Nov 8 12:52:19 g5n kernel: [69088.751995] grsec: (miro:U:/) exec of /usr/bin/qemu-img (qemu-img create -f qcow2 GentooVM.img 15G ) by /usr/bin/qemu-img[bash:15342] uid/euid:1000/1000 gid/egid:1000/1000, parent /bin/bash[bash:4203] uid/euid:1000/1000 gid/egid:1000/1000 Nov 8 12:56:01 g5n kernel: [69310.752897] grsec: (admin:S:/) exec of /bin/sleep (sleep 30 ) by /bin/sleep[bash:15346] uid/euid:0/0 gid/egid:0/0, parent /bin/bash[bash:4067] uid/euid:0/0 gid/egid:0/0 Nov 8 12:56:09 g5n kernel: [69318.246656] grsec: (miro:U:/) exec of /usr/local/bin/GentooVM (GentooVM -boot d -cdrom install-amd64-minimal-20161020.iso ) by /usr/local/bin/GentooVM[bash:15349] uid/euid:1000/1000 gid/egid:1000/1000, parent /bin/bash[bash:4203] uid/euid:1000/1000 gid/egid:1000/1000 Nov 8 12:56:09 g5n kernel: [69318.266743] grsec: (miro:U:/usr/bin/qemu-system-x86_64) exec of /usr/bin/qemu-system-x86_64 (qemu-system-x86_64 -enable-kvm -cpu host -drive file=GentooVM.img,if=virtio -netdev user,id=vmnic,hostname=gentoovm -device virt) by /usr/bin/qemu-system-x86_64[GentooVM:15349] uid/euid:1000/1000 gid/egid:1000/1000, parent /bin/bash[bash:4203] uid/euid:1000/1000 gid/egid:1000/1000 Nov 8 12:56:11 g5n kernel: [69320.277033] BUG: unable to handle kernel NULL pointer dereference at (nil) Nov 8 12:56:11 g5n kernel: [69320.277231] IP: [] kvm_irqfd_release+0x27/0x85 Nov 8 12:56:11 g5n kernel: [69320.277373] PGD afe6a067 PUD 0 Nov 8 12:56:11 g5n kernel: [69320.277456] Oops: 0000 [#1] PREEMPT SMP Nov 8 12:56:11 g5n kernel: [69320.277563] Modules linked in: Nov 8 12:56:11 g5n kernel: [69320.277639] CPU: 1 PID: 15350 Comm: qemu-system-x86 Not tainted 4.7.10-hardened-r2-161107_06 #1 Nov 8 12:56:11 g5n kernel: [69320.277820] Hardware name: To Be Filled By O.E.M. To Be Filled By O.E.M./970 Extreme4, BIOS P2.60 11/11/2013 Nov 8 12:56:11 g5n kernel: [69320.278023] task: ffff8800afebda00 ti: ffff8800afebe368 task.ti: ffff8800afebe368 Nov 8 12:56:11 g5n kernel: [69320.278177] RIP: 0010:[] [] kvm_irqfd_release+0x27/0x85 Nov 8 12:56:11 g5n kernel: [69320.278361] RSP: 0018:ffffc90007903bc0 EFLAGS: 00010047 Nov 8 12:56:11 g5n kernel: [69320.278473] RAX: 0000000000000000 RBX: ffff8803c4570000 RCX: 0000000000000001 Nov 8 12:56:11 g5n kernel: [69320.278619] RDX: 0000000000000001 RSI: ffff8800bd64b500 RDI: ffff8803c4570a50 Nov 8 12:56:11 g5n kernel: [69320.278790] RBP: ffffc90007903bd8 R08: 0000000000000000 R09: 0000000000000000 Nov 8 12:56:11 g5n kernel: [69320.278936] R10: ffffc90007903c08 R11: 0000000000000004 R12: ffff8803c4570a58 Nov 8 12:56:11 g5n kernel: [69320.279083] R13: ffff8803c4570a50 R14: ffff8800b98c84b0 R15: ffff88042d75e528 Nov 8 12:56:11 g5n kernel: [69320.279232] FS: 00000385cce0a700(0000) GS:ffff88043fc80000(0000) knlGS:0000000000000000 Nov 8 12:56:11 g5n kernel: [69320.279398] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 Nov 8 12:56:11 g5n kernel: [69320.279517] CR2: 0000000000000000 CR3: 0000000002196000 CR4: 00000000000006f0 Nov 8 12:56:11 g5n kernel: [69320.279663] Stack: Nov 8 12:56:11 g5n kernel: [69320.279708] ffff8803c4570000 0000000000000008 ffff8800b98015e0 ffffc90007903bf0 Nov 8 12:56:11 g5n kernel: [69320.279880] ffffffff8101a6a5 ffff8800bd64b500 ffffc90007903c28 ffffffff8119e589 Nov 8 12:56:11 g5n kernel: [69320.280073] ffff8800bd64b590 ffff8800afebda00 ffff8800afebe344 ffff8800bd64b390 Nov 8 12:56:11 g5n kernel: [69320.280244] Call Trace: Nov 8 12:56:11 g5n kernel: [69320.280304] [] kvm_vm_release+0x14/0x2f Nov 8 12:56:11 g5n kernel: [69320.280422] [] __fput+0x10d/0x1c5 Nov 8 12:56:11 g5n kernel: [69320.280529] [] ____fput+0x14/0x25 Nov 8 12:56:11 g5n kernel: [69320.280636] [] task_work_run+0x8f/0xb6 Nov 8 12:56:11 g5n kernel: [69320.280754] [] do_exit+0x412/0x98f Nov 8 12:56:11 g5n kernel: [69320.280864] [] ? _raw_spin_unlock+0x1c/0x3e Nov 8 12:56:11 g5n kernel: [69320.280989] [] ? futex_wait+0x173/0x239 Nov 8 12:56:11 g5n kernel: [69320.281107] [] do_group_exit+0x48/0xb8 Nov 8 12:56:11 g5n kernel: [69320.281246] [] get_signal+0x472/0x4a6 Nov 8 12:56:11 g5n kernel: [69320.281361] [] do_signal+0x38/0x55d Nov 8 12:56:11 g5n kernel: [69320.281474] [] prepare_exit_to_usermode+0x67/0xa6 Nov 8 12:56:11 g5n kernel: [69320.281609] [] syscall_return_slowpath+0x4d/0x67 Nov 8 12:56:11 g5n kernel: [69320.281742] [] entry_SYSCALL_64_fastpath+0xa1/0xa3 Nov 8 12:56:11 g5n kernel: [69320.281877] Code: 00 00 00 00 55 48 89 e5 41 55 41 54 49 89 fc 4d 8d ac 24 50 0a 00 00 49 81 c4 58 0a 00 00 53 4c 89 ef e8 58 03 b5 00 49 8b 04 24 <48> 8b 18 48 8d b8 40 ff ff ff 48 81 eb c0 00 00 00 48 8d 87 c0 Nov 8 12:56:11 g5n kernel: [69320.282654] RIP [] kvm_irqfd_release+0x27/0x85 Nov 8 12:56:11 g5n kernel: [69320.282789] RSP Nov 8 12:56:11 g5n kernel: [69320.282864] CR2: 0000000000000000 Nov 8 12:56:11 g5n kernel: [69320.305597] ---[ end trace 7777ce10174b6c20 ]--- Nov 8 12:56:11 g5n kernel: [69320.305605] grsec: banning user with uid 1000 until system restart for suspicious kernel crash Nov 8 12:56:11 g5n kernel: [69320.305878] Fixing recursive fault but reboot is needed! Nov 8 12:56:11 g5n kernel: [69320.305888] BUG: scheduling while atomic: qemu-system-x86/15350/0x00000002 Nov 8 12:56:11 g5n kernel: [69320.305893] Modules linked in: Nov 8 12:56:11 g5n kernel: [69320.305899] Preemption disabled at:[] ffffffff810db1fa Nov 8 12:56:11 g5n kernel: [69320.305908] Nov 8 12:56:11 g5n kernel: [69320.305917] CPU: 1 PID: 15350 Comm: qemu-system-x86 Tainted: G D 4.7.10-hardened-r2-161107_06 #1 Nov 8 12:56:11 g5n kernel: [69320.305924] Hardware name: To Be Filled By O.E.M. To Be Filled By O.E.M./970 Extreme4, BIOS P2.60 11/11/2013 Nov 8 12:56:11 g5n kernel: [69320.305930] 0000000000000086 0000000000000086 ffffc90007903870 ffffffff8147b5c6 Nov 8 12:56:11 g5n kernel: [69320.305944] 0000000000000003 ffff8800afebda00 0000000000000100 ffffc90007903888 Nov 8 12:56:11 g5n kernel: [69320.305957] ffffffff810dab8a ffff88043fc91f00 ffffc900079038d0 ffffffff81b6c40d Nov 8 12:56:11 g5n kernel: [69320.305968] Call Trace: Nov 8 12:56:11 g5n kernel: [69320.305982] [] dump_stack+0x50/0x7b Nov 8 12:56:11 g5n kernel: [69320.305992] [] __schedule_bug+0x91/0xae Nov 8 12:56:11 g5n kernel: [69320.306000] [] __schedule+0x68/0x55f Nov 8 12:56:11 g5n kernel: [69320.306007] [] schedule+0x8a/0xac Nov 8 12:56:11 g5n kernel: [69320.306017] [] do_exit+0x108/0x98f Nov 8 12:56:11 g5n kernel: [69320.306025] [] do_group_exit+0x48/0xb8 Nov 8 12:56:11 g5n kernel: [69320.306035] [] oops_end+0x84/0x98 Nov 8 12:56:11 g5n kernel: [69320.306046] [] no_context+0x395/0x3fd Nov 8 12:56:11 g5n kernel: [69320.306056] [] __bad_area_nosemaphore+0x78/0x538 Nov 8 12:56:11 g5n kernel: [69320.306066] [] ? __free_slab+0x19c/0x1b7 Nov 8 12:56:11 g5n kernel: [69320.306077] [] bad_area_nosemaphore+0x33/0x43 Nov 8 12:56:11 g5n kernel: [69320.306087] [] __do_page_fault+0x190/0x400 Nov 8 12:56:11 g5n kernel: [69320.306098] [] do_page_fault+0x20/0x30 Nov 8 12:56:11 g5n kernel: [69320.306108] [] page_fault+0x22/0x30 Nov 8 12:56:11 g5n kernel: [69320.306118] [] ? kvm_irqfd_release+0x27/0x85 Nov 8 12:56:11 g5n kernel: [69320.306128] [] kvm_vm_release+0x14/0x2f Nov 8 12:56:11 g5n kernel: [69320.306136] [] __fput+0x10d/0x1c5 Nov 8 12:56:11 g5n kernel: [69320.306144] [] ____fput+0x14/0x25 Nov 8 12:56:11 g5n kernel: [69320.306152] [] task_work_run+0x8f/0xb6 Nov 8 12:56:11 g5n kernel: [69320.306162] [] do_exit+0x412/0x98f Nov 8 12:56:11 g5n kernel: [69320.306171] [] ? _raw_spin_unlock+0x1c/0x3e Nov 8 12:56:11 g5n kernel: [69320.306180] [] ? futex_wait+0x173/0x239 Nov 8 12:56:11 g5n kernel: [69320.306188] [] do_group_exit+0x48/0xb8 Nov 8 12:56:11 g5n kernel: [69320.306197] [] get_signal+0x472/0x4a6 Nov 8 12:56:11 g5n kernel: [69320.306207] [] do_signal+0x38/0x55d Nov 8 12:56:11 g5n kernel: [69320.306217] [] prepare_exit_to_usermode+0x67/0xa6 Nov 8 12:56:11 g5n kernel: [69320.306226] [] syscall_return_slowpath+0x4d/0x67 Nov 8 12:56:11 g5n kernel: [69320.306234] [] entry_SYSCALL_64_fastpath+0xa1/0xa3 Nov 8 12:56:11 g5n kernel: [69320.367143] grsec: (root:U:/sbin/agetty) exec of /sbin/agetty (/sbin/agetty 38400 tty6 linux ) by /sbin/agetty[init:15351] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0 Nov 8 12:56:31 g5n kernel: [69340.759358] grsec: (admin:S:/) exec of /bin/cat (cat /var/log/messages ) by /bin/cat[bash:15354] uid/euid:0/0 gid/egid:0/0, parent /bin/bash[bash:4067] uid/euid:0/0 gid/egid:0/0 Nov 8 12:56:31 g5n kernel: [69340.810743] grsec: (admin:S:/) exec of /bin/date (date +%y%m%d_%H%M%S ) by /bin/date[bash:15357] uid/euid:0/0 gid/egid:0/0, parent /bin/bash[bash:15355] uid/euid:0/0 gid/egid:0/0 Nov 8 12:56:31 g5n kernel: [69340.815790] grsec: (admin:S:/) exec of /bin/grep (grep --colour=auto -aE -A30000 68798.280977 ) by /bin/grep[bash:15355] uid/euid:0/0 gid/egid:0/0, parent /bin/bash[bash:4067] uid/euid:0/0 gid/egid:0/0