Chromium browser triggers PAE kernel bug: "Corrupted page table at address"

Bug #1257256 reported by gcc
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Linux
Fix Released
Unknown
linux (Ubuntu)
Incomplete
Medium
Unassigned
Precise
Won't Fix
Medium
Unassigned

Bug Description

This bug has been reported upstream and addressed in Debian.

I found it while running the upstream kernel 3.6.0-030600rc6-generic, but since it was fixed in 3.9, it almost certainly applies to the stock Precise kernel as well. It's rare and not easy to reproduce, and I can't use my system properly with the stock Precise kernel (USB fails after suspend) so I can't really test that for you.

After running Chromium for some time, it may be killed by the kernel, with the following error in the kernel logs/dmesg:

[656997.934699] chromium-browse: Corrupted page table at address 45c72000
[656997.937966] *pdpt = 0000000000000000 *pde = f0001189f0001189
[656997.939741] Bad pagetable: 000f [#1] SMP
[656997.941504] Modules linked in: ufs qnx4 hfsplus hfs minix ntfs msdos jfs xfs reiserfs ext2 ppp_deflate bsd_comp ppp_async crc_ccitt option uas usb_storage cp210x snd_seq_dummy pci_stub vboxpci(O) vboxnetadp(O) vboxnetflt(O) vboxdrv(O) xfrm_user xfrm4_tunnel tunnel4 ipcomp xfrm_ipcomp esp4 ah4 ip6table_filter ip6_tables ebtable_nat ebtables xt_state ipt_REJECT xt_CHECKSUM iptable_mangle xt_tcpudp iptable_filter ipt_MASQUERADE iptable_nat nf_nat nf_conntrack_ipv4 nf_conntrack nf_defrag_ipv4 ip_tables x_tables bridge stp llc qmi_wwan usbnet cdc_wdm ib_iser rdma_cm ib_cm iw_cm ib_sa ib_mad ib_core ib_addr iscsi_tcp libiscsi_tcp libiscsi scsi_transport_iscsi deflate ctr twofish_generic twofish_i586 twofish_common camellia_generic dm_crypt serpent_sse2_i586 glue_helper lrw serpent_generic xts gf128mul blowfish_generic blowfish_common cast5 des_generic xcbc rmd160 sha512_generic crypto_null af_key xfrm_algo bnep rfcomm parport_pc ppdev lp parport snd_hda_codec_hdmi snd_hda_codec_conexant snd_hda_intel snd_hda_codec arc4 iwldvm snd_hwdep mac80211 snd_pcm thinkpad_acpi snd_seq_midi kvm_intel snd_rawmidi kvm snd_seq_midi_event iwlwifi snd_seq qcserial snd_timer usb_wwan btusb usbserial dm_multipath snd_seq_device snd lpc_ich soundcore scsi_dh microcode snd_page_alloc mei bluetooth mac_hid cfg80211 psmouse serio_raw joydev intel_ips tpm_tis nvram nfsd nfs_acl auth_rpcgss nfs coretemp fscache lockd hdaps(O) thinkpad_ec(O) sunrpc binfmt_misc raid10 raid456 async_raid6_recov async_pq raid6_pq async_xor xor async_memcpy async_tx raid1 raid0 multipath linear dm_mirror dm_region_hash dm_log btrfs zlib_deflate libcrc32c aesni_intel ablk_helper cryptd aes_i586 i915 e1000e drm_kms_helper drm i2c_algo_bit video wmi
[656997.964607] Pid: 7287, comm: chromium-browse Tainted: G W O 3.6.0-030600rc6-generic #201209161835 LENOVO 3323DAG/3323DAG
[656997.964610] EIP: 0073:[<b3602b23>] EFLAGS: 00210283 CPU: 1
[656997.964628] EIP is at 0xb3602b23
[656997.964630] EAX: 45c72000 EBX: b37a8d18 ECX: 00000024 EDX: 45c72fe0
[656997.964631] ESI: bfca81fc EDI: 00000000 EBP: bfca826c ESP: bfca81b0
[656997.964633] DS: 007b ES: 007b FS: 0000 GS: 0033 SS: 007b
[656997.964636] Process chromium-browse (pid: 7287, ti=e1564000 task=e97ff1a0 task.ti=e1564000)
[656997.964637]
[656997.964638] EIP: [<b3602b23>] 0xb3602b23 SS:ESP 007b:bfca81b0
[656997.987472] ---[ end trace 0ab1e74c159721af ]---

Description: Ubuntu 12.04.3 LTS
Release: 12.04

Tags: precise
Changed in linux:
status: Unknown → Confirmed
tags: added: precise
Changed in linux (Ubuntu):
status: New → Confirmed
Changed in linux (Ubuntu Precise):
status: New → Confirmed
Changed in linux (Ubuntu):
importance: Undecided → Medium
Changed in linux (Ubuntu Precise):
importance: Undecided → Medium
Revision history for this message
penalvch (penalvch) wrote :

gcc, could you please confirm this issue exists with the latest development release of Ubuntu? ISO images are available from http://cdimage.ubuntu.com/daily-live/current/ . If the issue remains, could you please run the following command in the development release from a Terminal (Applications->Accessories->Terminal), as it will automatically gather and attach updated debug information to this report:

apport-collect 1257256

Changed in linux (Ubuntu):
status: Confirmed → Incomplete
Changed in linux:
status: Confirmed → Fix Released
Revision history for this message
Steve Langasek (vorlon) wrote :

The Precise Pangolin has reached end of life, so this bug will not be fixed for that release

Changed in linux (Ubuntu Precise):
status: Confirmed → Won't Fix
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.