 8d 99 c6 05 f3 a2 ae 01 01 e8 b6 d9 92 ff <0f> 0b e9 6f df 79 00 80 3d e1 a2 ae 01 00 0f 85 5e ff ff ff 48 c7
RSP: 0018:ffffaed840013d90 EFLAGS: 00010282
RAX: 0000000000000000 RBX: ffffaed840013db8 RCX: 0000000000000000
RDX: 0000000000000002 RSI: 0000000000000027 RDI: 00000000ffffffff
RBP: ffff9d38c8d2c008 R08: 0000000000000000 R09: ffffaed840013c20
R10: 0000000000000003 R11: ffffffff9a1447c8 R12: ffff9d38ab5945a0
R13: ffff9d3889bb0000 R14: ffff9d3882e08ed0 R15: dead000000000100
FS:  00007fe861657940(0000) GS:ffff9d3991c00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f14387d1000 CR3: 0000000103296000 CR4: 00000000000506f0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x7e/0x90 [vmwgfx]
 ttm_prime_refcount_release+0x3d/0x60 [vmwgfx]
 ttm_release_base+0x85/0xd0 [vmwgfx]
 ttm_ref_object_release+0xb6/0xd0 [vmwgfx]
 ttm_object_file_release+0x39/0x90 [vmwgfx]
 vmw_postclose+0x15/0x20 [vmwgfx]
 drm_file_free.part.0+0x207/0x250
 drm_release+0x64/0xd0
 __fput+0x91/0x250
 task_work_run+0x59/0x90
 exit_to_user_mode_prepare+0x1de/0x1f0
 syscall_exit_to_user_mode+0x17/0x40
 do_syscall_64+0x68/0x90
 ? __irq_exit_rcu+0x3d/0x140
 entry_SYSCALL_64_after_hwframe+0x72/0xdc
RIP: 0033:0x7fe86192386c
Code: 0f 05 48 3d 00 f0 ff ff 77 3c c3 0f 1f 00 55 48 89 e5 48 83 ec 10 89 7d fc e8 20 72 f8 ff 8b 7d fc 89 c2 b8 03 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 2c 89 d7 89 45 fc e8 82 72 f8 ff 8b 45 fc c9
RSP: 002b:00007ffc6c6e6510 EFLAGS: 00000293 ORIG_RAX: 0000000000000003
RAX: 0000000000000000 RBX: 0000000000000099 RCX: 00007fe86192386c
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000099
RBP: 00007ffc6c6e6520 R08: 000055d2a9730330 R09: 0000000000000071
R10: 0000000000000000 R11: 0000000000000293 R12: 00007fe8616577d0
R13: 0000000000000000 R14: 000055d2a9808497 R15: 000055d2a95ff878
 </TASK>
Complete report #711025
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x7e
2
vmw_user_surface_base_release
vmwgfx 0x7e
3
vmw_user_surface_base_release
vmwgfx 0x7e
4
vmw_user_surface_base_release
vmwgfx 0x7e
5
vmw_user_surface_base_release
vmwgfx 0x7e
6
vmw_user_surface_base_release
vmwgfx 0x7e
7
drm_ioctl_kernel
vmlinux 0xc6
8
drm_ioctl_kernel
vmlinux 0xc6
9
drm_ioctl_kernel
vmlinux 0xc6
10
drm_ioctl_kernel
vmlinux 0xc6
11
drm_ioctl_kernel
vmlinux 0xc6
12
? drm_ioctl_kernel
vmlinux 0xc6
13
drm_ioctl_kernel
vmlinux 0xc6
14
drm_ioctl_kernel
vmlinux 0xc6
15
drm_ioctl_kernel
vmlinux 0xc6
16
? drm_ioctl_kernel
vmlinux 0xc6
17
drm_ioctl_kernel
vmlinux 0xc6
WARNING: CPU: 1 PID: 2128 at lib/refcount.c:28 refcount_warn_saturate+0xba/0x110
Modules linked in: xfs uinput isofs snd_seq_dummy snd_hrtimer nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc binfmt_misc snd_intel8x0 vfat snd_ac97_codec fat ac97_bus snd_seq snd_seq_device intel_rapl_msr snd_pcm intel_rapl_common snd_timer rapl i2c_piix4 pcspkr joydev snd soundcore vboxguest loop zram crct10dif_pclmul crc32_pclmul crc32c_intel polyval_clmulni polyval_generic ghash_clmulni_intel sha512_ssse3 vmwgfx video drm_ttm_helper e1000 wmi ttm serio_raw ip6_tables ip_tables fuse
CPU: 1 PID: 2128 Comm: Xwayland Tainted: G        W          6.2.15-300.fc38.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:refcount_warn_saturate+0xba/0x110
Code: 01 01 e8 d9 d9 92 ff 0f 0b c3 cc cc cc cc 80 3d 03 a3 ae 01 00 75 85 48 c7 c7 90 a7 8d 92 c6 05 f3 a2 ae 01 01 e8 b6 d9 92 ff <0f> 0b c3 cc cc cc cc 80 3d e1 a2 ae 01 00 0f 85 5e ff ff ff 48 c7
RSP: 0018:ffffa54902d73d30 EFLAGS: 00010282
RAX: 0000000000000000 RBX: ffffa54902d73d58 RCX: 0000000000000000
RDX: 0000000000000002 RSI: 0000000000000027 RDI: 00000000ffffffff
RBP: ffff8d4ed3420008 R08: 0000000000000000 R09: ffffa54902d73bc0
R10: 0000000000000003 R11: ffffffff931447c8 R12: ffff8d4e885f7c00
R13: ffff8d4ef6090000 R14: ffff8d4ecd3968d0 R15: dead000000000100
FS:  0000000000000000(0000) GS:ffff8d4efd100000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f1009313af4 CR3: 000000004d0bc003 CR4: 00000000000706e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x7e/0x90 [vmwgfx]
 ttm_prime_refcount_release+0x3d/0x60 [vmwgfx]
 ttm_release_base+0x85/0xd0 [vmwgfx]
 ttm_ref_object_release+0xb6/0xd0 [vmwgfx]
 ttm_object_file_release+0x39/0x90 [vmwgfx]
 vmw_postclose+0x15/0x20 [vmwgfx]
 drm_file_free.part.0+0x207/0x250
 drm_release+0x64/0xd0
 __fput+0x91/0x250
 task_work_run+0x59/0x90
 do_exit+0x33e/0xb20
 ? handle_mm_fault+0xff/0x2f0
 do_group_exit+0x2d/0x80
 __x64_sys_exit_group+0x14/0x20
 do_syscall_64+0x5c/0x90
 ? exc_page_fault+0x78/0x180
 entry_SYSCALL_64_after_hwframe+0x72/0xdc
RIP: 0033:0x7f6724a4644d
Code: Unable to access opcode bytes at 0x7f6724a46423.
RSP: 002b:00007fffe102a588 EFLAGS: 00000202 ORIG_RAX: 00000000000000e7
RAX: ffffffffffffffda RBX: 00007f6724b412e8 RCX: 00007f6724a4644d
RDX: 00000000000000e7 RSI: fffffffffffffd20 RDI: 0000000000000001
RBP: 00007fffe102a5e0 R08: 00007fffe102a530 R09: 0000000000000000
R10: 00007fffe102a020 R11: 0000000000000202 R12: 0000000000000ab9
R13: 0000000000000000 R14: 0000000000000001 R15: 00007f6724b41300
 </TASK>
Complete report #710474
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x7e
2
vmw_user_surface_base_release
vmwgfx 0x7e
3
vmw_user_surface_base_release
vmwgfx 0x7e
4
vmw_user_surface_base_release
vmwgfx 0x7e
5
vmw_user_surface_base_release
vmwgfx 0x7e
6
? vmw_user_surface_base_release
vmwgfx 0x7e
7
drm_ioctl_kernel
vmlinux 0xc6
8
drm_ioctl_kernel
vmlinux 0xc6
9
? vmw_user_surface_base_release
vmwgfx 0x7e
10
? drm_ioctl_kernel
vmlinux 0xc6
11
vmw_user_surface_base_release
vmwgfx 0x7e
12
drm_ioctl_kernel
vmlinux 0xc6
13
drm_ioctl_kernel
vmlinux 0xc6
14
? drm_ioctl_kernel
vmlinux 0xc6
15
drm_ioctl_kernel
vmlinux 0xc6
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#2] PREEMPT SMP PTI
CPU: 1 PID: 1225 Comm: gnome-shell Tainted: G      D    OE      6.2.15-300.fc38.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x30
Code: 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 0f 1f 44 00 00 48 8b 87 30 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 e7 8b 51 00 cc 0f 0b c3 cc cc cc cc 66
RSP: 0018:ffffc17602be3cb8 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffc17602be3ce0 RCX: 0000000000000000
RDX: ffff9bfe9eeaee00 RSI: ffff9bfe8b7c390a RDI: ffff9bfe9aac9200
RBP: ffff9bfeb4454008 R08: ffff9bfe8b7c39a0 R09: ffff9bff87e32bb8
R10: ffffc17602be3cc0 R11: ffffc17602be3cc8 R12: ffff9bff87e79780
R13: ffffc17602be3dd0 R14: ffff9bfe81336200 R15: 0000000000000008
FS:  00007fbeae42b600(0000) GS:ffff9bff9bc80000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 0000000001234005 CR4: 00000000000706e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x85/0x90 [vmwgfx]
 ttm_prime_refcount_release+0x3d/0x60 [vmwgfx]
 ttm_release_base+0x85/0xd0 [vmwgfx]
 ttm_ref_object_release+0xb6/0xd0 [vmwgfx]
 ttm_ref_object_base_unref+0x76/0xa0 [vmwgfx]
 ? __pfx_vmw_surface_destroy_ioctl+0x10/0x10 [vmwgfx]
 drm_ioctl_kernel+0xc9/0x170
 drm_ioctl+0x235/0x410
 ? __pfx_vmw_surface_destroy_ioctl+0x10/0x10 [vmwgfx]
 ? __pfx_drm_ioctl+0x10/0x10
 vmw_generic_ioctl+0xa7/0x110 [vmwgfx]
 __x64_sys_ioctl+0x90/0xd0
 do_syscall_64+0x5c/0x90
 ? __irq_exit_rcu+0x3d/0x140
 entry_SYSCALL_64_after_hwframe+0x72/0xdc
RIP: 0033:0x7fbeb3928edd
Code: 04 25 28 00 00 00 48 89 45 c8 31 c0 48 8d 45 10 c7 45 b0 10 00 00 00 48 89 45 b8 48 8d 45 d0 48 89 45 c0 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 1a 48 8b 45 c8 64 48 2b 04 25 28 00 00 00
RSP: 002b:00007ffdcf6c8190 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007fbeb3928edd
RDX: 00007ffdcf6c8230 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007ffdcf6c81e0 R08: 0000000000000001 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 00007ffdcf6c8230
R13: 000000004008644a R14: 000000000000000c R15: 00005627e508fc80
 </TASK>
Modules linked in: uvcvideo videobuf2_vmalloc videobuf2_memops videobuf2_v4l2 videobuf2_common videodev mc uinput isofs snd_seq_dummy snd_hrtimer vboxvideo drm_vram_helper nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc snd_intel8x0 snd_ac97_codec binfmt_misc ac97_bus intel_rapl_msr intel_rapl_common snd_seq rapl snd_seq_device snd_pcm snd_timer snd pcspkr soundcore i2c_piix4 joydev loop zram crct10dif_pclmul crc32_pclmul crc32c_intel polyval_clmulni polyval_generic vmwgfx ghash_clmulni_intel sha512_ssse3 video wmi e1000 drm_ttm_helper vboxguest(OE) ttm serio_raw ata_generic pata_acpi ip6_tables ip_tables fuse
CR2: 0000000000000000
Complete report #710342
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x7e
2
vmw_user_surface_base_release
vmwgfx 0x7e
3
? vmw_user_surface_base_release
vmwgfx 0x7e
4
vmw_user_surface_base_release
vmwgfx 0x7e
5
? vmw_user_surface_base_release
vmwgfx 0x7e
6
vmw_user_surface_base_release
vmwgfx 0x7e
7
? vmw_user_surface_base_release
vmwgfx 0x7e
8
drm_ioctl_kernel
vmlinux 0xc6
9
drm_ioctl_kernel
vmlinux 0xc6
10
? vmw_user_surface_base_release
vmwgfx 0x7e
11
? drm_ioctl_kernel
vmlinux 0xc6
12
vmw_user_surface_base_release
vmwgfx 0x7e
13
drm_ioctl_kernel
vmlinux 0xc6
14
drm_ioctl_kernel
vmlinux 0xc6
15
? drm_ioctl_kernel
vmlinux 0xc6
16
? drm_ioctl_kernel
vmlinux 0xc6
17
drm_ioctl_kernel
vmlinux 0xc6
general protection fault, probably for non-canonical address 0x4991f0951101d: 0000 [#2] PREEMPT SMP PTI
CPU: 0 PID: 1670 Comm: gnome-shell Tainted: G      D W          6.2.15-300.fc38.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:vmw_validation_add_resource+0x17f/0x270 [vmwgfx]
Code: 10 48 89 32 48 85 c0 74 04 48 89 70 08 48 89 ef e8 06 4f fe ff 48 89 43 28 48 85 c0 0f 84 cf 00 00 00 80 4b 40 04 48 8b 45 08 <80> b8 1d 10 00 00 00 74 16 48 89 ef e8 30 63 fe ff 83 f8 04 74 40
RSP: 0018:ffffae6583383a60 EFLAGS: 00010202
RAX: 0004991f09510000 RBX: ffff991f07b02538 RCX: 0000000000000002
RDX: 0000000000000003 RSI: ffff991f07b02548 RDI: ffff991f030efc10
RBP: ffff991f030efc10 R08: ffffae6583383ac0 R09: 0000000000000000
R10: 0000000000000006 R11: 0000000000000000 R12: 0000000000000000
R13: ffffae6583383ac0 R14: ffffae6583383bf8 R15: 0000000000000000
FS:  00007f2b38e50600(0000) GS:ffff991f1bc00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f3c9f8202a6 CR3: 0000000028866004 CR4: 00000000000706f0
Call Trace:
 <TASK>
 vmw_execbuf_res_val_add+0x1f0/0x4a0 [vmwgfx]
 vmw_execbuf_res_val_add+0x1cd/0x4a0 [vmwgfx]
 ? __pfx_vmw_execbuf_ioctl+0x10/0x10 [vmwgfx]
 vmw_execbuf_process+0x438/0x1160 [vmwgfx]
 ? __pfx_vmw_execbuf_ioctl+0x10/0x10 [vmwgfx]
 vmw_execbuf_ioctl+0x151/0x280 [vmwgfx]
 ? __pfx_vmw_execbuf_ioctl+0x10/0x10 [vmwgfx]
 drm_ioctl_kernel+0xc9/0x170
 drm_ioctl+0x235/0x410
 ? __pfx_vmw_execbuf_ioctl+0x10/0x10 [vmwgfx]
 ? __pfx_drm_ioctl+0x10/0x10
 vmw_generic_ioctl+0xa7/0x110 [vmwgfx]
 __x64_sys_ioctl+0x90/0xd0
 do_syscall_64+0x5c/0x90
 ? sched_clock_cpu+0xb/0xc0
 ? __irq_exit_rcu+0x3d/0x140
 entry_SYSCALL_64_after_hwframe+0x72/0xdc
RIP: 0033:0x7f2b3e328edd
Code: 04 25 28 00 00 00 48 89 45 c8 31 c0 48 8d 45 10 c7 45 b0 10 00 00 00 48 89 45 b8 48 8d 45 d0 48 89 45 c0 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 1a 48 8b 45 c8 64 48 2b 04 25 28 00 00 00
RSP: 002b:00007ffc45584230 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000028 RCX: 00007f2b3e328edd
RDX: 00007ffc455842f0 RSI: 000000004028644c RDI: 000000000000000c
RBP: 00007ffc45584280 R08: 0000000000000058 R09: 00007ffc45584388
R10: 0000000000000143 R11: 0000000000000246 R12: 00007ffc455842f0
R13: 000000004028644c R14: 000000000000000c R15: 00007ffc45584388
 </TASK>
Modules linked in: uinput snd_seq_dummy snd_hrtimer nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 rfkill ip_set nf_tables nfnetlink qrtr snd_intel8x0 snd_ac97_codec ac97_bus snd_seq intel_rapl_msr snd_seq_device intel_rapl_common snd_pcm intel_powerclamp rapl sunrpc snd_timer snd binfmt_misc pcspkr vboxguest i2c_piix4 soundcore joydev loop zram crct10dif_pclmul crc32_pclmul crc32c_intel vmwgfx polyval_clmulni polyval_generic ghash_clmulni_intel drm_ttm_helper sha512_ssse3 video e1000 ttm wmi serio_raw ata_generic pata_acpi ip6_tables ip_tables fuse
Complete report #709852
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x7e
2
vmw_user_surface_base_release
vmwgfx 0x7e
3
vmw_user_surface_base_release
vmwgfx 0x7e
4
vmw_user_surface_base_release
vmwgfx 0x7e
5
vmw_user_surface_base_release
vmwgfx 0x7e
6
vmw_user_surface_base_release
vmwgfx 0x7e
7
drm_ioctl_kernel
vmlinux 0xc6
8
drm_ioctl_kernel
vmlinux 0xc6
9
drm_ioctl_kernel
vmlinux 0xc6
10
drm_ioctl_kernel
vmlinux 0xc6
11
drm_ioctl_kernel
vmlinux 0xc6
12
drm_ioctl_kernel
vmlinux 0xc6
13
drm_ioctl_kernel
vmlinux 0xc6
14
? drm_ioctl_kernel
vmlinux 0xc6
15
? drm_ioctl_kernel
vmlinux 0xc6
16
drm_ioctl_kernel
vmlinux 0xc6
WARNING: CPU: 0 PID: 11064 at lib/refcount.c:28 refcount_warn_saturate+0xba/0x110
Modules linked in: uinput isofs snd_seq_dummy snd_hrtimer nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr snd_intel8x0 snd_ac97_codec ac97_bus snd_seq snd_seq_device intel_rapl_msr snd_pcm intel_rapl_common snd_timer sunrpc binfmt_misc rapl snd soundcore joydev vboxguest i2c_piix4 pcspkr loop zram vmwgfx crct10dif_pclmul crc32_pclmul crc32c_intel polyval_clmulni polyval_generic e1000 drm_ttm_helper video ghash_clmulni_intel sha512_ssse3 ttm wmi serio_raw ata_generic pata_acpi ip6_tables ip_tables fuse [last unloaded: vboxsf]
CPU: 0 PID: 11064 Comm: pingsender Not tainted 6.2.15-300.fc38.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:refcount_warn_saturate+0xba/0x110
Code: 01 01 e8 d9 d9 92 ff 0f 0b c3 cc cc cc cc 80 3d 03 a3 ae 01 00 75 85 48 c7 c7 90 a7 8d 95 c6 05 f3 a2 ae 01 01 e8 b6 d9 92 ff <0f> 0b c3 cc cc cc cc 80 3d e1 a2 ae 01 00 0f 85 5e ff ff ff 48 c7
RSP: 0018:ffffb3bb8aa8bd38 EFLAGS: 00010282
RAX: 0000000000000000 RBX: ffffb3bb8aa8bd60 RCX: 0000000000000000
RDX: 0000000000000002 RSI: 0000000000000027 RDI: 00000000ffffffff
RBP: ffff9d1af8538008 R08: 0000000000000000 R09: ffffb3bb8aa8bbc8
R10: 0000000000000003 R11: ffffffff961447c8 R12: ffff9d1af857f4e0
R13: ffff9d1a09fe0000 R14: ffff9d1b049722d0 R15: dead000000000100
FS:  0000000000000000(0000) GS:ffff9d1b56600000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007ffcd6fc39c9 CR3: 00000001fcef6001 CR4: 00000000000706f0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x7e/0x90 [vmwgfx]
 ttm_prime_refcount_release+0x3d/0x60 [vmwgfx]
 ttm_release_base+0x85/0xd0 [vmwgfx]
 ttm_ref_object_release+0xb6/0xd0 [vmwgfx]
 ttm_object_file_release+0x39/0x90 [vmwgfx]
 vmw_postclose+0x15/0x20 [vmwgfx]
 drm_file_free.part.0+0x207/0x250
 drm_release+0x64/0xd0
 __fput+0x91/0x250
 task_work_run+0x59/0x90
 exit_to_user_mode_prepare+0x1de/0x1f0
 syscall_exit_to_user_mode+0x17/0x40
 do_syscall_64+0x68/0x90
 ? do_user_addr_fault+0x1ef/0x710
 ? exc_page_fault+0x78/0x180
 entry_SYSCALL_64_after_hwframe+0x72/0xdc
RIP: 0033:0x7f76dead33b0
Code: Unable to access opcode bytes at 0x7f76dead3386.
RSP: 002b:00007ffcd6fc35c0 EFLAGS: 00000200 ORIG_RAX: 000000000000003b
RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000000
R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
 </TASK>
Complete report #637861
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
vmw_user_surface_base_release
vmwgfx 0x5d
7
? vmw_user_surface_base_release
vmwgfx 0x5d
8
vmw_user_surface_base_release
vmwgfx 0x5d
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
drm_ioctl_kernel
vmlinux 0x9e
11
drm_ioctl_kernel
vmlinux 0x9e
12
? vmw_user_surface_base_release
vmwgfx 0x5d
13
? drm_ioctl_kernel
vmlinux 0x9e
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
WARNING: CPU: 1 PID: 1454 at drivers/gpu/drm/vmwgfx/vmwgfx_cmdbuf.c:410 vmw_cmdbuf_ctx_process+0x20b/0x260 [vmwgfx]
Modules linked in: tls uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set nf_tables nfnetlink rfkill qrtr sunrpc intel_rapl_msr snd_intel8x0 intel_rapl_common snd_ac97_codec ac97_bus snd_seq snd_seq_device snd_pcm rapl joydev snd_timer pcspkr snd e1000 soundcore vboxguest i2c_piix4 zram crct10dif_pclmul crc32_pclmul vmwgfx crc32c_intel ghash_clmulni_intel serio_raw video ata_generic drm_ttm_helper ttm pata_acpi ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CPU: 1 PID: 1454 Comm: gnome-shell Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:vmw_cmdbuf_ctx_process+0x20b/0x260 [vmwgfx]
Code: e8 ea fb ff ff e9 f3 fe ff ff 80 3d 93 4d 03 00 00 0f 85 6f ff ff ff 48 c7 c7 0a 10 3e c0 c6 05 7f 4d 03 00 01 e8 1e 8c 8d e0 <0f> 0b 4c 89 f7 e8 bb fb ff ff e9 c4 fe ff ff 4c 8b 74 24 28 4c 89
RSP: 0018:ffffb94fc33fbad8 EFLAGS: 00010296
RAX: 000000000000001c RBX: ffff9da786138400 RCX: 0000000000000000
RDX: 0000000000000002 RSI: ffffffffa1665ad5 RDI: 00000000ffffffff
RBP: 0000000000000004 R08: 0000000000000000 R09: ffffb94fc33fb918
R10: ffffb94fc33fb910 R11: 0000000000000003 R12: ffff9da7a924c400
R13: ffff9da7a924ce18 R14: ffff9da7a924ce00 R15: ffff9da786138488
FS:  00007f5d56030600(0000) GS:ffff9da7fdd00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00005613bbaf9922 CR3: 00000000398a4001 CR4: 00000000000706e0
Call Trace:
 <TASK>
 vmw_cmdbuf_man_process+0x45/0xe0 [vmwgfx]
 __vmw_cmdbuf_cur_flush+0xad/0xf0 [vmwgfx]
 vmw_cmdbuf_reserve+0xaf/0x170 [vmwgfx]
 vmw_cmd_send_fence+0x31/0x160 [vmwgfx]
 vmw_execbuf_fence_commands+0x40/0xd0 [vmwgfx]
 vmw_execbuf_process+0x7d0/0x1130 [vmwgfx]
 ? vmw_execbuf_release_pinned_bo+0x50/0x50 [vmwgfx]
 vmw_execbuf_ioctl+0x140/0x270 [vmwgfx]
 ? vmw_execbuf_release_pinned_bo+0x50/0x50 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_execbuf_release_pinned_bo+0x50/0x50 [vmwgfx]
 ? __rseq_handle_notify_resume+0x93/0x440
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f5d5b627a3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffc887b65f0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000560375e02130 RCX: 00007f5d5b627a3f
RDX: 00007ffc887b66b0 RSI: 000000004028644c RDI: 000000000000000a
RBP: 00007ffc887b66b0 R08: 00000000000001fc R09: 00007ffc887b6738
R10: 00000000693d9274 R11: 0000000000000246 R12: 000000004028644c
R13: 000000000000000a R14: 0000000000000001 R15: 00007ffc887b6738
 </TASK>
Complete report #633862
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? drm_ioctl_kernel
vmlinux 0x9e
7
? drm_ioctl_kernel
vmlinux 0x9e
8
? vmw_user_surface_base_release
vmwgfx 0x5d
9
vmw_user_surface_base_release
vmwgfx 0x5d
10
? vmw_user_surface_base_release
vmwgfx 0x5d
11
drm_ioctl_kernel
vmlinux 0x9e
12
drm_ioctl_kernel
vmlinux 0x9e
13
? vmw_user_surface_base_release
vmwgfx 0x5d
14
? drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
17
drm_ioctl_kernel
vmlinux 0x9e
BUG: unable to handle page fault for address: 000000000000f010
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP NOPTI
CPU: 1 PID: 2612 Comm: gnome-control-c Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:vmwgfx_ht_find_item+0x29/0x50 [vmwgfx]
Code: 00 0f 1f 44 00 00 48 b8 eb 83 b5 80 46 86 c8 61 b9 40 00 00 00 2a 4f 08 48 0f af c6 48 d3 e8 48 8b 0f 89 c0 48 8d 04 c1 eb 08 <48> 3b 70 10 74 11 72 08 48 8b 00 48 85 c0 75 f0 b8 ea ff ff ff c3
RSP: 0018:ffffae1904ad7b60 EFLAGS: 00010206
RAX: 000000000000f000 RBX: ffffae1904ad7ca0 RCX: ffffae19035d4000
RDX: ffffae1904ad7b68 RSI: ffff8d5ec1aaa400 RDI: ffff8d5f821031a0
RBP: 0000000000000000 R08: ffff8d5eb39ca318 R09: ffff8d5eb50d0640
R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000001
R13: ffff8d5ec1aaa400 R14: ffffae1904ad7bf0 R15: 0000000000000018
FS:  00007f125d64d540(0000) GS:ffff8d5f9bd00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000000000000f010 CR3: 0000000034b70000 CR4: 00000000000506e0
Call Trace:
 <TASK>
 vmw_validation_find_bo_dup+0x23/0x70 [vmwgfx]
 vmw_validation_add_bo+0x23/0x180 [vmwgfx]
 vmw_translate_mob_ptr.constprop.0+0x5f/0x100 [vmwgfx]
 vmw_cmd_res_switch_backup.isra.0+0x74/0xb0 [vmwgfx]
 vmw_execbuf_process+0x4ff/0x1130 [vmwgfx]
 ? preempt_count_add+0x64/0x90
 ? __get_locked_pte+0xcf/0x110
 ? vmw_execbuf_release_pinned_bo+0x50/0x50 [vmwgfx]
 vmw_execbuf_ioctl+0x140/0x270 [vmwgfx]
 ? vmw_execbuf_release_pinned_bo+0x50/0x50 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_execbuf_release_pinned_bo+0x50/0x50 [vmwgfx]
 ? handle_mm_fault+0xae/0x280
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f12626b5a3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffd2779ac90 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 00005617afe19c80 RCX: 00007f12626b5a3f
RDX: 00007ffd2779ad50 RSI: 000000004028644c RDI: 000000000000001e
RBP: 00007ffd2779ad50 R08: 00000000000035f0 R09: 00007ffd2779add8
R10: 000000001d52dfe0 R11: 0000000000000246 R12: 000000004028644c
R13: 000000000000001e R14: 0000000000000006 R15: 00007ffd2779add8
 </TASK>
Modules linked in: tls uinput isofs snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set nf_tables nfnetlink rfkill qrtr sunrpc snd_hda_codec_idt snd_hda_codec_generic ledtrig_audio snd_hda_intel snd_intel_dspcfg snd_intel_sdw_acpi snd_hda_codec snd_hda_core intel_rapl_msr intel_rapl_common snd_hwdep snd_seq snd_seq_device snd_pcm kvm_amd snd_timer ccp snd kvm joydev soundcore vboxguest e1000 irqbypass pcspkr i2c_piix4 zram crct10dif_pclmul crc32_pclmul crc32c_intel ghash_clmulni_intel vmwgfx serio_raw drm_ttm_helper ttm ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 000000000000f010
Complete report #435332
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
drm_ioctl_kernel
vmlinux 0x9e
10
drm_ioctl_kernel
vmlinux 0x9e
11
drm_ioctl_kernel
vmlinux 0x9e
12
drm_ioctl_kernel
vmlinux 0x9e
13
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#2] PREEMPT SMP PTI
CPU: 0 PID: 3871 Comm: Xwayland Tainted: G      D W         5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffad48c4eabd98 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffad48c4eabdb8 RCX: 0000000000000001
RDX: ffff8ebf30706278 RSI: ffff8ebf5ef74b6a RDI: ffff8ec007fadc00
RBP: ffff8ebf03f82bc8 R08: ffff8ebf5ef74c88 R09: ffff8ec006f59150
R10: 0000000000000003 R11: ffff8ebf5ef74b68 R12: ffff8ebf306ecc00
R13: ffff8ec007a24000 R14: ffff8ebf26b7c2d0 R15: dead000000000100
FS:  0000000000000000(0000) GS:ffff8ec099c00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 000000003ce10006 CR4: 00000000000706f0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_object_file_release+0x39/0x90 [vmwgfx]
 vmw_postclose+0x15/0x20 [vmwgfx]
 drm_file_free.part.0+0x204/0x250
 drm_release+0x65/0x110
 __fput+0x91/0x250
 task_work_run+0x5c/0x90
 do_exit+0x31d/0xad0
 make_task_dead+0x51/0x60
 rewind_stack_and_make_dead+0x17/0x17
RIP: 0033:0x7f6ae18a91bf
Code: Unable to access opcode bytes at RIP 0x7f6ae18a9195.
RSP: 002b:00007ffe1ad87800 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f6ae18a91bf
RDX: 00007ffe1ad878a0 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007ffe1ad878a0 R08: 0000560d1477ddf0 R09: 0000000000000000
R10: 00000000ffffff9d R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 0000560d14797e30 R15: 0000560d147979e0
 </TASK>
Modules linked in: tls uinput isofs snd_seq_dummy snd_hrtimer nls_utf8 cifs cifs_arc4 cifs_md4 dns_resolver fscache netfs vboxvideo drm_vram_helper nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr vboxsf sunrpc binfmt_misc vfat fat snd_intel8x0 snd_ac97_codec ac97_bus snd_seq snd_seq_device snd_pcm intel_rapl_msr intel_rapl_common rapl snd_timer pcspkr joydev snd soundcore i2c_piix4 vboxguest zram mptsas scsi_transport_sas nvme nvme_core mptspi scsi_transport_spi crct10dif_pclmul crc32_pclmul mptscsih crc32c_intel vmwgfx mptbase ghash_clmulni_intel virtio_scsi serio_raw hid_multitouch e1000 drm_ttm_helper ttm ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #574323
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
? drm_ioctl_kernel
vmlinux 0x9e
14
vmw_user_surface_base_release
vmwgfx 0x5d
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
17
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#3] PREEMPT SMP PTI
CPU: 0 PID: 1682 Comm: gnome-shell Tainted: G      D W         5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffb35804d63d10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffb35804d63d30 RCX: 0000000000000001
RDX: ffff9336dbaaf478 RSI: ffff9336df39ada2 RDI: ffff9337b803e400
RBP: ffff9335c79e8ec8 R08: ffff9336df39aea0 R09: ffff9335c5e51ed0
R10: 0000000000000021 R11: ffff9336df39ada0 R12: ffff93378431d2a0
R13: ffffb35804d63e18 R14: ffff9335e1376c00 R15: ffff9335e1376c00
FS:  00007f11e02e0600(0000) GS:ffff9338cfc00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 0000000121fb0005 CR4: 00000000000706f0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? dentry_lru_isolate+0x5a/0x100
 ? __rseq_handle_notify_resume+0x93/0x440
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f11e58d7a3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffe77ac7e40 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f11e58d7a3f
RDX: 00007ffe77ac7ee0 RSI: 000000004008644a RDI: 000000000000000d
RBP: 00007ffe77ac7ee0 R08: 0000561b72b99c80 R09: 0000561b70cc1670
R10: 0000561b709fa080 R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000d R14: 0000561b7156a470 R15: 0000561b7156a020
 </TASK>
Modules linked in: tls vboxsf uinput isofs snd_seq_dummy snd_hrtimer vboxvideo drm_vram_helper nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc intel_rapl_msr intel_rapl_common rapl joydev snd_intel8x0 snd_ac97_codec ac97_bus snd_seq pcspkr snd_seq_device snd_pcm snd_timer i2c_piix4 e1000 snd vboxguest soundcore zram crct10dif_pclmul crc32_pclmul crc32c_intel ghash_clmulni_intel vmwgfx serio_raw drm_ttm_helper ttm ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #533216
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
vmw_user_surface_base_release
vmwgfx 0x5d
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#3] PREEMPT SMP PTI
CPU: 3 PID: 2161 Comm: Xwayland Tainted: G      D W    L    5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffb95c8405bd10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffb95c8405bd30 RCX: 0000000000000001
RDX: ffff907aa43a2878 RSI: ffff907a5d75dff2 RDI: ffff907aac799800
RBP: ffff907a4459b248 R08: ffff907a5d75e060 R09: ffff907a463f1a50
R10: 0000000000000000 R11: ffff907a5d75dff0 R12: ffff907aa40f5ba0
R13: ffffb95c8405be18 R14: ffff907a9a23b000 R15: ffff907a9a23b000
FS:  00007f9533deee80(0000) GS:ffff907b04980000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 00000000534e8003 CR4: 00000000000706e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? __schedule+0x28b/0x1230
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f9534a6da3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffc111c2db0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f9534a6da3f
RDX: 00007ffc111c2e50 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007ffc111c2e50 R08: 0000563b6b629c50 R09: 0000000000000000
R10: 00000000ffffff9d R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 0000563b6b62b490 R15: 0000563b6b62b040
 </TASK>
Modules linked in: tls uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc intel_rapl_msr intel_rapl_common rapl joydev snd_intel8x0 snd_ac97_codec ac97_bus snd_seq snd_seq_device pcspkr snd_pcm snd_timer snd e1000 vboxguest soundcore i2c_piix4 zram crct10dif_pclmul crc32_pclmul crc32c_intel vmwgfx ghash_clmulni_intel drm_ttm_helper serio_raw ttm ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #529612
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
? drm_ioctl_kernel
vmlinux 0x9e
14
vmw_user_surface_base_release
vmwgfx 0x5d
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
17
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#2] PREEMPT SMP NOPTI
CPU: 2 PID: 2137 Comm: Xwayland Tainted: G      D W         5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 ff e0 0f 1f 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffb2450558fd10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffb2450558fd30 RCX: 0000000000000001
RDX: ffff981122034278 RSI: ffff9810c105f47a RDI: ffff9810f9efb000
RBP: ffff9810e791e308 R08: ffff9810c105f4a8 R09: ffff981085f82750
R10: 0000000000000002 R11: ffff9810c105f478 R12: ffff981096a92540
R13: ffffb2450558fe18 R14: ffff9810e594d600 R15: ffff9810e594d600
FS:  00007fc81ac50e80(0000) GS:ffff981197d00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 0000000165936001 CR4: 00000000000306e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2c/0x40 [vmwgfx]
 ttm_release_base+0x71/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9b/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? __rseq_handle_notify_resume+0x93/0x440
 ? call_rcu+0xff/0x690
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8c/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8a/0xc0
 do_syscall_64+0x37/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7fc81b8cfa3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffc86b3c9f0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007fc81b8cfa3f
RDX: 00007ffc86b3ca90 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007ffc86b3ca90 R08: 0000000000000030 R09: 0000000000000031
R10: 0000000000000031 R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 000055e04a358b40 R15: 0000000000000000
 </TASK>
Modules linked in: tls uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc intel_rapl_msr intel_rapl_common rapl snd_intel8x0 snd_ac97_codec ac97_bus snd_seq joydev snd_seq_device snd_pcm snd_timer snd e1000 vboxguest i2c_piix4 soundcore pcspkr zram vmwgfx crc32c_intel drm_ttm_helper ttm serio_raw video ata_generic pata_acpi ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #412831
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
drm_ioctl_kernel
vmlinux 0x9e
10
drm_ioctl_kernel
vmlinux 0x9e
11
drm_ioctl_kernel
vmlinux 0x9e
12
drm_ioctl_kernel
vmlinux 0x9e
13
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#2] PREEMPT SMP NOPTI
CPU: 3 PID: 1961 Comm: Xwayland Tainted: G      D           5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffb11d852abd98 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffb11d852abdb8 RCX: 0000000000000001
RDX: ffff93a0fd76a878 RSI: ffff93a0ee87bd9a RDI: ffff93a0c47a7800
RBP: ffff93a0fd66b988 R08: ffff93a0ee87bee0 R09: ffff93a0c51bfc90
R10: 0000000000000002 R11: ffff93a0ee87bd98 R12: ffff93a0c45cba80
R13: ffff93a0c1b40000 R14: ffff93a0fd58bed0 R15: dead000000000100
FS:  00007f14c9eafe80(0000) GS:ffff93a1d7d80000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 0000000123274000 CR4: 00000000000406e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_object_file_release+0x39/0x90 [vmwgfx]
 vmw_postclose+0x15/0x20 [vmwgfx]
 drm_file_free.part.0+0x204/0x250
 drm_release+0x65/0x110
 __fput+0x91/0x250
 task_work_run+0x5c/0x90
 do_exit+0x31d/0xad0
 make_task_dead+0x51/0x60
 rewind_stack_and_make_dead+0x17/0x17
RIP: 0033:0x7f14c96961bf
Code: Unable to access opcode bytes at RIP 0x7f14c9696195.
RSP: 002b:00007fffa9893620 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f14c96961bf
RDX: 00007fffa98936c0 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007fffa98936c0 R08: 0000563dadf2dd80 R09: 0000000000000000
R10: 00000000ffffff9d R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 0000563dadf2f6f0 R15: 0000563dadf2f2a0
 </TASK>
Modules linked in: snd_seq_midi snd_seq_midi_event snd_usb_audio snd_usbmidi_lib snd_hwdep snd_rawmidi mc tls uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 rfkill ip_set nf_tables nfnetlink qrtr sunrpc vboxsf snd_intel8x0 joydev snd_ac97_codec ac97_bus snd_seq snd_seq_device snd_pcm snd_timer e1000 vboxguest snd soundcore pcspkr i2c_piix4 zram crct10dif_pclmul crc32_pclmul crc32c_intel ghash_clmulni_intel vmwgfx serio_raw drm_ttm_helper ttm ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #527083
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
vmw_user_surface_base_release
vmwgfx 0x5d
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#2] PREEMPT SMP NOPTI
CPU: 2 PID: 2105 Comm: Xwayland Tainted: G      D           5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffb4d1c55abd10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffb4d1c55abd30 RCX: 0000000000000001
RDX: ffff8cbf7b924c78 RSI: ffff8cbf80bf2da2 RDI: ffff8cbf42be1400
RBP: ffff8cbf7bbdbe48 R08: ffff8cbf80bf2f68 R09: ffff8cbf46d77750
R10: 0000000000000002 R11: ffff8cbf80bf2da0 R12: ffff8cbf7b778420
R13: ffffb4d1c55abe18 R14: ffff8cbf9afb7e00 R15: ffff8cbf9afb7e00
FS:  00007fcd9c144e80(0000) GS:ffff8cc153d00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 00000001650e2000 CR4: 00000000000506e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? __rseq_handle_notify_resume+0x93/0x440
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7fcd9cdc3a3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffd83ee1600 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007fcd9cdc3a3f
RDX: 00007ffd83ee16a0 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007ffd83ee16a0 R08: 0000560d034bd8a0 R09: 0000000000000000
R10: 00000000ffffff9d R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 0000560d034da360 R15: 0000560d034d9f10
 </TASK>
Modules linked in: isofs tls uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 rfkill ip_set nf_tables nfnetlink qrtr sunrpc intel_rapl_msr intel_rapl_common snd_intel8x0 joydev snd_ac97_codec ac97_bus snd_seq i2c_piix4 snd_seq_device snd_pcm pcspkr e1000 snd_timer vboxguest snd soundcore zram crct10dif_pclmul crc32_pclmul crc32c_intel ghash_clmulni_intel vmwgfx serio_raw drm_ttm_helper ttm ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #525045
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
vmw_user_surface_base_release
vmwgfx 0x5d
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP NOPTI
CPU: 3 PID: 2034 Comm: Xwayland Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 ff e0 0f 1f 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffa640c4f3bd10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffa640c4f3bd30 RCX: 0000000000000001
RDX: ffff8df7dcc18e78 RSI: ffff8df7e5d8c24a RDI: ffff8df7adcb8800
RBP: ffff8df7dcc2ae88 R08: ffff8df7e5d8c440 R09: ffff8df786e458d0
R10: 0000000000000006 R11: ffff8df7e5d8c248 R12: ffff8df7dcc7bb40
R13: ffffa640c4f3be18 R14: ffff8df7dcc0ce00 R15: ffff8df7dcc0ce00
FS:  00007f373cd8be80(0000) GS:ffff8df897d80000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 000000015d404001 CR4: 00000000000306e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2c/0x40 [vmwgfx]
 ttm_release_base+0x71/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9b/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? kvm_get_wallclock+0x3b/0x70
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8c/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8a/0xc0
 do_syscall_64+0x37/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f373da0aa3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007fff7bf572b0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f373da0aa3f
RDX: 00007fff7bf57350 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007fff7bf57350 R08: 0000000000000018 R09: 0000000000000031
R10: 0000000000000031 R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 00005582f4720540 R15: 0000000000000000
 </TASK>
Modules linked in: tls uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc intel_rapl_msr intel_rapl_common snd_intel8x0 snd_ac97_codec joydev ac97_bus snd_seq pcspkr snd_seq_device snd_pcm snd_timer e1000 snd vboxguest i2c_piix4 soundcore zram vmwgfx drm_ttm_helper crc32c_intel ttm serio_raw ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #518118
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
vmw_user_surface_base_release
vmwgfx 0x5d
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP PTI
CPU: 2 PID: 1023 Comm: Xwayland Tainted: G S                5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffff997940757d10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffff997940757d30 RCX: 0000000000000001
RDX: ffff8ae762f64e78 RSI: ffff8ae762096fea RDI: ffff8ae75c87b000
RBP: ffff8ae75ef02fc8 R08: ffff8ae762097088 R09: ffff8ae7451d2090
R10: 0000000000000000 R11: ffff8ae762096fe8 R12: ffff8ae76afb2000
R13: ffff997940757e18 R14: ffff8ae741fdc600 R15: ffff8ae741fdc600
FS:  00007f8bce1afe80(0000) GS:ffff8ae850500000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 0000000116f56000 CR4: 00000000000406e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? check_preempt_wakeup+0x10b/0x2a0
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f8bcee2ea3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffd5af1f4f0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f8bcee2ea3f
RDX: 00007ffd5af1f590 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007ffd5af1f590 R08: 0000558c6a6668c0 R09: 0000000000000000
R10: 00000000ffffff9d R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 0000558c6a67b4e0 R15: 0000558c6a67b090
 </TASK>
Modules linked in: uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set nf_tables rfkill nfnetlink qrtr sunrpc intel_rapl_msr intel_rapl_common snd_intel8x0 rapl snd_ac97_codec ac97_bus snd_seq snd_seq_device snd_pcm joydev snd_timer snd pcspkr soundcore e1000 vboxguest i2c_piix4 zram crct10dif_pclmul crc32_pclmul crc32c_intel vmwgfx ghash_clmulni_intel serio_raw drm_ttm_helper ttm ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #515968
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
? drm_ioctl_kernel
vmlinux 0x9e
9
drm_ioctl_kernel
vmlinux 0x9e
10
? vmw_user_surface_base_release
vmwgfx 0x5d
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
vmw_user_surface_base_release
vmwgfx 0x5d
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP NOPTI
CPU: 5 PID: 1566 Comm: gnome-shell Tainted: G        W    L    5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffba9c44fbbd10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffba9c44fbbd30 RCX: 0000000000000001
RDX: ffff99d706f2f478 RSI: ffff99d801e5591a RDI: ffff99d8fdbbd000
RBP: ffff99d82b3b5908 R08: ffff99d801e55a70 R09: ffff99d80591d510
R10: 0000000000000000 R11: ffff99d801e55918 R12: ffff99d842f2a360
R13: ffffba9c44fbbe18 R14: ffff99d83f35a800 R15: ffff99d83f35a800
FS:  00007f449201d600(0000) GS:ffff99d917d40000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 000000014056a000 CR4: 00000000000506e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 ? _raw_spin_unlock+0x16/0x30
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f4497614a3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffc2cf5e6d0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f4497614a3f
RDX: 00007ffc2cf5e770 RSI: 000000004008644a RDI: 000000000000000d
RBP: 00007ffc2cf5e770 R08: 00005590400d6b60 R09: 00007ffc2cf5e998
R10: 0000000000000000 R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000d R14: 000055903e8e8140 R15: 0000000000000000
 </TASK>
Modules linked in: binfmt_misc tls uinput exfat snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 rfkill ip_set nf_tables nfnetlink qrtr sunrpc squashfs loop intel_rapl_msr uas snd_intel8x0 joydev snd_ac97_codec ac97_bus usb_storage snd_seq snd_seq_device snd_pcm snd_timer intel_rapl_common snd e1000 soundcore i2c_piix4 pcspkr vboxguest zram crct10dif_pclmul crc32_pclmul crc32c_intel ghash_clmulni_intel vmwgfx serio_raw drm_ttm_helper ata_generic ttm video pata_acpi ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #514729
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
? drm_ioctl_kernel
vmlinux 0x9e
14
vmw_user_surface_base_release
vmwgfx 0x5d
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
17
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP NOPTI
CPU: 1 PID: 1647 Comm: gnome-shell Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 ff e0 0f 1f 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffa57943b5bd10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffa57943b5bd30 RCX: 0000000000000001
RDX: ffff912d104c7e78 RSI: ffff912d054bb47a RDI: ffff912d2320e000
RBP: ffff912d1064bd08 R08: ffff912d054bb660 R09: ffff912e072b9750
R10: 0000000000000000 R11: ffff912d054bb478 R12: ffff912e038c9180
R13: ffffa57943b5be18 R14: ffff912d232b3a00 R15: ffff912d232b3a00
FS:  00007f8194939600(0000) GS:ffff912e1bc80000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 0000000010042003 CR4: 00000000000306e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2c/0x40 [vmwgfx]
 ttm_release_base+0x71/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9b/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? __rseq_handle_notify_resume+0x93/0x440
 ? sched_clock_cpu+0xb/0xc0
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8c/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8a/0xc0
 do_syscall_64+0x37/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f8199f30a3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffc89d995c0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f8199f30a3f
RDX: 00007ffc89d99660 RSI: 000000004008644a RDI: 000000000000000d
RBP: 00007ffc89d99660 R08: 0000557970ad87a0 R09: 0000000000000000
R10: 0000000000000004 R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000d R14: 000055796d535a40 R15: 000055796d3125c0
 </TASK>
Modules linked in: tls uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc intel_rapl_msr intel_rapl_common snd_intel8x0 snd_ac97_codec ac97_bus snd_seq snd_seq_device joydev snd_pcm snd_timer snd soundcore i2c_piix4 e1000 vboxguest pcspkr zram vmwgfx crc32c_intel serio_raw ata_generic drm_ttm_helper ttm pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #506518
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
? drm_ioctl_kernel
vmlinux 0x9e
9
drm_ioctl_kernel
vmlinux 0x9e
10
? vmw_user_surface_base_release
vmwgfx 0x5d
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
? drm_ioctl_kernel
vmlinux 0x9e
14
vmw_user_surface_base_release
vmwgfx 0x5d
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
17
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP NOPTI
CPU: 1 PID: 973 Comm: Xwayland Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 ff e0 0f 1f 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffb7e98361bd10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffb7e98361bd30 RCX: 0000000000000001
RDX: ffff8c56c243a478 RSI: ffff8c55c15aa6ca RDI: ffff8c56d1346000
RBP: ffff8c55c602a688 R08: ffff8c55c15aa770 R09: ffff8c56c4cebf90
R10: 0000000000000000 R11: ffff8c55c15aa6c8 R12: ffff8c55dac2b840
R13: ffffb7e98361be18 R14: ffff8c55c126cc00 R15: ffff8c55c126cc00
FS:  00007fd790f15e80(0000) GS:ffff8c56dbc80000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 000000000126a002 CR4: 00000000000306e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2c/0x40 [vmwgfx]
 ttm_release_base+0x71/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9b/0x140
 ? _raw_spin_unlock+0x16/0x30
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? asm_sysvec_reboot+0x1b/0x20
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8c/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8a/0xc0
 do_syscall_64+0x37/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7fd791b94a3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffd6048c680 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007fd791b94a3f
RDX: 00007ffd6048c720 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007ffd6048c720 R08: 0000557d049feb90 R09: 0000000000000000
R10: 00000000ffffff9d R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 0000557d04a11890 R15: 0000557d04a11440
 </TASK>
Modules linked in: uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc snd_intel8x0 snd_ac97_codec ac97_bus snd_seq intel_rapl_msr snd_seq_device intel_rapl_common joydev snd_pcm snd_timer e1000 snd soundcore vboxguest i2c_piix4 pcspkr zram vmwgfx crc32c_intel drm_ttm_helper serio_raw ttm ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #499640
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
vmw_user_surface_base_release
vmwgfx 0x5d
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP PTI
CPU: 0 PID: 908 Comm: Xwayland Tainted: G        W         5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffbbcb426f7d10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffbbcb426f7d30 RCX: 0000000000000001
RDX: ffff9ec285506078 RSI: ffff9ec28dba4492 RDI: ffff9ec28c5d6800
RBP: ffff9ec289623ac8 R08: ffff9ec28dba4538 R09: ffff9ec286a70750
R10: 0000000000000000 R11: ffff9ec28dba4490 R12: ffff9ec2891e1ba0
R13: ffffbbcb426f7e18 R14: ffff9ec295989000 R15: ffff9ec295989000
FS:  00007f3366700e80(0000) GS:ffff9ec2fd400000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 000000000a638004 CR4: 00000000000706f0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? check_preempt_wakeup+0x10b/0x2a0
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f336737fa3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007fffbf5ac750 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f336737fa3f
RDX: 00007fffbf5ac7f0 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007fffbf5ac7f0 R08: 0000563285ad4880 R09: 0000000000000000
R10: 00000000ffffff9d R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 0000563285ae2380 R15: 0000563285ae1f30
 </TASK>
Modules linked in: uinput isofs snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc vfat fat snd_intel8x0 intel_rapl_msr snd_ac97_codec ac97_bus snd_seq snd_seq_device intel_rapl_common snd_pcm rapl joydev pcspkr snd_timer e1000 snd soundcore vboxguest i2c_piix4 zram hid_multitouch vmwgfx nvme nvme_core crct10dif_pclmul crc32_pclmul crc32c_intel drm_ttm_helper ttm ghash_clmulni_intel serio_raw video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #495943
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
vmw_user_surface_base_release
vmwgfx 0x5d
13
drm_ioctl_kernel
vmlinux 0x9e
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP NOPTI
CPU: 0 PID: 1928 Comm: Xwayland Tainted: G             L    5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffa9260572bd10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffa9260572bd30 RCX: 0000000000000001
RDX: ffff999b0b212878 RSI: ffff999ac77a9242 RDI: ffff999ac5459400
RBP: ffff999ac3c080c8 R08: ffff999ac77a93b0 R09: ffff999ac5d89c90
R10: 0000000000000002 R11: ffff999ac77a9240 R12: ffff999b0f55b540
R13: ffffa9260572be18 R14: ffff999ae643bc00 R15: ffff999ae643bc00
FS:  00007f2354515e80(0000) GS:ffff999dcfc00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 0000000123e00002 CR4: 00000000000706f0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f2355194a3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffc88702430 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f2355194a3f
RDX: 00007ffc887024d0 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007ffc887024d0 R08: 0000564b01843950 R09: 0000000000000000
R10: 00000000ffffff9d R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 0000564b01856a00 R15: 0000564b018565b0
 </TASK>
Modules linked in: vboxsf binfmt_misc tls uinput isofs snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc intel_rapl_msr intel_rapl_common snd_intel8x0 joydev rapl snd_ac97_codec ac97_bus snd_seq snd_seq_device snd_pcm snd_timer vboxguest snd pcspkr e1000 i2c_piix4 soundcore zram vmwgfx crct10dif_pclmul crc32_pclmul crc32c_intel drm_ttm_helper ttm ghash_clmulni_intel serio_raw ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #491942
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
? drm_ioctl_kernel
vmlinux 0x9e
9
drm_ioctl_kernel
vmlinux 0x9e
10
? vmw_user_surface_base_release
vmwgfx 0x5d
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
vmw_user_surface_base_release
vmwgfx 0x5d
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#2] PREEMPT SMP NOPTI
CPU: 3 PID: 840 Comm: Xwayland Tainted: G      D           5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 ff e0 0f 1f 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffb3fc8483fd10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffb3fc8483fd30 RCX: 0000000000000001
RDX: ffff907543a0be78 RSI: ffff907559629ff2 RDI: ffff90758401cc00
RBP: ffff9075710b5388 R08: ffff90755962a0a8 R09: ffff907547239090
R10: 0000000000000000 R11: ffff907559629ff0 R12: ffff9075540992a0
R13: ffffb3fc8483fe18 R14: ffff9075538f9600 R15: ffff9075538f9600
FS:  00007f4a957ade80(0000) GS:ffff907657d80000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 0000000109b2e006 CR4: 00000000000306e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2c/0x40 [vmwgfx]
 ttm_release_base+0x71/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9b/0x140
 ? _raw_spin_unlock+0x16/0x30
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8c/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8a/0xc0
 do_syscall_64+0x37/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f4a9642ca3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffe32d38fa0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f4a9642ca3f
RDX: 00007ffe32d39040 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007ffe32d39040 R08: 0000562b5683c210 R09: 0000000000000000
R10: 00000000ffffff9d R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 0000562b568314e0 R15: 0000562b56831090
 </TASK>
Modules linked in: nfnetlink(+) sunrpc(+) intel_rapl_msr snd_intel8x0 intel_rapl_common snd_ac97_codec ac97_bus joydev snd_seq snd_seq_device snd_pcm snd_timer e1000 snd i2c_piix4 pcspkr soundcore vboxguest zram vmwgfx drm_ttm_helper crc32c_intel ttm serio_raw ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #487653
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
vmw_user_surface_base_release
vmwgfx 0x5d
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP NOPTI
CPU: 2 PID: 1720 Comm: gnome-shell Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffa4f003867d10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffa4f003867d30 RCX: 0000000000000001
RDX: ffff9589844cd478 RSI: ffff9589a0195ff2 RDI: ffff958995fbfc00
RBP: ffff9589c517fec8 R08: ffff9589a0196138 R09: ffff9589b5ba0a50
R10: 0000000000000000 R11: ffff9589a0195ff0 R12: ffff958984e1d780
R13: ffffa4f003867e18 R14: ffff9589bdccd400 R15: ffff9589bdccd400
FS:  00007f6c86496600(0000) GS:ffff958a3c280000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 00000000447c6000 CR4: 00000000000506e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? mprotect_fixup+0x11b/0x340
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f6c8ba8da3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007fff20a49a70 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f6c8ba8da3f
RDX: 00007fff20a49b10 RSI: 000000004008644a RDI: 000000000000000d
RBP: 00007fff20a49b10 R08: 0000562d0d4434b0 R09: 0000000000000000
R10: 0000562d0f99ba48 R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000d R14: 0000562d0e8b9050 R15: 0000562d0e8b8c00
 </TASK>
Modules linked in: tls uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc intel_rapl_msr intel_rapl_common kvm_amd ccp kvm snd_intel8x0 snd_ac97_codec irqbypass ac97_bus joydev snd_seq snd_seq_device snd_pcm pcspkr snd_timer snd e1000 soundcore i2c_piix4 vboxguest zram crct10dif_pclmul crc32_pclmul crc32c_intel vmwgfx ghash_clmulni_intel serio_raw drm_ttm_helper ttm ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #486226
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
? drm_ioctl_kernel
vmlinux 0x9e
5
? vmw_user_surface_base_release
vmwgfx 0x5d
6
vmw_user_surface_base_release
vmwgfx 0x5d
7
? vmw_user_surface_base_release
vmwgfx 0x5d
8
drm_ioctl_kernel
vmlinux 0x9e
9
drm_ioctl_kernel
vmlinux 0x9e
10
? vmw_user_surface_base_release
vmwgfx 0x5d
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
drm_ioctl_kernel
vmlinux 0x9e
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
BUG: unable to handle page fault for address: ffffbf1ec1800018
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 100000067 P4D 100000067 PUD 1001f6067 PMD 106b6a067 PTE 0
Oops: 0000 [#1] PREEMPT SMP PTI
CPU: 1 PID: 4824 Comm: gnome-shell Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 07/29/2019
RIP: 0010:vmw_update_seqno+0x1c/0x60 [vmwgfx]
Code: ff ff 66 66 2e 0f 1f 84 00 00 00 00 00 90 0f 1f 44 00 00 53 48 89 fb 81 bf 90 0f 00 00 06 04 00 00 74 28 48 8b 87 c0 0f 00 00 <8b> 40 18 39 83 80 11 00 00 75 03 5b c3 cc 89 83 80 11 00 00 48 8b
RSP: 0018:ffffbf1ec0787bc8 EFLAGS: 00010297
RAX: ffffbf1ec1800000 RBX: ffff9931034b4000 RCX: 0000000000000000
RDX: 0000000000000000 RSI: ffff99310a3728c0 RDI: ffff9931034b4000
RBP: ffff9931034b4000 R08: ffff99310a372898 R09: 0000000000000000
R10: ffff99313388f400 R11: 0000000000000000 R12: ffff9931034b4000
R13: ffff993108e84000 R14: ffffbf1ec0787c88 R15: ffff9931355bf700
FS:  00007f710e3f1600(0000) GS:ffff993139e40000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: ffffbf1ec1800018 CR3: 000000011a402005 CR4: 00000000003706e0
Call Trace:
 <TASK>
 vmw_cmd_send_fence+0xbb/0x160 [vmwgfx]
 vmw_execbuf_fence_commands+0x40/0xd0 [vmwgfx]
 vmw_execbuf_process+0x7d0/0x1130 [vmwgfx]
 ? __get_locked_pte+0xcf/0x110
 ? vmw_execbuf_release_pinned_bo+0x50/0x50 [vmwgfx]
 vmw_execbuf_ioctl+0x140/0x270 [vmwgfx]
 ? vmw_execbuf_release_pinned_bo+0x50/0x50 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_execbuf_release_pinned_bo+0x50/0x50 [vmwgfx]
 ? check_tsc_unstable+0xb/0x10
 ? sched_clock_cpu+0xb/0xc0
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f71139e8a3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007fff551fc760 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 000055c6d03a6b80 RCX: 00007f71139e8a3f
RDX: 00007fff551fc820 RSI: 000000004028644c RDI: 000000000000000d
RBP: 00007fff551fc820 R08: 0000000000001454 R09: 00007fff551fc8a8
R10: 0000000000000000 R11: 0000000000000246 R12: 000000004028644c
R13: 000000000000000d R14: 0000000000000001 R15: 00007fff551fc8a8
 </TASK>
Modules linked in: tls uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set nf_tables nfnetlink qrtr bnep vsock_loopback vmw_vsock_virtio_transport_common vmw_vsock_vmci_transport vsock sunrpc snd_seq_midi snd_seq_midi_event snd_ens1371 snd_ac97_codec snd_rawmidi intel_rapl_msr intel_rapl_common gameport btusb ac97_bus btrtl snd_seq btbcm btintel snd_seq_device rapl vmw_balloon snd_pcm btmtk bluetooth ecdh_generic rfkill snd_timer e1000 joydev pcspkr snd soundcore vmw_vmci i2c_piix4 zram crct10dif_pclmul crc32_pclmul crc32c_intel ghash_clmulni_intel serio_raw mptspi scsi_transport_spi mptscsih vmwgfx mptbase drm_ttm_helper ttm ata_generic pata_acpi ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: ffffbf1ec1800018
Complete report #484516
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
? drm_ioctl_kernel
vmlinux 0x9e
9
drm_ioctl_kernel
vmlinux 0x9e
10
? vmw_user_surface_base_release
vmwgfx 0x5d
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
? drm_ioctl_kernel
vmlinux 0x9e
14
vmw_user_surface_base_release
vmwgfx 0x5d
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
17
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP PTI
CPU: 1 PID: 1627 Comm: gnome-shell Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffbf5303adbd10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffbf5303adbd30 RCX: 0000000000000001
RDX: ffffa00043dfee78 RSI: ffff9fff7d51991a RDI: ffff9fff93ce6c00
RBP: ffff9fff5b8ea848 R08: ffff9fff7d5199f8 R09: ffffa000451e0090
R10: 0000000000000006 R11: ffff9fff7d519918 R12: ffff9fff4bce2660
R13: ffffbf5303adbe18 R14: ffff9fff5c2eea00 R15: ffff9fff5c2eea00
FS:  00007fac15f0a600(0000) GS:ffffa0005fb00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 00000000200e8004 CR4: 00000000000306e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 ? _raw_spin_unlock+0x16/0x30
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? __rseq_handle_notify_resume+0x93/0x440
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7fac1b501a3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffe53f46680 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007fac1b501a3f
RDX: 00007ffe53f46720 RSI: 000000004008644a RDI: 000000000000000d
RBP: 00007ffe53f46720 R08: 000055b726b93380 R09: 0000000000000030
R10: 0000000000000002 R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000d R14: 000055b72604c480 R15: 000055b72604c030
 </TASK>
Modules linked in: tls uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc iTCO_wdt intel_pmc_bxt intel_rapl_msr snd_intel8x0 iTCO_vendor_support intel_rapl_common snd_ac97_codec ac97_bus snd_seq rapl snd_seq_device snd_pcm joydev e1000 snd_timer snd pcspkr lpc_ich soundcore vboxguest i2c_piix4 zram vmwgfx crc32c_intel serio_raw drm_ttm_helper ata_generic ttm pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #484431
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
? drm_ioctl_kernel
vmlinux 0x9e
9
drm_ioctl_kernel
vmlinux 0x9e
10
? vmw_user_surface_base_release
vmwgfx 0x5d
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
vmw_user_surface_base_release
vmwgfx 0x5d
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP PTI
CPU: 5 PID: 1772 Comm: gnome-shell Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffa7ec45187d10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffa7ec45187d30 RCX: 0000000000000001
RDX: ffff9a4229bc7878 RSI: ffff9a424492824a RDI: ffff9a426d599800
RBP: ffff9a4204054f08 R08: ffff9a4244928278 R09: ffff9a42063c45d0
R10: 0000000000000000 R11: ffff9a4244928248 R12: ffff9a4267f07780
R13: ffffa7ec45187e18 R14: ffff9a424bd02c00 R15: ffff9a424bd02c00
FS:  00007f7e48e31600(0000) GS:ffff9a4503c80000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 0000000105eac004 CR4: 00000000000706e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 ? x2apic_send_IPI+0x46/0x50
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f7e4e428a3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007fffdde55170 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f7e4e428a3f
RDX: 00007fffdde55210 RSI: 000000004008644a RDI: 000000000000000d
RBP: 00007fffdde55210 R08: 0000555c36597340 R09: 0000000000000030
R10: 0000000000000002 R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000d R14: 0000555c3714a770 R15: 0000555c3714a320
 </TASK>
Modules linked in: tls uinput isofs snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 rfkill ip_set nf_tables nfnetlink qrtr sunrpc vfat fat intel_rapl_msr intel_rapl_common joydev snd_intel8x0 kvm_intel snd_ac97_codec ac97_bus kvm snd_seq snd_seq_device snd_pcm irqbypass rapl snd_timer pcspkr snd e1000 soundcore vboxguest i2c_piix4 zram crct10dif_pclmul vmwgfx crc32_pclmul crc32c_intel ghash_clmulni_intel serio_raw drm_ttm_helper ttm ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #478723
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
vmw_user_surface_base_release
vmwgfx 0x5d
7
? vmw_user_surface_base_release
vmwgfx 0x5d
8
vmw_user_surface_base_release
vmwgfx 0x5d
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
drm_ioctl_kernel
vmlinux 0x9e
11
drm_ioctl_kernel
vmlinux 0x9e
12
? vmw_user_surface_base_release
vmwgfx 0x5d
13
? drm_ioctl_kernel
vmlinux 0x9e
14
? drm_ioctl_kernel
vmlinux 0x9e
15
? drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
17
drm_ioctl_kernel
vmlinux 0x9e
18
drm_ioctl_kernel
vmlinux 0x9e
WARNING: CPU: 0 PID: 1128 at drivers/gpu/drm/vmwgfx/vmwgfx_cmdbuf.c:400 vmw_cmdbuf_ctx_process+0x259/0x260 [vmwgfx]
Modules linked in: tls isofs snd_seq_dummy snd_hrtimer nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr vsock_loopback vmw_vsock_virtio_transport_common vmw_vsock_vmci_transport vsock sunrpc snd_seq_midi snd_seq_midi_event intel_rapl_msr vmw_balloon intel_rapl_common snd_ens1371 joydev snd_ac97_codec snd_rawmidi gameport ac97_bus snd_seq pcspkr snd_seq_device snd_pcm pcnet32 snd_timer snd soundcore mii i2c_piix4 vmw_vmci zram crct10dif_pclmul crc32_pclmul crc32c_intel vmwgfx ghash_clmulni_intel serio_raw mptspi scsi_transport_spi drm_ttm_helper mptscsih ttm mptbase ata_generic pata_acpi fuse ipmi_devintf ipmi_msghandler
CPU: 0 PID: 1128 Comm: Xorg Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 07/22/2020
RIP: 0010:vmw_cmdbuf_ctx_process+0x259/0x260 [vmwgfx]
Code: c7 74 04 41 83 06 01 48 83 c4 30 5b 5d 41 5c 41 5d 41 5e 41 5f c3 cc 48 c7 c7 f3 9f 2a c0 c6 05 32 4d 03 00 01 e8 d0 fb a0 f0 <0f> 0b e9 1c fe ff ff 0f 1f 44 00 00 41 55 4c 8d af 88 00 00 00 41
RSP: 0018:ffffaffb80d17ae0 EFLAGS: 00010282
RAX: 0000000000000015 RBX: ffff8f50c648d000 RCX: 0000000000000000
RDX: 0000000000000002 RSI: ffffffffb1665ad5 RDI: 00000000ffffffff
RBP: 0000000000000003 R08: 0000000000000000 R09: ffffaffb80d17920
R10: ffffaffb80d17918 R11: 0000000000000003 R12: ffff8f50c648d080
R13: ffff8f50f67b8818 R14: ffff8f50f67b8800 R15: ffff8f50c648d088
FS:  00007fb0a3269fc0(0000) GS:ffff8f50fbc00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fffc4cc98e8 CR3: 000000012837a000 CR4: 0000000000350ef0
Call Trace:
 <TASK>
 vmw_cmdbuf_man_process+0x45/0xe0 [vmwgfx]
 __vmw_cmdbuf_cur_flush+0xad/0xf0 [vmwgfx]
 vmw_cmdbuf_commit+0x68/0xd0 [vmwgfx]
 vmw_cmd_send_fence+0xb3/0x160 [vmwgfx]
 vmw_execbuf_fence_commands+0x40/0xd0 [vmwgfx]
 vmw_execbuf_process+0x7d0/0x1130 [vmwgfx]
 ? vmw_execbuf_release_pinned_bo+0x50/0x50 [vmwgfx]
 vmw_execbuf_ioctl+0x140/0x270 [vmwgfx]
 ? vmw_execbuf_release_pinned_bo+0x50/0x50 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_execbuf_release_pinned_bo+0x50/0x50 [vmwgfx]
 ? __rseq_handle_notify_resume+0x93/0x440
 ? check_tsc_unstable+0xb/0x10
 ? native_apic_msr_write+0x27/0x30
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7fb0a3adda3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffe6aafcd00 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000562c9ea82c70 RCX: 00007fb0a3adda3f
RDX: 00007ffe6aafcde0 RSI: 000000004020644c RDI: 0000000000000010
RBP: 00007ffe6aafcde0 R08: 00000000000081d8 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 000000004020644c
R13: 0000000000000010 R14: 000000000000039a R15: 00000000000081d8
 </TASK>
Complete report #482639
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
? drm_ioctl_kernel
vmlinux 0x9e
14
vmw_user_surface_base_release
vmwgfx 0x5d
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
17
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP PTI
CPU: 1 PID: 1038 Comm: Xwayland Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffb9b6c2363d10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffb9b6c2363d30 RCX: 0000000000000001
RDX: ffffa0daed612278 RSI: ffffa0dad92ff90a RDI: ffffa0db2d531800
RBP: ffffa0daee5d8dc8 R08: ffffa0dad92ff9a8 R09: ffffa0daca748810
R10: 0000000000000000 R11: ffffa0dad92ff908 R12: ffffa0dadfa76300
R13: ffffb9b6c2363e18 R14: ffffa0daed614a00 R15: ffffa0daed614a00
FS:  00007f0535510e80(0000) GS:ffffa0dc75480000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 00000001167a4006 CR4: 00000000000706e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? __mutex_lock.constprop.0+0x8a/0x440
 ? sched_clock_cpu+0xb/0xc0
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f053618fa3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007fff0fbac320 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f053618fa3f
RDX: 00007fff0fbac3c0 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007fff0fbac3c0 R08: 000055db3fb74fe0 R09: 0000000000000000
R10: 00000000ffffff9d R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 000055db3fb772a0 R15: 000055db3fb76e50
 </TASK>
Modules linked in: uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 rfkill ip_set nf_tables nfnetlink qrtr sunrpc intel_rapl_msr intel_rapl_common kvm_intel kvm irqbypass rapl joydev snd_intel8x0 snd_ac97_codec ac97_bus snd_seq snd_seq_device snd_pcm snd_timer snd e1000 i2c_piix4 vboxguest soundcore pcspkr zram crct10dif_pclmul vmwgfx crc32_pclmul crc32c_intel ghash_clmulni_intel drm_ttm_helper ttm serio_raw ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #466312
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
vmw_user_surface_base_release
vmwgfx 0x5d
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#2] PREEMPT SMP PTI
CPU: 0 PID: 2064 Comm: Xwayland Tainted: G      D           5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffb4c7c565bd10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffb4c7c565bd30 RCX: 0000000000000001
RDX: ffff9cdd9580a678 RSI: ffff9cddec8f148a RDI: ffff9cdd81777400
RBP: ffff9cdec4c745c8 R08: ffff9cddec8f15d0 R09: ffff9cde84d90210
R10: 0000000000000016 R11: ffff9cddec8f1488 R12: ffff9cddca6d9060
R13: ffffb4c7c565be18 R14: ffff9cdebc159800 R15: ffff9cdebc159800
FS:  00007fe0a19f2e80(0000) GS:ffff9cdf97c00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 0000000169d88004 CR4: 00000000000706f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? __do_munmap+0x2a3/0x530
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7fe0a2671a3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffd6a9efc10 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007fe0a2671a3f
RDX: 00007ffd6a9efcb0 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007ffd6a9efcb0 R08: 0000559049283280 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 000055904914d530 R15: 000055904914d0e0
 </TASK>
Modules linked in: tls uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 rfkill ip_set nf_tables nfnetlink qrtr sunrpc vfat fat snd_intel8x0 intel_rapl_msr snd_ac97_codec ac97_bus snd_seq intel_rapl_common snd_seq_device snd_pcm rapl snd_timer joydev snd i2c_piix4 pcspkr e1000 soundcore vboxguest zram crct10dif_pclmul crc32_pclmul crc32c_intel vmwgfx ghash_clmulni_intel serio_raw drm_ttm_helper ata_generic ttm video pata_acpi ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #466232
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
? drm_ioctl_kernel
vmlinux 0x9e
9
drm_ioctl_kernel
vmlinux 0x9e
10
? vmw_user_surface_base_release
vmwgfx 0x5d
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
? drm_ioctl_kernel
vmlinux 0x9e
14
? drm_ioctl_kernel
vmlinux 0x9e
15
vmw_user_surface_base_release
vmwgfx 0x5d
16
drm_ioctl_kernel
vmlinux 0x9e
17
drm_ioctl_kernel
vmlinux 0x9e
18
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP PTI
CPU: 2 PID: 1662 Comm: gnome-shell Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffaf19c4c4bd10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffaf19c4c4bd30 RCX: 0000000000000001
RDX: ffffa09037639a78 RSI: ffffa08fceb3fd9a RDI: ffffa09033c27800
RBP: ffffa08fc4598508 R08: ffffa08fceb3ff80 R09: ffffa08fc5b01ed0
R10: 0000000000000004 R11: ffffa08fceb3fd98 R12: ffffa08feb39bf00
R13: ffffaf19c4c4be18 R14: ffffa08fff787a00 R15: ffffa08fff787a00
FS:  00007f8aeb306600(0000) GS:ffffa090d1d00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 0000000103cba004 CR4: 00000000000306e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 ? try_to_wake_up+0x83/0x520
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? __mutex_lock.constprop.0+0x8a/0x440
 ? eventfd_write+0xb4/0x2d0
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f8af08fda3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffc33e081b0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f8af08fda3f
RDX: 00007ffc33e08250 RSI: 000000004008644a RDI: 000000000000000d
RBP: 00007ffc33e08250 R08: 000055ddf90a51e0 R09: 0000000000000030
R10: 0000000000000002 R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000d R14: 000055ddf9382850 R15: 000055ddf9382400
 </TASK>
Modules linked in: tls uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc snd_intel8x0 snd_ac97_codec ac97_bus snd_seq snd_seq_device intel_rapl_msr snd_pcm intel_rapl_common snd_timer rapl snd joydev e1000 soundcore vboxguest pcspkr i2c_piix4 zram vmwgfx drm_ttm_helper crc32c_intel serio_raw ttm video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #463893
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
? drm_ioctl_kernel
vmlinux 0x9e
9
drm_ioctl_kernel
vmlinux 0x9e
10
? vmw_user_surface_base_release
vmwgfx 0x5d
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
? drm_ioctl_kernel
vmlinux 0x9e
14
vmw_user_surface_base_release
vmwgfx 0x5d
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
17
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP NOPTI
CPU: 2 PID: 1435 Comm: Xwayland Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffb955c47f7d10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffb955c47f7d30 RCX: 0000000000000001
RDX: ffff9031f6e7ae78 RSI: ffff9031f9876482 RDI: ffff903219571800
RBP: ffff9031eaaa2588 R08: ffff9031f9876528 R09: ffff9031c62895d0
R10: 0000000000000000 R11: ffff9031f9876480 R12: ffff9031fb140960
R13: ffffb955c47f7e18 R14: ffff9031fd4cb000 R15: ffff9031fd4cb000
FS:  00007fa04d08de80(0000) GS:ffff9032d7c80000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 0000000102392000 CR4: 00000000000506e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 ? _raw_spin_unlock+0x16/0x30
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? check_tsc_unstable+0xb/0x10
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7fa04dd0ca3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007fffd7b8beb0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007fa04dd0ca3f
RDX: 00007fffd7b8bf50 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007fffd7b8bf50 R08: 000055f48fea1680 R09: 0000000000000000
R10: 00000000ffffff9d R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 000055f48fea41b0 R15: 000055f48fea3d60
 </TASK>
Modules linked in: uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc intel_rapl_msr snd_intel8x0 snd_ac97_codec ac97_bus intel_rapl_common snd_seq joydev snd_seq_device snd_pcm pcspkr snd_timer e1000 snd vboxguest soundcore i2c_piix4 zram dm_crypt crct10dif_pclmul crc32_pclmul crc32c_intel vmwgfx ghash_clmulni_intel serio_raw drm_ttm_helper ttm ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #455542
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
? drm_ioctl_kernel
vmlinux 0x9e
9
drm_ioctl_kernel
vmlinux 0x9e
10
? vmw_user_surface_base_release
vmwgfx 0x5d
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
vmw_user_surface_base_release
vmwgfx 0x5d
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP PTI
CPU: 0 PID: 1019 Comm: Xwayland Tainted: G S                5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffab66c365fd10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffab66c365fd30 RCX: 0000000000000001
RDX: ffff96e11d91e878 RSI: ffff96e1078c4922 RDI: ffff96e211a3f400
RBP: ffff96e109ba9d48 R08: ffff96e1078c49c8 R09: ffff96e205e2b810
R10: 0000000000000000 R11: ffff96e1078c4920 R12: ffff96e112678a20
R13: ffffab66c365fe18 R14: ffff96e101211a00 R15: ffff96e101211a00
FS:  00007facb2c27e80(0000) GS:ffff96e21bc00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 00000000011ae000 CR4: 00000000000406f0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 ? _raw_spin_unlock+0x16/0x30
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7facb38a6a3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffc29e7cdc0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007facb38a6a3f
RDX: 00007ffc29e7ce60 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007ffc29e7ce60 R08: 000055a039a0b0a0 R09: 0000000000000000
R10: 00000000ffffff9d R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 000055a039a0bd60 R15: 000055a039a0b910
 </TASK>
Modules linked in: uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 rfkill ip_set nf_tables nfnetlink qrtr sunrpc intel_rapl_msr intel_rapl_common rapl snd_intel8x0 snd_ac97_codec joydev ac97_bus snd_seq snd_seq_device snd_pcm pcspkr snd_timer e1000 snd soundcore i2c_piix4 vboxguest zram crct10dif_pclmul crc32_pclmul crc32c_intel vmwgfx ghash_clmulni_intel serio_raw drm_ttm_helper ttm ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #450755
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
? drm_ioctl_kernel
vmlinux 0x9e
14
vmw_user_surface_base_release
vmwgfx 0x5d
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
17
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP NOPTI
CPU: 1 PID: 1871 Comm: gnome-shell Tainted: G        W         5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffb652c1a07d10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffb652c1a07d30 RCX: 0000000000000001
RDX: ffff99d784e6dc78 RSI: ffff99d76bb9a912 RDI: ffff99d775876400
RBP: ffff99d7481a39c8 R08: ffff99d76bb9a960 R09: ffff99d742803890
R10: 0000000000000000 R11: ffff99d76bb9a910 R12: ffff99d78b949a80
R13: ffffb652c1a07e18 R14: ffff99d78cc7bc00 R15: ffff99d78cc7bc00
FS:  00007ff74a2f1600(0000) GS:ffff99da4fa40000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 0000000145e46000 CR4: 00000000000506e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? __mutex_lock.constprop.0+0x8a/0x440
 ? eventfd_write+0xb4/0x2d0
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7ff74f8e8a3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffe23b15320 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007ff74f8e8a3f
RDX: 00007ffe23b153c0 RSI: 000000004008644a RDI: 000000000000000d
RBP: 00007ffe23b153c0 R08: 000055e10bc58580 R09: 00007ffe23b155e8
R10: 0000000000000000 R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000d R14: 000055e10a6db3a0 R15: 0000000000000000
 </TASK>
Modules linked in: tls uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 rfkill ip_set nf_tables nfnetlink qrtr sunrpc vfat fat intel_rapl_msr intel_rapl_common snd_intel8x0 snd_ac97_codec kvm_amd ac97_bus snd_seq ccp snd_seq_device snd_pcm kvm irqbypass joydev snd_timer e1000 pcspkr i2c_piix4 snd soundcore vboxguest zram vmwgfx crct10dif_pclmul crc32_pclmul crc32c_intel nvme nvme_core ghash_clmulni_intel drm_ttm_helper ttm serio_raw ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #463100
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
? drm_ioctl_kernel
vmlinux 0x9e
9
drm_ioctl_kernel
vmlinux 0x9e
10
? vmw_user_surface_base_release
vmwgfx 0x5d
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
vmw_user_surface_base_release
vmwgfx 0x5d
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP NOPTI
CPU: 3 PID: 1277 Comm: Xwayland Tainted: G        W         5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffafd50114fd10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffafd50114fd30 RCX: 0000000000000001
RDX: ffff9ddb217ce878 RSI: ffff9ddb2bd56b5a RDI: ffff9ddb0b577400
RBP: ffff9ddb2010f2c8 R08: ffff9ddb2bd56c00 R09: ffff9ddc05a3e5d0
R10: 0000000000000000 R11: ffff9ddb2bd56b58 R12: ffff9ddb2c581660
R13: ffffafd50114fe18 R14: ffff9ddb217d1800 R15: ffff9ddb217d1800
FS:  00007fa134393e80(0000) GS:ffff9ddc1bd80000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 000000005f872000 CR4: 00000000000506e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 ? _raw_spin_unlock+0x16/0x30
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7fa135012a3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffcc9373620 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007fa135012a3f
RDX: 00007ffcc93736c0 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007ffcc93736c0 R08: 0000556f10193240 R09: 0000000000000000
R10: 00000000ffffff9d R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 0000556f1018b9f0 R15: 0000556f1018b5a0
 </TASK>
Modules linked in: uinput isofs snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc vfat fat intel_rapl_msr snd_intel8x0 snd_ac97_codec joydev ac97_bus snd_seq snd_seq_device snd_pcm snd_timer intel_rapl_common e1000 snd vboxguest i2c_piix4 pcspkr soundcore zram dm_crypt crct10dif_pclmul crc32_pclmul crc32c_intel vmwgfx ghash_clmulni_intel nvme nvme_core serio_raw drm_ttm_helper ttm ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #468407
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
? drm_ioctl_kernel
vmlinux 0x9e
9
drm_ioctl_kernel
vmlinux 0x9e
10
? vmw_user_surface_base_release
vmwgfx 0x5d
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
? drm_ioctl_kernel
vmlinux 0x9e
14
? drm_ioctl_kernel
vmlinux 0x9e
15
vmw_user_surface_base_release
vmwgfx 0x5d
16
drm_ioctl_kernel
vmlinux 0x9e
17
drm_ioctl_kernel
vmlinux 0x9e
18
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP NOPTI
CPU: 3 PID: 1886 Comm: gnome-shell Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffb7dcc3993d10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffb7dcc3993d30 RCX: 0000000000000001
RDX: ffff9b181dfb5c78 RSI: ffff9b183dc706da RDI: ffff9b1807784c00
RBP: ffff9b181a4ef788 R08: ffff9b183dc708d8 R09: ffff9b1835b07f90
R10: 0000000000000003 R11: ffff9b183dc706d8 R12: ffff9b1870dd4d80
R13: ffffb7dcc3993e18 R14: ffff9b183db4a400 R15: ffff9b183db4a400
FS:  00007f867d9ac600(0000) GS:ffff9b18ceb00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 000000003db74000 CR4: 00000000000506e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 ? _raw_spin_unlock+0x16/0x30
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? __rseq_handle_notify_resume+0x93/0x440
 ? call_rcu+0xff/0x690
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f8682fa3a3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007fff1338ebf0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f8682fa3a3f
RDX: 00007fff1338ec90 RSI: 000000004008644a RDI: 000000000000000d
RBP: 00007fff1338ec90 R08: 000055efa5d63970 R09: 0000000000000030
R10: 0000000000000002 R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000d R14: 000055efa6804160 R15: 000055efa6803d10
 </TASK>
Modules linked in: tls uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 rfkill ip_set nf_tables nfnetlink qrtr sunrpc intel_rapl_msr snd_intel8x0 snd_ac97_codec ac97_bus intel_rapl_common snd_seq joydev snd_seq_device snd_pcm snd_timer pcspkr snd e1000 vboxguest soundcore i2c_piix4 zram crct10dif_pclmul crc32_pclmul crc32c_intel vmwgfx ghash_clmulni_intel serio_raw drm_ttm_helper ttm ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #465385
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
? drm_ioctl_kernel
vmlinux 0x9e
9
drm_ioctl_kernel
vmlinux 0x9e
10
? vmw_user_surface_base_release
vmwgfx 0x5d
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
? drm_ioctl_kernel
vmlinux 0x9e
14
? drm_ioctl_kernel
vmlinux 0x9e
15
vmw_user_surface_base_release
vmwgfx 0x5d
16
drm_ioctl_kernel
vmlinux 0x9e
17
drm_ioctl_kernel
vmlinux 0x9e
18
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP NOPTI
CPU: 0 PID: 1449 Comm: gnome-shell Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffb772846bbd10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffb772846bbd30 RCX: 0000000000000001
RDX: ffff98ca0d141e78 RSI: ffff98c9fb309b62 RDI: ffff98c9c5656800
RBP: ffff98c9c356cb48 R08: ffff98c9fb309bd8 R09: ffff98c9c57f7150
R10: 0000000000000002 R11: ffff98c9fb309b60 R12: ffff98ca094c60c0
R13: ffffb772846bbe18 R14: ffff98c9fb609e00 R15: ffff98c9fb609e00
FS:  00007f8fe6cba600(0000) GS:ffff98ca6ee00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 0000000104b70000 CR4: 00000000000506f0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 ? _raw_spin_unlock+0x16/0x30
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? __mutex_lock.constprop.0+0x8a/0x440
 ? eventfd_write+0xb4/0x2d0
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f8fec2b1a3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffd0e6cb2d0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f8fec2b1a3f
RDX: 00007ffd0e6cb370 RSI: 000000004008644a RDI: 000000000000000d
RBP: 00007ffd0e6cb370 R08: 000056141d554580 R09: 00007ffd0e6cb598
R10: 0000000000000000 R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000d R14: 000056141bc94560 R15: 0000000000000000
 </TASK>
Modules linked in: uinput isofs snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc snd_intel8x0 intel_rapl_msr snd_ac97_codec ac97_bus snd_seq snd_seq_device snd_pcm intel_rapl_common joydev snd_timer e1000 snd pcspkr vboxguest i2c_piix4 soundcore zram vmwgfx crct10dif_pclmul crc32_pclmul crc32c_intel ghash_clmulni_intel serio_raw drm_ttm_helper ttm ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #440044
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
vmw_user_surface_base_release
vmwgfx 0x5d
13
drm_ioctl_kernel
vmlinux 0x9e
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP PTI
CPU: 0 PID: 1448 Comm: gnome-shell Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffa2bbc37ffd10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffa2bbc37ffd30 RCX: 0000000000000001
RDX: ffff927d10f01c78 RSI: ffff927d07872002 RDI: ffff927e149c3000
RBP: ffff927d1c080548 R08: ffff927d07872098 R09: ffff927e06858810
R10: 0000000000000000 R11: ffff927d07872000 R12: ffff927e0619e420
R13: ffffa2bbc37ffe18 R14: ffff927d1c05a000 R15: ffff927d1c05a000
FS:  00007f5bfb8b6600(0000) GS:ffff927e1bc00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 000000001c2a8003 CR4: 00000000000706f0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? asm_sysvec_apic_timer_interrupt+0x12/0x20
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f5c00eada3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffc6b84eef0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f5c00eada3f
RDX: 00007ffc6b84ef90 RSI: 000000004008644a RDI: 000000000000000d
RBP: 00007ffc6b84ef90 R08: 000055c9da85c0a0 R09: 000055c9da3b7010
R10: 0000000000000000 R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000d R14: 000055c9dbcfd450 R15: 000055c9dbcfd000
 </TASK>
Modules linked in: uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 rfkill ip_set nf_tables nfnetlink qrtr snd_intel8x0 snd_ac97_codec ac97_bus snd_seq intel_rapl_msr sunrpc intel_rapl_common snd_seq_device intel_powerclamp rapl snd_pcm joydev snd_timer e1000 snd pcspkr vboxguest i2c_piix4 soundcore zram vmwgfx crct10dif_pclmul crc32_pclmul crc32c_intel ghash_clmulni_intel drm_ttm_helper ttm serio_raw ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #436131
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x8e
8
? drm_ioctl_kernel
vmlinux 0x8e
9
drm_ioctl_kernel
vmlinux 0x8e
10
? vmw_user_surface_base_release
vmwgfx 0x5d
11
? drm_ioctl_kernel
vmlinux 0x8e
12
? drm_ioctl_kernel
vmlinux 0x8e
13
vmw_user_surface_base_release
vmwgfx 0x5d
14
drm_ioctl_kernel
vmlinux 0x8e
15
drm_ioctl_kernel
vmlinux 0x8e
16
drm_ioctl_kernel
vmlinux 0x8e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP PTI
CPU: 0 PID: 3897 Comm: Xwayland Not tainted 5.17.11-100.fc34.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 ff fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 d7 74 78 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffb7c3c20bfd10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffb7c3c20bfd30 RCX: 0000000000000001
RDX: ffff895b55e76678 RSI: ffff895b4d030ffa RDI: ffff895b410fc800
RBP: ffff895c48267cc0 R08: ffff895b55e76600 R09: ffff895c48267d50
R10: 0000000000000000 R11: ffff895b4d030ff8 R12: ffff895b55b20cc0
R13: ffffb7c3c20bfe18 R14: ffff895b80c34600 R15: ffff895b80c34600
FS:  00007f0b7a34aa00(0000) GS:ffff895c5bc00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 000000003a49c005 CR4: 00000000000706f0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x6a/0xa0 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x480/0x480 [vmwgfx]
 drm_ioctl_kernel+0x8e/0x120
 ? ptep_set_access_flags+0x30/0x40
 drm_ioctl+0x221/0x3e0
 ? vmw_surface_dirty_range_add+0x480/0x480 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? drm_ioctl_kernel+0x120/0x120
 vmw_generic_ioctl+0x8e/0x100 [vmwgfx]
 __x64_sys_ioctl+0x83/0xc0
 do_syscall_64+0x3b/0x90
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f0b7ad6507b
Code: ff ff ff 85 c0 79 9b 49 c7 c4 ff ff ff ff 5b 5d 4c 89 e0 41 5c c3 66 0f 1f 84 00 00 00 00 00 f3 0f 1e fa b8 10 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d cd bd 0c 00 f7 d8 64 89 01 48
RSP: 002b:00007fffb292ce28 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 00007fffb292ce70 RCX: 00007f0b7ad6507b
RDX: 00007fffb292ce70 RSI: 000000004008644a RDI: 000000000000000c
RBP: 000000004008644a R08: 000055bb5a59b880 R09: 0000000000000000
R10: 00000000ffffff9d R11: 0000000000000246 R12: 000055bb5a59e400
R13: 000000000000000c R14: 000055bb5a5ba4c0 R15: 000055bb5a59e504
 </TASK>
Modules linked in: uinput snd_seq_dummy snd_hrtimer xt_CHECKSUM xt_MASQUERADE xt_conntrack ipt_REJECT nf_nat_tftp nf_conntrack_tftp bridge stp llc nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat ip6table_nat ip6table_mangle ip6table_raw ip6table_security iptable_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 iptable_mangle iptable_raw iptable_security ip_set rfkill nf_tables nfnetlink ip6table_filter ip6_tables iptable_filter sunrpc snd_intel8x0 snd_ac97_codec ac97_bus intel_rapl_msr snd_seq intel_rapl_common snd_seq_device intel_powerclamp rapl snd_pcm joydev snd_timer pcspkr snd i2c_piix4 vboxguest soundcore zram ip_tables vmwgfx crct10dif_pclmul crc32_pclmul crc32c_intel e1000 ghash_clmulni_intel drm_ttm_helper serio_raw ttm ata_generic pata_acpi video ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #429198
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
vmw_user_surface_base_release
vmwgfx 0x5d
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#3] PREEMPT SMP PTI
CPU: 2 PID: 1824 Comm: gnome-shell Tainted: G      D W         5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffb105837dbd10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffb105837dbd30 RCX: 0000000000000001
RDX: ffff9e97c930ec78 RSI: ffff9e97fdb1191a RDI: ffff9e981b207800
RBP: ffff9e97c4f8d788 R08: ffff9e97fdb119f8 R09: ffff9e97f5dad450
R10: 0000000000000004 R11: ffff9e97fdb11918 R12: ffff9e97d9dad720
R13: ffffb105837dbe18 R14: ffff9e97fd4f6600 R15: ffff9e97fd4f6600
FS:  00007f81acc8a600(0000) GS:ffff9e9885900000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 000000005b198005 CR4: 00000000000706e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? __rseq_handle_notify_resume+0x93/0x440
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f81b2281a3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffd67441060 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f81b2281a3f
RDX: 00007ffd67441100 RSI: 000000004008644a RDI: 000000000000000d
RBP: 00007ffd67441100 R08: 000056025eced160 R09: 0000000000000030
R10: 0000000000000002 R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000d R14: 000056025e0c4720 R15: 000056025e0c42d0
 </TASK>
Modules linked in: tls uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set nf_tables nfnetlink rfkill qrtr sunrpc snd_intel8x0 intel_rapl_msr snd_ac97_codec intel_rapl_common ac97_bus snd_seq snd_seq_device snd_pcm rapl snd_timer joydev e1000 pcspkr snd soundcore vboxguest i2c_piix4 zram crct10dif_pclmul crc32_pclmul crc32c_intel vmwgfx ghash_clmulni_intel serio_raw drm_ttm_helper ttm ata_generic video pata_acpi ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #424330
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
vmw_user_surface_base_release
vmwgfx 0x5d
13
drm_ioctl_kernel
vmlinux 0x9e
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP PTI
CPU: 0 PID: 1006 Comm: Xwayland Tainted: G        W         5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffad7b81143d10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffad7b81143d30 RCX: 0000000000000001
RDX: ffff9b564f12fe78 RSI: ffff9b564491e922 RDI: ffff9b567d771000
RBP: ffff9b564fa58288 R08: ffff9b564491e9c8 R09: ffff9b5746e5c150
R10: 0000000000000000 R11: ffff9b564491e920 R12: ffff9b5644e94c00
R13: ffffad7b81143e18 R14: ffff9b56421ec200 R15: ffff9b56421ec200
FS:  00007f9d06e05e80(0000) GS:ffff9b575bc00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 0000000004fb8006 CR4: 00000000000706f0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f9d07a84a3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007fff9e5103b0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f9d07a84a3f
RDX: 00007fff9e510450 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007fff9e510450 R08: 000055ce29d6da20 R09: 0000000000000000
R10: 00000000ffffff9d R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 000055ce29d8c340 R15: 000055ce29d8bef0
 </TASK>
Modules linked in: uinput isofs snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 rfkill ip_set nf_tables nfnetlink qrtr sunrpc vfat fat intel_rapl_msr intel_rapl_common snd_intel8x0 snd_ac97_codec ac97_bus joydev snd_seq snd_seq_device snd_pcm snd_timer snd e1000 pcspkr i2c_piix4 soundcore vboxguest zram crct10dif_pclmul crc32_pclmul crc32c_intel vmwgfx ghash_clmulni_intel nvme nvme_core drm_ttm_helper serio_raw ttm ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #423821
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
? drm_ioctl_kernel
vmlinux 0x9e
9
drm_ioctl_kernel
vmlinux 0x9e
10
? vmw_user_surface_base_release
vmwgfx 0x5d
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
vmw_user_surface_base_release
vmwgfx 0x5d
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP NOPTI
CPU: 2 PID: 1012 Comm: Xwayland Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffb77dc2323d10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffb77dc2323d30 RCX: 0000000000000001
RDX: ffff96bc82569278 RSI: ffff96bb814f148a RDI: ffff96bc94138400
RBP: ffff96bb8f292008 R08: ffff96bb814f1500 R09: ffff96bc84a768d0
R10: 0000000000000000 R11: ffff96bb814f1488 R12: ffff96bb8fb4e9c0
R13: ffffb77dc2323e18 R14: ffff96bb8f566a00 R15: ffff96bb8f566a00
FS:  00007fd838ff8e80(0000) GS:ffff96bc9bd00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 00000000011be000 CR4: 00000000000506e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 ? dequeue_signal+0x119/0x1b0
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7fd839c77a3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007fff31cb3830 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007fd839c77a3f
RDX: 00007fff31cb38d0 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007fff31cb38d0 R08: 00005592a1ef3360 R09: 0000000000000000
R10: 00000000ffffff9d R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 00005592a1ef55c0 R15: 00005592a1ef5170
 </TASK>
Modules linked in: uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 rfkill ip_set nf_tables nfnetlink qrtr sunrpc intel_rapl_msr snd_intel8x0 snd_ac97_codec intel_rapl_common joydev ac97_bus snd_seq snd_seq_device snd_pcm snd_timer snd e1000 vboxguest i2c_piix4 soundcore pcspkr zram crct10dif_pclmul crc32_pclmul crc32c_intel vmwgfx ghash_clmulni_intel serio_raw drm_ttm_helper ttm ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #421476
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
vmw_user_surface_base_release
vmwgfx 0x5d
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP NOPTI
CPU: 1 PID: 992 Comm: Xwayland Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffb1e9c470fd10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffb1e9c470fd30 RCX: 0000000000000001
RDX: ffff9936ac69c078 RSI: ffff9936a0620db2 RDI: ffff9936bff49800
RBP: ffff9936ab250b88 R08: ffff9936a0620e58 R09: ffff993684ebfd50
R10: 0000000000000000 R11: ffff9936a0620db0 R12: ffff9936ab5e2660
R13: ffffb1e9c470fe18 R14: ffff993696763600 R15: ffff993696763600
FS:  00007f8ab86fee80(0000) GS:ffff993797d00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 0000000116760004 CR4: 00000000000706e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? check_preempt_wakeup+0x10b/0x2a0
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f8ab937da3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007fff35d481b0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f8ab937da3f
RDX: 00007fff35d48250 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007fff35d48250 R08: 000056457af8aa20 R09: 0000000000000000
R10: 00000000ffffff9d R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 000056457af82bf0 R15: 000056457af827a0
 </TASK>
Modules linked in: uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc intel_rapl_msr intel_rapl_common kvm_intel kvm snd_intel8x0 snd_ac97_codec ac97_bus snd_seq joydev irqbypass rapl snd_seq_device snd_pcm snd_timer e1000 snd soundcore i2c_piix4 pcspkr vboxguest zram crct10dif_pclmul crc32_pclmul vmwgfx crc32c_intel ghash_clmulni_intel drm_ttm_helper ttm video ata_generic pata_acpi serio_raw ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #420985
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
vmw_user_surface_base_release
vmwgfx 0x5d
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP NOPTI
CPU: 0 PID: 1635 Comm: gnome-shell Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffff9caa43c3fd10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffff9caa43c3fd30 RCX: 0000000000000001
RDX: ffff89f34239f678 RSI: ffff89f34dedd48a RDI: ffff89f34d653c00
RBP: ffff89f37a65c388 R08: ffff89f34dedd598 R09: ffff89f44639b450
R10: 0000000000000004 R11: ffff89f34dedd488 R12: ffff89f34d4b2a80
R13: ffff9caa43c3fe18 R14: ffff89f37a7c4c00 R15: ffff89f37a7c4c00
FS:  00007fc5c76f6600(0000) GS:ffff89f45bc00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 000000003a46e004 CR4: 00000000000706f0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? __rseq_handle_notify_resume+0x93/0x440
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7fc5ccceda3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007fff256b8460 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007fc5ccceda3f
RDX: 00007fff256b8500 RSI: 000000004008644a RDI: 000000000000000d
RBP: 00007fff256b8500 R08: 0000557c498316e0 R09: 0000000000000030
R10: 0000000000000002 R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000d R14: 0000557c49cc89a0 R15: 0000557c49cc8550
 </TASK>
Modules linked in: tls uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc snd_intel8x0 snd_ac97_codec ac97_bus snd_seq intel_rapl_msr snd_seq_device intel_rapl_common snd_pcm intel_powerclamp rapl snd_timer e1000 joydev snd pcspkr soundcore i2c_piix4 vboxguest zram vmwgfx crct10dif_pclmul crc32_pclmul crc32c_intel ghash_clmulni_intel drm_ttm_helper serio_raw ata_generic ttm pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #420823
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
? drm_ioctl_kernel
vmlinux 0x9e
14
vmw_user_surface_base_release
vmwgfx 0x5d
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
17
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP NOPTI
CPU: 2 PID: 5871 Comm: Xorg Tainted: G        W         5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffb9d043fe7d10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffb9d043fe7d30 RCX: 0000000000000001
RDX: ffff921ee2dec478 RSI: ffff921f6cfb96d2 RDI: ffff921fd33ed000
RBP: ffff921f051a24c8 R08: ffff921f6cfb9840 R09: ffff921fc5426b10
R10: 0000000000000005 R11: ffff921f6cfb96d0 R12: ffff921f0470dc00
R13: ffffb9d043fe7e18 R14: ffff921f1a098a00 R15: ffff921f1a098a00
FS:  00007f3df8705fc0(0000) GS:ffff921fdbc80000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 000000005d688000 CR4: 00000000000506e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? clocksource_mark_unstable+0x7a/0xa0
 ? sched_clock_cpu+0xb/0xc0
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f3df8f79a3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffd857ee5d0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f3df8f79a3f
RDX: 00007ffd857ee670 RSI: 000000004008644a RDI: 0000000000000010
RBP: 00007ffd857ee670 R08: 00000000907a6718 R09: 0000000000000005
R10: 000000003f800000 R11: 0000000000000246 R12: 000000004008644a
R13: 0000000000000010 R14: 0000000000000001 R15: 000055607093b200
 </TASK>
Modules linked in: tls uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc joydev intel_rapl_msr snd_intel8x0 snd_ac97_codec ac97_bus snd_seq snd_seq_device snd_pcm snd_timer snd soundcore intel_rapl_common e1000 vboxguest i2c_piix4 pcspkr zram vmwgfx crct10dif_pclmul crc32_pclmul crc32c_intel ghash_clmulni_intel drm_ttm_helper ttm serio_raw ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #420401
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
? drm_ioctl_kernel
vmlinux 0x9e
14
vmw_user_surface_base_release
vmwgfx 0x5d
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
17
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP PTI
CPU: 0 PID: 1611 Comm: gnome-shell Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffaac7434cbd10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffaac7434cbd30 RCX: 0000000000000001
RDX: ffff9c7e131dc478 RSI: ffff9c7e136fedb2 RDI: ffff9c7e3afdec00
RBP: ffff9c7e02ff6288 R08: ffff9c7e136feea0 R09: ffff9c7e066bcd50
R10: 0000000000000000 R11: ffff9c7e136fedb0 R12: ffff9c7e0417ccc0
R13: ffffaac7434cbe18 R14: ffff9c7e1f394e00 R15: ffff9c7e1f394e00
FS:  00007fc65eaa8600(0000) GS:ffff9c7e7d400000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 000000001e1f4005 CR4: 00000000000706f0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? clocksource_mark_unstable+0x7a/0xa0
 ? sched_clock_cpu+0xb/0xc0
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7fc66409fa3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007fff0dfdd060 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007fc66409fa3f
RDX: 00007fff0dfdd100 RSI: 000000004008644a RDI: 000000000000000d
RBP: 00007fff0dfdd100 R08: 000055df8625e0d0 R09: 0000000000000030
R10: 0000000000000002 R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000d R14: 000055df860e4e50 R15: 000055df860e4a00
 </TASK>
Modules linked in: tls uinput isofs snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 rfkill ip_set nf_tables nfnetlink qrtr sunrpc vfat fat intel_rapl_msr snd_intel8x0 snd_ac97_codec ac97_bus snd_seq snd_seq_device intel_rapl_common joydev rapl snd_pcm pcspkr vboxguest snd_timer e1000 snd i2c_piix4 soundcore zram crct10dif_pclmul vmwgfx crc32_pclmul crc32c_intel ghash_clmulni_intel drm_ttm_helper serio_raw ttm ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #419802
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
drm_ioctl_kernel
vmlinux 0x9e
10
drm_ioctl_kernel
vmlinux 0x9e
11
drm_ioctl_kernel
vmlinux 0x9e
12
drm_ioctl_kernel
vmlinux 0x9e
13
drm_ioctl_kernel
vmlinux 0x9e
14
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#3] PREEMPT SMP NOPTI
CPU: 0 PID: 850 Comm: systemd-logind Tainted: G      D W         5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 ff e0 0f 1f 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffad69c1d3bdc0 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffad69c1d3bde0 RCX: 0000000000000001
RDX: ffff9309d5affe78 RSI: ffff9309c17ba002 RDI: ffff930a0a5a5000
RBP: ffff9309c3822248 R08: ffff9309c17ba090 R09: ffff930ac6608990
R10: 0000000000000000 R11: ffff9309c17ba000 R12: ffff9309d5a73540
R13: ffff930ac21ee000 R14: ffff9309c3805cd0 R15: dead000000000100
FS:  00007f54c63efbc0(0000) GS:ffff930adbc00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 0000000113004005 CR4: 00000000000306f0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2c/0x40 [vmwgfx]
 ttm_release_base+0x71/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_object_file_release+0x39/0x90 [vmwgfx]
 vmw_postclose+0x15/0x20 [vmwgfx]
 drm_file_free.part.0+0x201/0x250
 drm_release+0x65/0x110
 __fput+0x8e/0x250
 task_work_run+0x59/0x90
 exit_to_user_mode_prepare+0x229/0x230
 syscall_exit_to_user_mode+0x18/0x40
 do_syscall_64+0x46/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f54c6ff35fa
Code: b8 03 00 00 00 0f 05 48 3d 00 f0 ff ff 77 41 c3 48 83 ec 18 89 7c 24 0c e8 73 6f f8 ff 8b 7c 24 0c 89 c2 b8 03 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 36 89 d7 89 44 24 0c e8 c3 6f f8 ff 8b 44 24
RSP: 002b:00007fff43fe7cc0 EFLAGS: 00000293 ORIG_RAX: 0000000000000003
RAX: 0000000000000000 RBX: 0000000000000017 RCX: 00007f54c6ff35fa
RDX: 0000000000000000 RSI: 0000000000000003 RDI: 0000000000000017
RBP: 00007f54c63ef9e8 R08: 0000558d9060fa90 R09: 00007f54c704d380
R10: 00007fff43fe7aa4 R11: 0000000000000293 R12: 0000000000000000
R13: 0000558d905f16c0 R14: 0000000000000000 R15: 00007fff43fe7e10
 </TASK>
Modules linked in: uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc snd_intel8x0 snd_ac97_codec ac97_bus snd_seq snd_seq_device intel_rapl_msr snd_pcm intel_rapl_common rapl joydev snd_timer e1000 pcspkr snd soundcore vboxguest i2c_piix4 zram dm_crypt vmwgfx crc32c_intel drm_ttm_helper serio_raw ata_generic ttm pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #419774
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
? drm_ioctl_kernel
vmlinux 0x9e
9
drm_ioctl_kernel
vmlinux 0x9e
10
? vmw_user_surface_base_release
vmwgfx 0x5d
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
vmw_user_surface_base_release
vmwgfx 0x5d
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP PTI
CPU: 0 PID: 917 Comm: Xwayland Tainted: G             L    5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffa622c37cfd10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffa622c37cfd30 RCX: 0000000000000001
RDX: ffff8f7d50a40678 RSI: ffff8f7d4806e492 RDI: ffff8f7d8ff77c00
RBP: ffff8f7d50f70788 R08: ffff8f7d4806e530 R09: ffff8f7e4870a450
R10: 0000000000000000 R11: ffff8f7d4806e490 R12: ffff8f7d5e0df240
R13: ffffa622c37cfe18 R14: ffff8f7d5081d400 R15: ffff8f7d5081d400
FS:  00007fb3de718e80(0000) GS:ffff8f7e5bc00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 0000000004592005 CR4: 00000000000306f0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 ? _raw_spin_unlock+0x16/0x30
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7fb3df397a3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffe965449b0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007fb3df397a3f
RDX: 00007ffe96544a50 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007ffe96544a50 R08: 000056320344bb00 R09: 0000000000000000
R10: 00000000ffffff9d R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 000056320344fb30 R15: 000056320344f6e0
 </TASK>
Modules linked in: uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc snd_intel8x0 snd_ac97_codec ac97_bus snd_seq snd_seq_device snd_pcm intel_rapl_msr intel_rapl_common rapl snd_timer snd joydev e1000 soundcore vboxguest i2c_piix4 pcspkr zram vmwgfx crc32c_intel serio_raw drm_ttm_helper ttm ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #418663
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
vmw_user_surface_base_release
vmwgfx 0x5d
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#3] PREEMPT SMP PTI
CPU: 2 PID: 1520 Comm: gnome-shell Tainted: G      D W         5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffb35883bdfd10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffb35883bdfd30 RCX: 0000000000000001
RDX: ffff9f7a81b34078 RSI: ffff9f7a85edc6da RDI: ffff9f7b04f03800
RBP: ffff9f7b97948288 R08: ffff9f7a85edc8c8 R09: ffff9f7b86a975d0
R10: 0000000000000000 R11: ffff9f7a85edc6d8 R12: ffff9f7a82d6c6c0
R13: ffffb35883bdfe18 R14: ffff9f7a8fa60a00 R15: ffff9f7a8fa60a00
FS:  00007fc9f4722600(0000) GS:ffff9f7b9bd00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 000000000fa62003 CR4: 00000000000706e0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? __schedule+0x28b/0x1230
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7fc9f9d19a3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffe60190300 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007fc9f9d19a3f
RDX: 00007ffe601903a0 RSI: 000000004008644a RDI: 000000000000000d
RBP: 00007ffe601903a0 R08: 000055ca32224510 R09: 0000000000000030
R10: 0000000000000002 R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000d R14: 000055ca320ad9a0 R15: 000055ca320ad550
 </TASK>
Modules linked in: uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set nf_tables rfkill nfnetlink qrtr sunrpc snd_intel8x0 intel_rapl_msr snd_ac97_codec intel_rapl_common ac97_bus snd_seq snd_seq_device snd_pcm rapl snd_timer snd joydev e1000 soundcore vboxguest i2c_piix4 pcspkr zram vmwgfx crct10dif_pclmul crc32_pclmul crc32c_intel ghash_clmulni_intel drm_ttm_helper ttm serio_raw ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #415133
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
vmw_user_surface_base_release
vmwgfx 0x5d
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP PTI
CPU: 2 PID: 2664 Comm: Xwayland Tainted: P           OE     5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffb170c55dbd10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffb170c55dbd30 RCX: 0000000000000001
RDX: ffff98748a962278 RSI: ffff9874ac542482 RDI: ffff98756b43dc00
RBP: ffff9874bbfec508 R08: ffff9874ac5424c0 R09: ffff987486222990
R10: 0000000000000000 R11: ffff9874ac542480 R12: ffff9874bc17fa20
R13: ffffb170c55dbe18 R14: ffff98748a962e00 R15: ffff98748a962e00
FS:  00007f3e01186e80(0000) GS:ffff98778fc80000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 000000012a662003 CR4: 00000000000706e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? __rseq_handle_notify_resume+0x93/0x440
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f3e01df6b5f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007fffcfad3140 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f3e01df6b5f
RDX: 00007fffcfad31e0 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007fffcfad31e0 R08: 000055e962ce71b0 R09: 0000000000000000
R10: 000055e962a16fc0 R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 000055e962d114f0 R15: 000055e962d11584
 </TASK>
Modules linked in: binfmt_misc lp parport tls uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc intel_rapl_msr intel_rapl_common kvm_intel kvm snd_intel8x0 irqbypass snd_ac97_codec ac97_bus snd_seq snd_seq_device snd_pcm joydev e1000 snd_timer snd soundcore vboxguest i2c_piix4 pcspkr zram crct10dif_pclmul vmwgfx crc32_pclmul crc32c_intel ghash_clmulni_intel serio_raw drm_ttm_helper ata_generic pata_acpi ttm video ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #414608
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
vmw_user_surface_base_release
vmwgfx 0x5d
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP PTI
CPU: 0 PID: 1969 Comm: Xwayland Tainted: G           OE     5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffb936c4447d10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffb936c4447d30 RCX: 0000000000000001
RDX: ffff90d59c5b5c78 RSI: ffff90d5ac4de24a RDI: ffff90d5c4f12800
RBP: ffff90d5aa12ca48 R08: ffff90d5ac4de338 R09: ffff90d686114090
R10: 0000000000000004 R11: ffff90d5ac4de248 R12: ffff90d5b87a00c0
R13: ffffb936c4447e18 R14: ffff90d5a9f9ba00 R15: ffff90d5a9f9ba00
FS:  00007fb5bddc4e80(0000) GS:ffff90d69bc00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 000000003bf24003 CR4: 00000000000706f0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? check_tsc_unstable+0xb/0x10
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7fb5bea43a3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffedb3d14e0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007fb5bea43a3f
RDX: 00007ffedb3d1580 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007ffedb3d1580 R08: 0000000000000018 R09: 0000000000000031
R10: 0000000000000031 R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 0000562bf6b78160 R15: 0000000000000000
 </TASK>
Modules linked in: uinput isofs snd_seq_dummy snd_hrtimer vboxvideo drm_vram_helper nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc vfat fat intel_rapl_msr intel_rapl_common rapl snd_intel8x0 snd_ac97_codec ac97_bus snd_seq snd_seq_device snd_pcm snd_timer e1000 joydev pcspkr snd i2c_piix4 soundcore zram vmwgfx crct10dif_pclmul crc32_pclmul crc32c_intel ghash_clmulni_intel serio_raw video vboxguest(OE) drm_ttm_helper ttm ata_generic pata_acpi ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #419891
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
? drm_ioctl_kernel
vmlinux 0x9e
14
vmw_user_surface_base_release
vmwgfx 0x5d
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
17
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP NOPTI
CPU: 3 PID: 2128 Comm: Xwayland Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffa0a385607d10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffa0a385607d30 RCX: 0000000000000001
RDX: ffff8979b173b078 RSI: ffff8979a1e3cffa RDI: ffff89795776c000
RBP: ffff8979abd7d408 R08: ffff8979a1e3d078 R09: ffff897945442750
R10: 0000000000000000 R11: ffff8979a1e3cff8 R12: ffff8979abd3b4e0
R13: ffffa0a385607e18 R14: ffff8979980dbc00 R15: ffff8979980dbc00
FS:  00007fd5a7699e80(0000) GS:ffff897ad5cc0000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 000000015daee005 CR4: 00000000000706e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? __rseq_handle_notify_resume+0x93/0x440
 ? __schedule+0x28b/0x1230
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7fd5a8318a3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffea2484550 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007fd5a8318a3f
RDX: 00007ffea24845f0 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007ffea24845f0 R08: 000055d0d1b900c0 R09: 0000000000000000
R10: 00000000ffffff9d R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 000055d0d1b91d70 R15: 000055d0d1b91920
 </TASK>
Modules linked in: tls uinput isofs snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc intel_rapl_msr intel_rapl_common snd_intel8x0 rapl snd_ac97_codec ac97_bus joydev snd_seq snd_seq_device pcspkr snd_pcm snd_timer snd e1000 soundcore vboxguest i2c_piix4 zram crct10dif_pclmul crc32_pclmul crc32c_intel vmwgfx ghash_clmulni_intel drm_ttm_helper ttm serio_raw ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #421399
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
? drm_ioctl_kernel
vmlinux 0x9e
14
vmw_user_surface_base_release
vmwgfx 0x5d
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
17
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP NOPTI
CPU: 0 PID: 1889 Comm: Xwayland Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffb3a6052e3d10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffb3a6052e3d30 RCX: 0000000000000001
RDX: ffff8b6f4b459c78 RSI: ffff8b6f20f46492 RDI: ffff8b6f053fdc00
RBP: ffff8b6f3bea7348 R08: ffff8b6f20f46528 R09: ffff8b6f06661750
R10: 0000000000000002 R11: ffff8b6f20f46490 R12: ffff8b6f3c4bea80
R13: ffffb3a6052e3e18 R14: ffff8b6f08d6fe00 R15: ffff8b6f08d6fe00
FS:  00007fbb17f45e80(0000) GS:ffff8b71f8200000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 00000001172ac000 CR4: 00000000000506f0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? __rseq_handle_notify_resume+0x93/0x440
 ? drm_ioctl_kernel+0x5b/0x140
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7fbb18bc4a3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007fff16c00490 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007fbb18bc4a3f
RDX: 00007fff16c00530 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007fff16c00530 R08: 0000565122bb6640 R09: 0000000000000000
R10: 00000000ffffff9d R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 0000565122bf1d60 R15: 0000565122bf1910
 </TASK>
Modules linked in: binfmt_misc tls uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc snd_intel8x0 intel_rapl_msr snd_ac97_codec ac97_bus snd_seq joydev snd_seq_device intel_rapl_common snd_pcm pcspkr snd_timer e1000 snd i2c_piix4 vboxguest soundcore zram vmwgfx crct10dif_pclmul crc32_pclmul crc32c_intel ghash_clmulni_intel serio_raw drm_ttm_helper ata_generic ttm pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #419827
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
? drm_ioctl_kernel
vmlinux 0x9e
14
vmw_user_surface_base_release
vmwgfx 0x5d
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
17
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP NOPTI
CPU: 6 PID: 1685 Comm: gnome-shell Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffa9a443e7fd10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffa9a443e7fd30 RCX: 0000000000000001
RDX: ffff958d44565c78 RSI: ffff958c4248eda2 RDI: ffff958c464b5000
RBP: ffff958c545f6748 R08: ffff958c4248ede8 R09: ffff958d474b0690
R10: 0000000000000000 R11: ffff958c4248eda0 R12: ffff958c64faf7e0
R13: ffffa9a443e7fe18 R14: ffff958c42f01600 R15: ffff958c42f01600
FS:  00007fc554af8600(0000) GS:ffff958d5bd80000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 0000000014b88000 CR4: 00000000000506e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? __mutex_lock.constprop.0+0x8a/0x440
 ? eventfd_write+0xb4/0x2d0
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7fc55a0efa3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffce5b554c0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007fc55a0efa3f
RDX: 00007ffce5b55560 RSI: 000000004008644a RDI: 000000000000000d
RBP: 00007ffce5b55560 R08: 0000561e1c266c80 R09: 00007ffce5b55788
R10: 0000000000000000 R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000d R14: 0000561e1b006c30 R15: 0000000000000000
 </TASK>
Modules linked in: isofs uinput snd_seq_dummy snd_hrtimer vboxvideo drm_vram_helper nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc intel_rapl_msr intel_rapl_common snd_intel8x0 kvm_amd snd_ac97_codec ccp ac97_bus snd_seq kvm snd_seq_device joydev irqbypass snd_pcm snd_timer e1000 snd soundcore vboxguest i2c_piix4 pcspkr zram vmwgfx crct10dif_pclmul crc32_pclmul crc32c_intel ghash_clmulni_intel serio_raw drm_ttm_helper ttm ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #419155
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
? drm_ioctl_kernel
vmlinux 0x9e
14
vmw_user_surface_base_release
vmwgfx 0x5d
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
17
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP NOPTI
CPU: 0 PID: 2019 Comm: Xwayland Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffa8af83b67d10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffa8af83b67d30 RCX: 0000000000000001
RDX: ffff958ddc825678 RSI: ffff958e2d87f242 RDI: ffff958e27946800
RBP: ffff958e23fdca48 R08: ffff958e2d87f3d8 R09: ffff958dc66ff2d0
R10: 0000000000000000 R11: ffff958e2d87f240 R12: ffff958de85c1e40
R13: ffffa8af83b67e18 R14: ffff958e27974600 R15: ffff958e27974600
FS:  00007f9bc0d31e80(0000) GS:ffff958e3dc00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 000000006789e000 CR4: 00000000000506f0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? __schedule+0x28b/0x1230
 ? sched_clock_cpu+0xb/0xc0
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f9bc19b0a3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffcc59a7820 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f9bc19b0a3f
RDX: 00007ffcc59a78c0 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007ffcc59a78c0 R08: 0000000000000018 R09: 0000000000000031
R10: 0000000000000031 R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 000055dc198ca550 R15: 0000000000000000
 </TASK>
Modules linked in: tls uinput isofs snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 rfkill ip_set nf_tables nfnetlink qrtr sunrpc snd_intel8x0 snd_ac97_codec ac97_bus snd_seq intel_rapl_msr snd_seq_device snd_pcm intel_rapl_common snd_timer joydev e1000 snd pcspkr i2c_piix4 vboxguest soundcore zram vmwgfx crct10dif_pclmul crc32_pclmul crc32c_intel ghash_clmulni_intel serio_raw drm_ttm_helper ttm ata_generic pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #412871
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
vmw_user_surface_base_release
vmwgfx 0x5d
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP NOPTI
CPU: 1 PID: 1936 Comm: Xwayland Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffb83505123d10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffb83505123d30 RCX: 0000000000000001
RDX: ffff9f1f79bbd478 RSI: ffff9f1f8b8036d2 RDI: ffff9f1f44ee3c00
RBP: ffff9f1f8a97c788 R08: ffff9f1f8b8038b8 R09: ffff9f1f4581bf90
R10: 0000000000000000 R11: ffff9f1f8b8036d0 R12: ffff9f1f6daf02a0
R13: ffffb83505123e18 R14: ffff9f1f8c82de00 R15: ffff9f1f8c82de00
FS:  00007f709c2cfe80(0000) GS:ffff9f204bf00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 000000014c82e000 CR4: 00000000000506e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? sched_clock_cpu+0xb/0xc0
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f709cf4f1bf
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffcac2632c0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f709cf4f1bf
RDX: 00007ffcac263360 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007ffcac263360 R08: 000055f7233089f0 R09: 0000000000000001
R10: 000000003f800000 R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 0000000000000000 R15: 000055f7233386e0
 </TASK>
Modules linked in: tls uinput snd_seq_dummy snd_hrtimer snd_seq snd_seq_device snd_timer snd soundcore nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc intel_rapl_msr joydev intel_rapl_common e1000 vboxguest pcspkr i2c_piix4 zram crct10dif_pclmul vmwgfx crc32_pclmul crc32c_intel ghash_clmulni_intel video drm_ttm_helper ttm ata_generic serio_raw pata_acpi ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #413683
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
? drm_ioctl_kernel
vmlinux 0x9e
9
drm_ioctl_kernel
vmlinux 0x9e
10
? vmw_user_surface_base_release
vmwgfx 0x5d
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
vmw_user_surface_base_release
vmwgfx 0x5d
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP PTI
CPU: 1 PID: 977 Comm: Xwayland Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffa4f6c375fd10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffa4f6c375fd30 RCX: 0000000000000001
RDX: ffff93f694f5de78 RSI: ffff93f681679242 RDI: ffff93f6c09f3c00
RBP: ffff93f689e39088 R08: ffff93f6816792e0 R09: ffff93f786b05450
R10: 0000000000000000 R11: ffff93f681679240 R12: ffff93f6984d68a0
R13: ffffa4f6c375fe18 R14: ffff93f681158200 R15: ffff93f681158200
FS:  00007fa891fdfe80(0000) GS:ffff93f79fb00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 000000000117e002 CR4: 00000000000706e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 ? _raw_spin_unlock+0x16/0x30
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7fa892c5ea3f
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffcd07e9260 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007fa892c5ea3f
RDX: 00007ffcd07e9300 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007ffcd07e9300 R08: 00005568584eea80 R09: 0000000000000000
R10: 00000000ffffff9d R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 00005568584f9680 R15: 00005568584f9230
 </TASK>
Modules linked in: uinput isofs snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc vfat fat intel_rapl_msr iTCO_wdt intel_rapl_common intel_pmc_bxt iTCO_vendor_support rapl snd_intel8x0 snd_ac97_codec ac97_bus snd_seq joydev snd_seq_device snd_pcm pcspkr virtio_net net_failover failover snd_timer lpc_ich vboxguest snd i2c_piix4 soundcore zram vmwgfx crct10dif_pclmul crc32_pclmul crc32c_intel ghash_clmulni_intel serio_raw drm_ttm_helper ttm video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #409886
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
vmw_user_surface_base_release
vmwgfx 0x5d
13
drm_ioctl_kernel
vmlinux 0x9e
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP PTI
CPU: 0 PID: 1870 Comm: Xwayland Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffbb1c8421bd10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffbb1c8421bd30 RCX: 0000000000000001
RDX: ffff937ee245b678 RSI: ffff937ed47b5242 RDI: ffff937f56e82800
RBP: ffff937ee3144508 R08: ffff937ed47b5330 R09: ffff937fc5269b10
R10: 0000000000000000 R11: ffff937ed47b5240 R12: ffff937ef76a30c0
R13: ffffbb1c8421be18 R14: ffff937ee2e49000 R15: ffff937ee2e49000
FS:  00007f38bf2dae80(0000) GS:ffff937fdbc00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 0000000022e4c004 CR4: 00000000000706f0
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f38bff591bf
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffe892cf240 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f38bff591bf
RDX: 00007ffe892cf2e0 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007ffe892cf2e0 R08: 000055c798499dd0 R09: 0000000000000000
R10: 00000000ffffff9d R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 000055c79849b890 R15: 000055c79849b440
 </TASK>
Modules linked in: tls uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr sunrpc intel_rapl_msr intel_rapl_common rapl snd_intel8x0 snd_ac97_codec ac97_bus snd_seq snd_seq_device snd_pcm joydev e1000 snd_timer snd soundcore pcspkr vboxguest i2c_piix4 zram crct10dif_pclmul crc32_pclmul crc32c_intel ghash_clmulni_intel vmwgfx video drm_ttm_helper ttm serio_raw ata_generic pata_acpi ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #409806
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
? drm_ioctl_kernel
vmlinux 0x9e
14
vmw_user_surface_base_release
vmwgfx 0x5d
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
17
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP NOPTI
CPU: 1 PID: 2155 Comm: Xwayland Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffb04b03e1bd10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffb04b03e1bd30 RCX: 0000000000000001
RDX: ffff8c4cd94bd678 RSI: ffff8c4cce46191a RDI: ffff8c4c887dbc00
RBP: ffff8c4cbd8dfd48 R08: ffff8c4cce461a98 R09: ffff8c4c86a36510
R10: 0000000000000004 R11: ffff8c4cce461918 R12: ffff8c4d0cabe300
R13: ffffb04b03e1be18 R14: ffff8c4cb9d0c800 R15: ffff8c4cb9d0c800
FS:  00007f8dc3229e80(0000) GS:ffff8c4d3cd00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 0000000048f90000 CR4: 00000000000506e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? __rseq_handle_notify_resume+0x93/0x440
 ? call_rcu+0xff/0x690
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f8dc2a0e1bf
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffd8a3255e0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f8dc2a0e1bf
RDX: 00007ffd8a325680 RSI: 000000004008644a RDI: 000000000000000c
RBP: 00007ffd8a325680 R08: 0000000000000000 R09: 0000000000000031
R10: 0000000000000000 R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000c R14: 00005623a04df960 R15: 0000000000000000
 </TASK>
Modules linked in: tls isofs uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr vboxsf sunrpc snd_intel8x0 snd_ac97_codec ac97_bus snd_seq snd_seq_device snd_pcm e1000 snd_timer snd vboxguest joydev pcspkr soundcore i2c_piix4 zram vmwgfx crct10dif_pclmul crc32_pclmul crc32c_intel ghash_clmulni_intel drm_ttm_helper ttm ata_generic serio_raw pata_acpi video ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000
Complete report #408400
Frame # Function Binary Source or offset Line
1
vmw_user_surface_base_release
vmwgfx 0x5d
2
vmw_user_surface_base_release
vmwgfx 0x5d
3
vmw_user_surface_base_release
vmwgfx 0x5d
4
vmw_user_surface_base_release
vmwgfx 0x5d
5
vmw_user_surface_base_release
vmwgfx 0x5d
6
? vmw_user_surface_base_release
vmwgfx 0x5d
7
drm_ioctl_kernel
vmlinux 0x9e
8
drm_ioctl_kernel
vmlinux 0x9e
9
? vmw_user_surface_base_release
vmwgfx 0x5d
10
? drm_ioctl_kernel
vmlinux 0x9e
11
? drm_ioctl_kernel
vmlinux 0x9e
12
? drm_ioctl_kernel
vmlinux 0x9e
13
vmw_user_surface_base_release
vmwgfx 0x5d
14
drm_ioctl_kernel
vmlinux 0x9e
15
drm_ioctl_kernel
vmlinux 0x9e
16
drm_ioctl_kernel
vmlinux 0x9e
BUG: kernel NULL pointer dereference, address: 0000000000000000
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0 
Oops: 0000 [#1] PREEMPT SMP NOPTI
CPU: 1 PID: 1468 Comm: gnome-shell Not tainted 5.17.5-300.fc36.x86_64 #1
Hardware name: innotek GmbH VirtualBox/VirtualBox, BIOS VirtualBox 12/01/2006
RIP: 0010:drm_gem_object_free+0xc/0x20
Code: 44 00 00 48 8b bf e0 05 00 00 e9 3f fe 00 00 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 48 8b 87 40 01 00 00 <48> 8b 00 48 85 c0 74 06 e9 f7 26 79 00 cc 0f 0b c3 cc 66 90 0f 1f
RSP: 0018:ffffb0c644a43d10 EFLAGS: 00010246
RAX: 0000000000000000 RBX: ffffb0c644a43d30 RCX: 0000000000000001
RDX: ffffa04cf153ce78 RSI: fffff0c6446ac580 RDI: ffffa04d41b78000
RBP: ffffa04cc366c288 R08: 0000000000000000 R09: 0000000000400012
R10: ffffa04cdab16480 R11: ffffa04d0dbccdb0 R12: ffffa04d1814a5a0
R13: ffffb0c644a43e18 R14: ffffa04ce981b400 R15: ffffa04ce981b400
FS:  00007f1ccd664600(0000) GS:ffffa04dcbf00000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 00000001256f4000 CR4: 00000000000506e0
Call Trace:
 <TASK>
 vmw_user_surface_base_release+0x5d/0x70 [vmwgfx]
 ttm_prime_refcount_release+0x2f/0x40 [vmwgfx]
 ttm_release_base+0x74/0xa0 [vmwgfx]
 ttm_ref_object_release+0xa2/0xb0 [vmwgfx]
 ttm_ref_object_base_unref+0x68/0x90 [vmwgfx]
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 drm_ioctl_kernel+0x9e/0x140
 drm_ioctl+0x21c/0x410
 ? vmw_surface_dirty_range_add+0x450/0x450 [vmwgfx]
 ? ioctl_has_perm.constprop.0.isra.0+0xaa/0xf0
 ? check_tsc_unstable+0xb/0x10
 ? drm_ioctl_kernel+0x140/0x140
 vmw_generic_ioctl+0x8f/0xf0 [vmwgfx]
 __x64_sys_ioctl+0x8d/0xc0
 do_syscall_64+0x3a/0x80
 entry_SYSCALL_64_after_hwframe+0x44/0xae
RIP: 0033:0x7f1cd2c641bf
Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 18 48 8b 44 24 18 64 48 2b 04 25 28 00 00
RSP: 002b:00007ffe53c54c40 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f1cd2c641bf
RDX: 00007ffe53c54ce0 RSI: 000000004008644a RDI: 000000000000000d
RBP: 00007ffe53c54ce0 R08: 000055de81136bd0 R09: 0000000000000030
R10: 0000000000000002 R11: 0000000000000246 R12: 000000004008644a
R13: 000000000000000d R14: 000055de7fcd34d0 R15: 000055de7fcd3080
 </TASK>
Modules linked in: uinput snd_seq_dummy snd_hrtimer nft_objref nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set rfkill nf_tables nfnetlink qrtr vboxsf sunrpc intel_rapl_msr snd_intel8x0 snd_ac97_codec ac97_bus joydev snd_seq snd_seq_device snd_pcm intel_rapl_common e1000 snd_timer snd vboxguest pcspkr i2c_piix4 soundcore zram crct10dif_pclmul crc32_pclmul crc32c_intel vmwgfx ghash_clmulni_intel drm_ttm_helper serio_raw video ttm ata_generic pata_acpi ip6_tables ip_tables ipmi_devintf ipmi_msghandler fuse
CR2: 0000000000000000