# Redacted crash(8) analysis — (Dell PowerEdge R740), kdump of 2026-06-23. # Source: crash(8) over vmcore + vmlinux debuginfo for 5.14.0-687.15.1.el9_8. # Anonymized: , , , , , , # . Nothing else altered. (The crash dump itself carries the real # NODENAME etc.; this excerpt is the redacted copy for the public bug tracker.) # Note: the autofs "given options" line below was truncated in the source at # "closetimeo="; the effective expanded options are the authoritative ones. given options via autofs: sec=krb5,cruid=${UID},uid=${UID},gid=${GID},forceuid,forcegid,iocharset =utf8,vers=3.0,nosuid,nodev,dir_mode=0700,file_mode=0700,noserverino,ca che=none after option expanding: rw,nosuid,nodev,relatime,vers=3.0,sec=krb5,cruid=,cache=none, upcall_target=app,username=,uid=,forceuid,gid=, forcegid,addr=,file_mode=0700,dir_mode=0700,iocharset=utf8 ,soft,nounix,mapposix,reparse=nfs,nativesocket,symlink=native,rsize=419 4304,wsize=4194304,bsize=1048576,echo_interval=60,actimeo=1,closetimeo= KERNEL: /usr/lib/debug/lib/modules/5.14.0-687.15.1.el9_8.x86_64/vmlinux [TAINTED] DUMPFILE: vmcore [PARTIAL DUMP] CPUS: 40 DATE: Tue Jun 23 16:27:35 CEST 2026 UPTIME: 17:46:27 LOAD AVERAGE: 4.56, 4.12, 4.17 TASKS: 2771 NODENAME: RELEASE: 5.14.0-687.15.1.el9_8.x86_64 VERSION: #1 SMP PREEMPT_DYNAMIC Thu Jun 11 08:51:45 EDT 2026 MACHINE: x86_64 (3100 Mhz) MEMORY: 766.6 GB PANIC: "kernel BUG at mm/filemap.c:1593!" PID: 70950 COMMAND: "dask worker [tc" TASK: ffff893e88be0000 [THREAD_INFO: ffff893e88be0000] CPU: 22 STATE: TASK_RUNNING (PANIC) 1567 /** 1568 * folio_end_writeback - End writeback against a folio. 1569 * @folio: The folio. 1570 */ 1571 void folio_end_writeback(struct folio *folio) 1572 { 0xffffffff813791a0 <+0>: call 0xffffffff8107d860 <__fentry__> 0xffffffff813791a9 <+9>: mov %rdi,%rbp 1573 /* 1574 * folio_test_clear_reclaim() could be used here but it is an 1575 * atomic operation and overkill in this particular case. Failing 1576 * to shuffle a folio marked for immediate reclaim is too mild 1577 * a gain to justify taking an atomic operation penalty at the 1578 * end of every folio writeback. 1579 */ 1580 if (folio_test_reclaim(folio)) { 0xffffffff813791ac <+12>: test $0x40000,%eax 0xffffffff813791b1 <+17>: jne 0xffffffff813791fe 1581 folio_clear_reclaim(folio); 1582 folio_rotate_reclaimable(folio); 0xffffffff81379203 <+99>: call 0xffffffff8138c5f0 0xffffffff81379208 <+104>: jmp 0xffffffff813791b3 1583 } 1584 1585 /* 1586 * Writeback does not hold a folio reference of its own, relying 1587 * on truncation to wait for the clearing of PG_writeback. 1588 * But here we must make sure that the folio is not freed and 1589 * reused before the folio_wake(). 1590 */ 1591 folio_get(folio); 1592 if (!__folio_end_writeback(folio)) 0xffffffff813791b7 <+23>: mov %rbp,%rdi 0xffffffff813791ba <+26>: call 0xffffffff813881d0 <__folio_end_writeback> 0xffffffff813791bf <+31>: test %al,%al 0xffffffff813791c1 <+33>: je 0xffffffff8137921d 1593 BUG(); 0xffffffff8137921d <+125>: ud2 1594 1595 smp_mb__after_atomic(); 1596 folio_wake(folio, PG_writeback); 1597 acct_reclaim_writeback(folio); 1598 folio_put(folio); 1599 } 0xffffffff813791f8 <+88>: pop %rbp 0xffffffff813791f9 <+89>: jmp 0xffffffff81d65cb0 <__x86_return_thunk> 0xffffffff8137920d <+109>: pop %rbp PID: 70950 TASK: ffff893e88be0000 CPU: 22 COMMAND: "dask worker [tc" #0 [ffffcb0eb1297830] machine_kexec at ffffffffa527f00e #1 [ffffcb0eb1297888] __crash_kexec at ffffffffa5425d8a #2 [ffffcb0eb1297948] crash_kexec at ffffffffa5426370 #3 [ffffcb0eb1297950] oops_end at ffffffffa5238fd6 #4 [ffffcb0eb1297970] do_trap at ffffffffa5234d8f #5 [ffffcb0eb12979c0] do_error_trap at ffffffffa5234e35 #6 [ffffcb0eb1297a00] exc_invalid_op at ffffffffa5f4d77e #7 [ffffcb0eb1297a20] asm_exc_invalid_op at ffffffffa6000b36 [exception RIP: folio_end_writeback+125] RIP: ffffffffa557921d RSP: ffffcb0eb1297ad8 RFLAGS: 00010246 RAX: 0000000000000b00 RBX: ffff899f43699680 RCX: 0000000000000000 RDX: ffff893e88be0000 RSI: ffffedc013097e00 RDI: ffff893e88be0000 RBP: ffffedc013097e00 R8: ffffcb0eb1297aa8 R9: 000000008024001f R10: 000000000000001c R11: ffff899f43699680 R12: 0000000000000bd8 R13: 0000000000000000 R14: ffffcb0eb1297c60 R15: ffff89961e9d9800 ORIG_RAX: ffffffffffffffff CS: 0010 SS: 0018 #8 [ffffcb0eb1297ae0] cifs_writepages at ffffffffc28095e8 [cifs] #9 [ffffcb0eb1297ba8] do_writepages at ffffffffa5587cd5 #10 [ffffcb0eb1297c38] filemap_fdatawrite_wbc at ffffffffa55774a6 #11 [ffffcb0eb1297c58] __filemap_fdatawrite_range at ffffffffa557c194 #12 [ffffcb0eb1297cd0] filemap_write_and_wait_range at ffffffffa557c3ee #13 [ffffcb0eb1297cf8] cifs_flush at ffffffffc280b293 [cifs] #14 [ffffcb0eb1297d18] filp_flush at ffffffffa5688ace #15 [ffffcb0eb1297d38] __x64_sys_close at ffffffffa5688b9e #16 [ffffcb0eb1297d50] do_syscall_64 at ffffffffa5f4cf8f #17 [ffffcb0eb1297f50] entry_SYSCALL_64_after_hwframe at ffffffffa600012b RIP: 00007fae16303f3b RSP: 00007fadee5db388 RFLAGS: 00000202 RAX: ffffffffffffffda RBX: 00007fac240977a0 RCX: 00007fae16303f3b RDX: 00007fae163f79e0 RSI: 00000000fbad2404 RDI: 0000000000000038 RBP: 0000000000000000 R8: 0000000000000000 R9: 0000000000000020 R10: 00000000002aa212 R11: 0000000000000202 R12: 00007fae163f85e0 R13: 00007fac670c7b18 R14: 00007fadee5db458 R15: 0000000000000002 ORIG_RAX: 0000000000000003 CS: 0033 SS: 002b kmem ffff893e88be0000 CACHE OBJSIZE ALLOCATED TOTAL SLABS SSIZE NAME ffff8935c021d100 9096 2770 2964 988 32k task_struct SLAB MEMORY NODE TOTAL ALLOCATED FREE ffffedbea722f800 ffff893e88be0000 0 3 2 1 FREE / [ALLOCATED] [ffff893e88be0000] PID: 70950 COMMAND: "dask worker [tc" TASK: ffff893e88be0000 [THREAD_INFO: ffff893e88be0000] CPU: 22 STATE: TASK_RUNNING (PANIC) PAGE PHYSICAL MAPPING INDEX CNT FLAGS ffffedbea722f800 9c8be0000 dead000000000001 ffff893e88be23c0 1 17ffffc0000840 slab,head [63988.140018] CIFS: VFS: \\ Error -32 sending data on socket to server [63988.140045] ------------[ cut here ]------------ [63988.140046] refcount_t: underflow; use-after-free. [63988.140059] WARNING: CPU: 22 PID: 70950 at lib/refcount.c:28 refcount_warn_saturate+0xba/0x110 [63988.140067] Modules linked in: nls_utf8 cifs cifs_arc4 rdma_cm iw_cm ib_cm ib_core cifs_md4 dns_resolver rfkill nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 nf_tables nfnetlink qrtr vfat fat nvidia_uvm(POE) nvidia_drm(POE) nvidia_modeset(POE) nvidia(POE) intel_rapl_msr intel_rapl_common intel_uncore_frequency intel_uncore_frequency_common skx_edac nfit libnvdimm x86_pkg_temp_thermal intel_powerclamp coretemp kvm_intel kvm ipmi_ssif drm_ttm_helper ttm ipmi_si iTCO_wdt iTCO_vendor_support rapl lpc_ich acpi_power_meter intel_cstate video intel_uncore dcdbas i2c_i801 dell_smbios dell_wmi_descriptor mei_me acpi_ipmi mei wmi_bmof ipmi_devintf ipmi_msghandler pcspkr i2c_smbus intel_pch_thermal auth_rpcgss sunrpc xfs libcrc32c sd_mod sg mgag200 drm_client_lib i2c_algo_bit drm_shmem_helper drm_kms_helper ahci libahci crct10dif_pclmul crc32_pclmul libata drm bnxt_en crc32c_intel megaraid_sas tg3 [63988.140123] ghash_clmulni_intel wmi dm_mirror dm_region_hash dm_log dm_mod i2c_dev fuse [63988.140130] CPU: 22 PID: 70950 Comm: dask worker [tc Kdump: loaded Tainted: P OE ------ --- 5.14.0-687.15.1.el9_8.x86_64 #1 [63988.140132] Hardware name: Dell Inc. PowerEdge R740/, BIOS 2.26.1 01/28/2026 [63988.140133] RIP: 0010:refcount_warn_saturate+0xba/0x110 [63988.140136] Code: 01 01 e8 69 b1 a5 ff 0f 0b c3 cc cc cc cc 80 3d 74 61 c9 01 00 75 85 48 c7 c7 a8 4c 91 a6 c6 05 64 61 c9 01 01 e8 46 b1 a5 ff <0f> 0b e9 0f b0 6a 00 80 3d 4f 61 c9 01 00 0f 85 5e ff ff ff 48 c7 [63988.140137] RSP: 0018:ffffcb0eb1297998 EFLAGS: 00010286 [63988.140139] RAX: 0000000000000000 RBX: ffff89963ec89ec0 RCX: 0000000000000027 [63988.140140] RDX: 0000000000000027 RSI: 00000000ffff7fff RDI: ffff899380ee0f08 [63988.140142] RBP: ffff89954451c9c0 R08: 0000000000000000 R09: ffffcb0eb1297840 [63988.140143] R10: ffffcb0eb1297838 R11: ffffffffa73e2ee8 R12: ffff89954451c800 [63988.140144] R13: ffff89a3b7f2ca80 R14: 00000000ffffff99 R15: ffff89954451c9f8 [63988.140145] FS: 00007fadee5dd640(0000) GS:ffff899380ec0000(0000) knlGS:0000000000000000 [63988.140147] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [63988.140148] CR2: 00007efc90327b68 CR3: 000000652bb80006 CR4: 00000000007726f0 [63988.140149] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [63988.140149] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [63988.140150] PKRU: 55555554 [63988.140151] Call Trace: [63988.140153] [63988.140156] ? __warn+0x84/0x140 [63988.140161] ? refcount_warn_saturate+0xba/0x110 [63988.140163] ? report_bug+0x16b/0x180 [63988.140168] ? handle_bug+0x3c/0x70 [63988.140174] ? exc_invalid_op+0x14/0x70 [63988.140176] ? asm_exc_invalid_op+0x16/0x20 [63988.140182] ? refcount_warn_saturate+0xba/0x110 [63988.140184] ? refcount_warn_saturate+0xba/0x110 [63988.140187] cifs_call_async+0x1ee/0x330 [cifs] [63988.140275] smb2_async_writev+0x473/0x6f0 [cifs] [63988.140334] ? __pfx_cifs_writedata_release+0x10/0x10 [cifs] [63988.140383] ? cifs_writepages+0x52f/0xbc0 [cifs] [63988.140431] cifs_writepages+0x52f/0xbc0 [cifs] [63988.140477] ? vfs_write+0x1a9/0x470 [63988.140481] do_writepages+0xd5/0x1b0 [63988.140485] ? syscall_exit_work+0xff/0x130 [63988.140490] ? syscall_exit_to_user_mode+0x19/0x40 [63988.140493] ? do_syscall_64+0x6b/0xe0 [63988.140496] filemap_fdatawrite_wbc+0x66/0x90 [63988.140499] __filemap_fdatawrite_range+0x54/0x80 [63988.140501] filemap_write_and_wait_range+0x3e/0xb0 [63988.140503] cifs_flush+0x73/0x120 [cifs] [63988.140550] filp_flush+0x2e/0x80 [63988.140553] __x64_sys_close+0x2e/0x80 [63988.140555] do_syscall_64+0x5f/0xe0 [63988.140558] ? do_numa_page+0x3a6/0x520 [63988.140562] ? __handle_mm_fault+0x2fb/0x650 [63988.140565] ? __count_memcg_events+0x50/0xb0 [63988.140568] ? mm_account_fault+0x6c/0x100 [63988.140571] ? handle_mm_fault+0x138/0x270 [63988.140573] ? do_user_addr_fault+0x35d/0x6a0 [63988.140576] ? clear_bhb_loop+0x40/0x90 [63988.140578] ? clear_bhb_loop+0x40/0x90 [63988.140580] ? clear_bhb_loop+0x40/0x90 [63988.140581] ? clear_bhb_loop+0x40/0x90 [63988.140582] ? clear_bhb_loop+0x40/0x90 [63988.140583] entry_SYSCALL_64_after_hwframe+0x76/0x7e [63988.140588] RIP: 0033:0x7fae16303f3b [63988.140590] Code: c3 66 0f 1f 44 00 00 48 8b 15 d9 6e 0f 00 f7 d8 64 89 02 b8 ff ff ff ff eb bc 0f 1f 44 00 00 f3 0f 1e fa b8 03 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 05 c3 0f 1f 40 00 48 8b 15 a9 6e 0f 00 f7 d8 [63988.140591] RSP: 002b:00007fadee5db388 EFLAGS: 00000202 ORIG_RAX: 0000000000000003 [63988.140593] RAX: ffffffffffffffda RBX: 00007fac240977a0 RCX: 00007fae16303f3b [63988.140594] RDX: 00007fae163f79e0 RSI: 00000000fbad2404 RDI: 0000000000000038 [63988.140595] RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000020 [63988.140596] R10: 00000000002aa212 R11: 0000000000000202 R12: 00007fae163f85e0 [63988.140597] R13: 00007fac670c7b18 R14: 00007fadee5db458 R15: 0000000000000002 [63988.140599] [63988.140599] ---[ end trace 0000000000000000 ]--- [63988.140612] CIFS: VFS: \\ Error -32 sending data on socket to server [63988.140627] ------------[ cut here ]------------ [63988.140636] kernel BUG at mm/filemap.c:1593! [63988.140650] invalid opcode: 0000 [#1] PREEMPT SMP NOPTI [63988.140660] CPU: 22 PID: 70950 Comm: dask worker [tc Kdump: loaded Tainted: P W OE ------ --- 5.14.0-687.15.1.el9_8.x86_64 #1 [63988.140673] Hardware name: Dell Inc. PowerEdge R740/, BIOS 2.26.1 01/28/2026 [63988.140683] RIP: 0010:folio_end_writeback+0x7d/0x80 [63988.140693] Code: ff 4d 34 74 12 5d c3 cc cc cc cc f0 80 67 02 fb e8 e8 33 01 00 eb a9 48 89 ef 5d e9 5d 16 01 00 48 89 ee e8 c5 23 02 00 eb d5 <0f> 0b 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 0f 1f 44 [63988.140713] RSP: 0018:ffffcb0eb1297ad8 EFLAGS: 00010246 [63988.140719] RAX: 0000000000000b00 RBX: ffff899f43699680 RCX: 0000000000000000 [63988.140728] RDX: ffff893e88be0000 RSI: ffffedc013097e00 RDI: ffff893e88be0000 [63988.140736] RBP: ffffedc013097e00 R08: ffffcb0eb1297aa8 R09: 000000008024001f [63988.140743] R10: 000000000000001c R11: ffff899f43699680 R12: 0000000000000bd8 [63988.140752] R13: 0000000000000000 R14: ffffcb0eb1297c60 R15: ffff89961e9d9800 [63988.140762] FS: 00007fadee5dd640(0000) GS:ffff899380ec0000(0000) knlGS:0000000000000000 [63988.140772] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [63988.140779] CR2: 00007efc90327b68 CR3: 000000652bb80006 CR4: 00000000007726f0 [63988.140787] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [63988.140796] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [63988.140804] PKRU: 55555554 [63988.140808] Call Trace: [63988.140813] [63988.140816] ? die+0x33/0x90 [63988.140826] ? do_trap+0xdf/0x110 [63988.140836] ? folio_end_writeback+0x7d/0x80 [63988.140844] ? do_error_trap+0x65/0x80 [63988.140850] ? folio_end_writeback+0x7d/0x80 [63988.140858] ? exc_invalid_op+0x4e/0x70 [63988.140866] ? folio_end_writeback+0x7d/0x80 [63988.140873] ? asm_exc_invalid_op+0x16/0x20 [63988.140883] ? folio_end_writeback+0x7d/0x80 [63988.140891] ? folio_end_writeback+0x1f/0x80 [63988.141114] cifs_writepages+0x998/0xbc0 [cifs] [63988.141375] do_writepages+0xd5/0x1b0 [63988.141551] ? syscall_exit_work+0xff/0x130 [63988.141723] ? syscall_exit_to_user_mode+0x19/0x40 [63988.141890] ? do_syscall_64+0x6b/0xe0 [63988.142050] filemap_fdatawrite_wbc+0x66/0x90 [63988.142205] __filemap_fdatawrite_range+0x54/0x80 [63988.142351] filemap_write_and_wait_range+0x3e/0xb0 [63988.142498] cifs_flush+0x73/0x120 [cifs] [63988.142709] filp_flush+0x2e/0x80 [63988.142856] __x64_sys_close+0x2e/0x80 [63988.143001] do_syscall_64+0x5f/0xe0 [63988.143151] ? do_numa_page+0x3a6/0x520 [63988.143297] ? __handle_mm_fault+0x2fb/0x650 [63988.143441] ? __count_memcg_events+0x50/0xb0 [63988.143586] ? mm_account_fault+0x6c/0x100 [63988.143727] ? handle_mm_fault+0x138/0x270 [63988.143868] ? do_user_addr_fault+0x35d/0x6a0 [63988.144007] ? clear_bhb_loop+0x40/0x90 [63988.144139] ? clear_bhb_loop+0x40/0x90 [63988.144267] ? clear_bhb_loop+0x40/0x90 [63988.144391] ? clear_bhb_loop+0x40/0x90 [63988.144509] ? clear_bhb_loop+0x40/0x90 [63988.144620] entry_SYSCALL_64_after_hwframe+0x76/0x7e [63988.144733] RIP: 0033:0x7fae16303f3b [63988.144842] Code: c3 66 0f 1f 44 00 00 48 8b 15 d9 6e 0f 00 f7 d8 64 89 02 b8 ff ff ff ff eb bc 0f 1f 44 00 00 f3 0f 1e fa b8 03 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 05 c3 0f 1f 40 00 48 8b 15 a9 6e 0f 00 f7 d8 [63988.145076] RSP: 002b:00007fadee5db388 EFLAGS: 00000202 ORIG_RAX: 0000000000000003 [63988.145197] RAX: ffffffffffffffda RBX: 00007fac240977a0 RCX: 00007fae16303f3b [63988.145318] RDX: 00007fae163f79e0 RSI: 00000000fbad2404 RDI: 0000000000000038 [63988.145438] RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000020 [63988.145556] R10: 00000000002aa212 R11: 0000000000000202 R12: 00007fae163f85e0 [63988.145673] R13: 00007fac670c7b18 R14: 00007fadee5db458 R15: 0000000000000002 [63988.145792] [63988.145908] Modules linked in: nls_utf8 cifs cifs_arc4 rdma_cm iw_cm ib_cm ib_core cifs_md4 dns_resolver rfkill nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 nf_tables nfnetlink qrtr vfat fat nvidia_uvm(POE) nvidia_drm(POE) nvidia_modeset(POE) nvidia(POE) intel_rapl_msr intel_rapl_common intel_uncore_frequency intel_uncore_frequency_common skx_edac nfit libnvdimm x86_pkg_temp_thermal intel_powerclamp coretemp kvm_intel kvm ipmi_ssif drm_ttm_helper ttm ipmi_si iTCO_wdt iTCO_vendor_support rapl lpc_ich acpi_power_meter intel_cstate video intel_uncore dcdbas i2c_i801 dell_smbios dell_wmi_descriptor mei_me acpi_ipmi mei wmi_bmof ipmi_devintf ipmi_msghandler pcspkr i2c_smbus intel_pch_thermal auth_rpcgss sunrpc xfs libcrc32c sd_mod sg mgag200 drm_client_lib i2c_algo_bit drm_shmem_helper drm_kms_helper ahci libahci crct10dif_pclmul crc32_pclmul libata drm bnxt_en crc32c_intel megaraid_sas tg3 [63988.145950] ghash_clmulni_intel wmi dm_mirror dm_region_hash dm_log dm_mod i2c_dev fuse