Been trying to track this bug down. The original mitigation did not
work. Instead, I'm mitigating by setting
kernel.apparmor_cache_timeout=0.
With AppArmor prompting enabled, notify.c arms a 5-second reclaim timer
on an audit-cache node without checking whether the node was actually
inserted into the cache. When an equivalent entry already exists the
node is not inserted, nothing holds a reference to it, and it is freed
via call_rcu() as soon as the requesting syscall returns — timer still
armed. The stale timer fires into freed memory; slot reuse then links
the same timer_list into two wheel buckets, and detach_timer() faults on
LIST_POISON2.
Steps to reproduce
Ubuntu 26.04 with prompting on and the prompting-client / desktop-
security-center snaps installed:
sudo snap set system experimental.apparmor-prompting=true
sysctl kernel.apparmor_cache_timeout # 5 (default)
Log into a desktop session and launch the chromium snap.
Download several large files — concurrent downloads work best. Answer the
permission prompts, or leave them standing. Chromium’s download path creates
and renames files continuously:
__x64_sys_creat → … → apparmor_path_mknod → aa_audit_file →
check_user
Each creat() on an un-cached path produces a prompt; each response arms the
temporal-cache timer.
Watch the kernel log. Non-fatal WARNs appear within minutes; the panic
follows within seconds to hours:
dmesg -w | grep -E 'workqueue.c:2351|dead00000000012a'
Confirm the owner on any affected system, no rebuild (bpftrace; BTF
is in the Ubuntu kernel):
sudo bpftrace -e 'kprobe:__queue_work { $w=(struct work_struct*)arg2;
if ((uint64)$w->entry.next==0) {
printf("CORRUPT %p func=%s\n", arg2, ksym((uint64)$w->func)); } }'
CORRUPT 0xffff88bb937d0fc8 func=audit_cache_work_function
I'd imagine something like the following is probably what is needed, but I
don't have the experience in kernel development to know if I'm missing things
here.
- insert_in_cache(knotif);
- INIT_DELAYED_WORK(&node->work, audit_cache_work_function);
- schedule_delayed_work(&node->work,
- secs_to_jiffies(aa_cache_timeout));
+ if (insert_in_cache(knotif)) {
+ INIT_DELAYED_WORK(&node->work,
audit_cache_work_function);
+ schedule_delayed_work(&node->work,
+
secs_to_jiffies(aa_cache_timeout));
+ }
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2165930
Title:
Kernel oops (GPF) in __run_timers via tmigr_handle_remote on
7.0.0-28-generic under network load
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2165930/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs