Bug 2521847

Summary: Kernel panic at skb_clone on 7.1.8-200.fc44.x86_64 during a Google Meet call with a screen being shared, while Podman containers, VSCode, and Slack were running in the background.
Product: [Fedora] Fedora Reporter: Dalibor Kricka <dkricka>
Component: kernelAssignee: Justin M. Forbes <jforbes>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: unspecified    
Version: 44CC: acaringi, adscvr, airlied, hans, hpa, jforbes, junjie.cao, kernel-maint, linville, masami256, mchehab, nickolasjcarr, ptalbert, steved, suraj.ghimire7
Target Milestone: ---   
Target Release: ---   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: kernel-7.1.13-200.fc44 kernel-7.1.13-100.fc43 Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2026-09-04 01:11:43 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Dalibor Kricka 2026-08-24 12:47:17 UTC
1. Please describe the problem:
The whole system crashed with a black screen, error trace QR-Code, and the title "Kernel panic! Fatal exception in interupt" on 7.1.8-200.fc44.x86_64 during a Google Meet call with a screen being shared, while Podman containers, VSCode, and Slack were running in the background.


2. What is the Version-Release number of the kernel:
7.1.8-200.fc44.x86_64


3. Did it work previously in Fedora? If so, what kernel version did the issue
   *first* appear?  Old kernels are available for download at
   https://koji.fedoraproject.org/koji/packageinfo?packageID=8 :
First time this happened to me.


4. Can you reproduce this issue? If so, please provide the steps to reproduce
   the issue below:
I did not managed to reproduce it.


5. Does this problem occur with the latest Rawhide kernel? To install the
   Rawhide kernel, run ``sudo dnf install fedora-repos-rawhide`` followed by
   ``sudo dnf update --enablerepo=rawhide kernel``:
I did not managed to reproduce it.


6. Are you running any modules that not shipped with directly Fedora's kernel?:
I don't think so.


7. Please attach the kernel logs. You can get the complete kernel log
   for a boot with ``journalctl --no-hostname -k > dmesg.txt``. If the
   issue occurred on a previous boot, use the journalctl ``-b`` flag.

Linux kernel version: 7.1.8-200.fc44.x86_64
Architecture: x86_64
Fedora version: 44

[522705.613410] RSP: 002b:00007ffdc6785ee0 EFLAGS: 00000202 ORIG_RAX: 0000000000000001
[522705.613412] RAX: ffffffffffffffda RBX: 000055eb6b88fb90 RCX: 00007fe66767654e
[522705.613413] RDX: 0000000000000027 RSI: 000055eb6b81bd50 RDI: 0000000000000010
[522705.613414] RBP: 00007ffdc6785ef0 R08: 0000000000000000 R09: 0000000000000000
[522705.613415] R10: 0000000000000000 R11: 0000000000000202 R12: 0000000000000010
[522705.613417] R13: 0000000000000002 R14: 000055eb6b81bca0 R15: 000055eb6b81bd50
[522705.613419]  </TASK>
[522705.613420] Modules linked in: nft_nat veth bridge stp llc tun hid_sensor_hub overlay snd_usb_audio snd_usbmidi_lib snd_ump snd_rawmidi typec_displayport nft_masq uinput rfcomm nf_conntrack_netlink snd_seq_dummy snd_hrtimer xt_CT ip_set_hash_net ip_set xt_connmark xt_TCPMSS xt_MASQUERADE xt_mark xt_conntrack nft_compat wireguard libcurve25519 ip6_udp_tunnel udp_tunnel nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 nf_tables nfnetlink qrtr uhid bnep sunrpc binfmt_misc snd_soc_skl_hda_dsp snd_soc_intel_sof_board_helpers snd_soc_intel_hda_dsp_common snd_sof_probes vfat fat snd_hda_codec_intelhdmi snd_hda_codec_hdmi snd_hda_codec_alc269 snd_hda_codec_realtek_lib snd_hda_scodec_component snd_hda_codec_generic snd_soc_dmic snd_hda_intel snd_sof_pci_intel_mtl snd_sof_intel_hda_generic soundwire_intel snd_sof_intel_hda_sdw_bpt iwlmld r8153_ecm
[522705.613465]  snd_sof_intel_hda_common cdc_ether usbnet snd_soc_hdac_hda snd_sof_intel_hda_mlink snd_sof_intel_hda mac80211 intel_rapl_msr soundwire_cadence snd_sof_pci intel_uncore_frequency snd_sof_xtensa_dsp intel_uncore_frequency_common snd_sof x86_pkg_temp_thermal intel_powerclamp coretemp snd_sof_utils snd_hda_ext_core kvm_intel snd_hda_codec libarc4 snd_hda_core snd_intel_dspcfg snd_intel_sdw_acpi kvm snd_soc_acpi_intel_match snd_soc_acpi_intel_sdca_quirks soundwire_generic_allocation iwlwifi snd_soc_sdw_utils snd_hda_scodec_tas2781_i2c snd_soc_acpi uvcvideo snd_hwdep btusb snd_hda_scodec_tas2781 soundwire_bus btmtk uvc snd_soc_tas2781_comlib_i2c videobuf2_vmalloc snd_soc_tas2781_fmwlib snd_soc_sdca spi_nor videobuf2_memops btrtl irqbypass snd_soc_tas2781_comlib videobuf2_v4l2 btbcm iTCO_wdt rapl crc8 btintel intel_cstate snd_ctl_led mei_gsc_proxy mei_wdt spd5118 mtd intel_pmc_bxt snd_soc_core r8152 think_lmi videobuf2_common intel_uncore cfg80211 bluetooth mii firmware_attributes_class snd_compress videodev
[522705.613510]  wmi_bmof ac97_bus processor_thermal_device_pci pcspkr processor_thermal_device snd_pcm_dmaengine snd_seq thinkpad_acpi processor_thermal_wt_hint mc snd_seq_device sparse_keymap platform_temperature_control snd_pcm rfkill processor_thermal_soc_slider int3403_thermal processor_thermal_rfim mei_me int3400_thermal snd_timer intel_pmc_core processor_thermal_rapl acpi_thermal_rel intel_rapl_common snd mei processor_thermal_wt_req i2c_i801 pmt_telemetry spi_intel_pci processor_thermal_power_floor pmt_discovery joydev soundcore i2c_smbus acpi_tad spi_intel acpi_pad pmt_class intel_pmc_ssram_telemetry processor_thermal_mbox idma64 igen6_edac int340x_thermal_zone zram lz4hc_compress lz4_compress dm_crypt hid_logitech_hidpp hid_logitech_dj xe drm_ttm_helper drm_suballoc_helper gpu_sched drm_gpuvm drm_exec drm_gpusvm_helper i915 ucsi_acpi drm_buddy typec_ucsi i2c_algo_bit ttm typec hid_multitouch rtsx_pci_sdmmc nvme mmc_core drm_display_helper thunderbolt i2c_hid_acpi i2c_hid nvme_core intel_vpu video rtsx_pci cec
[522705.613559]  nvme_keyring wmi nvme_auth pinctrl_meteorlake intel_vsec serio_raw fuse ntsync i2c_dev
[522705.613569] ---[ end trace 0000000000000000 ]---
[522705.613572] RIP: 0010:skb_clone+0x159/0x1e0
[522705.613576] Code: 48 89 90 d0 00 00 00 8b 93 d8 00 00 00 c7 80 dc 00 00 00 01 00 00 00 89 90 d8 00 00 00 8b 93 c0 00 00 00 48 03 93 c8 00 00 00 <f0> ff 42 20 80 4b 7e 01 48 83 c4 08 5b c3 cc cc cc cc 48 8b 93 d0
[522705.613578] RSP: 0018:ffffcb72004fcd50 EFLAGS: 00010286
[522705.613579] RAX: ffff8a7543afb500 RBX: ffff8a7554ffad00 RCX: 0000000000000020
[522705.613580] RDX: ffff8a73736d279f RSI: 0000000000000003 RDI: ffff8a6e63490f00
[522705.613582] RBP: ffffffff91fc9900 R08: 00000000ffffff01 R09: ffff8a7543afb500
[522705.613583] R10: ffff8a6dc4349120 R11: ffff8a6e63490f00 R12: ffff8a73736d272d
[522705.613584] R13: 0000000000000000 R14: 000000000000001c R15: ffff8a7554ffad00
[522705.613585] FS:  00007fe668566480(0000) GS:ffff8a7d5e415000(0000) knlGS:0000000000000000
[522705.613586] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[522705.613588] CR2: 00007fb8de35a000 CR3: 0000000112919004 CR4: 0000000000f72ef0
[522705.613589] PKRU: 55555554
[522705.613590] Kernel panic - not syncing: Fatal exception in interrupt
[522705.613758] Kernel Offset: 0xd200000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff)


Reproducible: Always

Comment 1 junjie.cao 2026-09-01 00:59:41 UTC
Same instruction as bug 2521546, decoded from your inline Oops: the
Code bytes at skb_clone+0x159 are "f0 ff 42 20" = lock incl 0x20(%rdx),
the atomic_inc on skb_shinfo(skb)->dataref, with RDX =
ffff8a73736d279f. That puts dataref at ...27bf, byte 63 of a 64-byte
cache line, so the 4-byte atomic straddles two lines: a kernel-mode
split lock, fatal on Intel. skb->head is misaligned by 0x1f because it
came from a page_pool fragment at an odd offset -- your module list has
veth/bridge (Podman), and veth's skb_pp_cow_data() is one of the callers
that leaves the pool's fragment offset odd.

Upstream fix, in net.git with Cc: stable:
https://git.kernel.org/netdev/net/c/dc0df5a0c62c
Fedora 44 backport MR:
https://gitlab.com/cki-project/kernel-ark/-/merge_requests/4730

Workaround until it lands: boot with split_lock_detect=off.

Comment 2 Fedora Update System 2026-09-02 17:55:19 UTC
FEDORA-2026-a7b1ccd14c (kernel-7.1.13-100.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-a7b1ccd14c

Comment 3 Fedora Update System 2026-09-02 17:56:00 UTC
FEDORA-2026-0d885c0533 (kernel-7.1.13-200.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-0d885c0533

Comment 4 Fedora Update System 2026-09-03 01:39:06 UTC
FEDORA-2026-0d885c0533 has been pushed to the Fedora 44 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-0d885c0533`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-0d885c0533

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 5 Fedora Update System 2026-09-03 01:54:45 UTC
FEDORA-2026-a7b1ccd14c has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-a7b1ccd14c`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-a7b1ccd14c

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 6 Fedora Update System 2026-09-04 01:11:43 UTC
FEDORA-2026-0d885c0533 (kernel-7.1.13-200.fc44) has been pushed to the Fedora 44 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 7 Fedora Update System 2026-09-04 01:28:06 UTC
FEDORA-2026-a7b1ccd14c (kernel-7.1.13-100.fc43) has been pushed to the Fedora 43 stable repository.
If problem still persists, please make note of it in this bug report.