I have verified this on various kernels (4.4 / 4.15 / 5.4 / 5.8 / 5.10 OEM). It looks like this is only affecting 5.6 OEM. Traces can be found in dmesg: [ 1377.246198] LTP: starting io_uring02 [ 1377.248923] usercopy: Kernel memory overwrite attempt detected to null address (offset 0, size 110)! [ 1377.254584] ------------[ cut here ]------------ [ 1377.254587] kernel BUG at mm/usercopy.c:99! [ 1377.257041] invalid opcode: 0000 [#1] SMP PTI [ 1377.259183] CPU: 0 PID: 49675 Comm: io_uring02 Not tainted 5.6.0-1056-oem #60-Ubuntu [ 1377.261706] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.10.2-1ubuntu1 04/01/2014 [ 1377.264350] RIP: 0010:usercopy_abort+0x7b/0x7d [ 1377.265631] Code: 4c 0f 45 de 51 4c 89 d1 48 c7 c2 75 93 7b 8f 57 48 c7 c6 d0 4d 7a 8f 48 c7 c7 40 94 7b 8f 48 0f 45 f2 4c 89 da e8 58 28 e3 ff <0f> 0b 4c 89 e1 49 89 d8 44 89 ea 31 f6 48 29 c1 48 c7 c7 b7 93 7b [ 1377.271104] RSP: 0018:ffffafdcc09f3bd8 EFLAGS: 00010246 [ 1377.272730] RAX: 0000000000000058 RBX: 000000000000006e RCX: 0000000000000000 [ 1377.274943] RDX: 0000000000000000 RSI: ffff8caa3dc19808 RDI: ffff8caa3dc19808 [ 1377.277057] RBP: ffffafdcc09f3bf0 R08: 0000000000000264 R09: ffffafdcc0318810 [ 1377.279161] R10: ffff8caa3b977bc0 R11: 0000000000000002 R12: 0000000000000000 [ 1377.281454] R13: 0000000000000000 R14: 000000000000006e R15: 000000000000006e [ 1377.283694] FS: 00007f6355cd6600(0000) GS:ffff8caa3dc00000(0000) knlGS:0000000000000000 [ 1377.286251] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 1377.288060] CR2: 00007f6355d0c000 CR3: 0000000032062000 CR4: 00000000000006f0 [ 1377.290336] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 1377.292685] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 1377.294826] Call Trace: [ 1377.295535] __check_object_size.cold+0x5d/0x83 [ 1377.296995] move_addr_to_kernel.part.0+0x27/0x80 [ 1377.298499] copy_msghdr_from_user+0x112/0x150 [ 1377.299953] sendmsg_copy_msghdr+0x17/0x40 [ 1377.301281] io_sendmsg_prep+0x75/0x90 [ 1377.302514] io_req_defer_prep+0x315/0x5b0 [ 1377.303877] io_queue_sqe+0x3e2/0x9e0 [ 1377.305084] ? vma_wants_writenotify+0x55/0xd0 [ 1377.306613] ? vma_set_page_prot+0x2f/0x60 [ 1377.307954] ? _cond_resched+0x19/0x30 [ 1377.309162] ? kmem_cache_alloc+0x16d/0x230 [ 1377.310517] io_submit_sqes+0x852/0xb00 [ 1377.311787] ? vm_mmap_pgoff+0x108/0x120 [ 1377.313057] __x64_sys_io_uring_enter+0x229/0x320 [ 1377.314650] do_syscall_64+0x57/0x1b0 [ 1377.315847] entry_SYSCALL_64_after_hwframe+0x44/0xa9 [ 1377.317451] RIP: 0033:0x7f6355bfe89d [ 1377.318606] Code: 00 c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d c3 f5 0c 00 f7 d8 64 89 01 48 [ 1377.324843] RSP: 002b:00007ffd525d4b28 EFLAGS: 00000246 ORIG_RAX: 00000000000001aa [ 1377.327322] RAX: ffffffffffffffda RBX: 0000000000000005 RCX: 00007f6355bfe89d [ 1377.329610] RDX: 0000000000000001 RSI: 0000000000000001 RDI: 0000000000000005 [ 1377.331964] RBP: 0000000000000001 R08: 0000000000000000 R09: 0000000000000008 [ 1377.334330] R10: 0000000000000001 R11: 0000000000000246 R12: 000055eda2074004 [ 1377.336715] R13: 00000000000000e3 R14: 0000000000000001 R15: 00007f6355cd6580 [ 1377.340504] Modules linked in: sctp nfsd auth_rpcgss nfsv4 nfs_acl nfs lockd grace sunrpc fscache dm_multipath scsi_dh_rdac scsi_dh_emc scsi_dh_alua kvm_intel kvm joydev input_leds mac_hid serio_raw qemu_fw_cfg sch_fq_codel ip_tables x_tables autofs4 btrfs blake2b_generic zstd_compress raid10 raid456 async_raid6_recov async_memcpy async_pq async_xor async_tx xor raid6_pq libcrc32c raid1 raid0 multipath linear cirrus drm_kms_helper syscopyarea sysfillrect sysimgblt fb_sys_fops cec rc_core psmouse virtio_blk virtio_net drm net_failover failover i2c_piix4 pata_acpi floppy [ 1377.366586] ---[ end trace 459a94f96a25efad ]--- [ 1377.369722] RIP: 0010:usercopy_abort+0x7b/0x7d [ 1377.372805] Code: 4c 0f 45 de 51 4c 89 d1 48 c7 c2 75 93 7b 8f 57 48 c7 c6 d0 4d 7a 8f 48 c7 c7 40 94 7b 8f 48 0f 45 f2 4c 89 da e8 58 28 e3 ff <0f> 0b 4c 89 e1 49 89 d8 44 89 ea 31 f6 48 29 c1 48 c7 c7 b7 93 7b [ 1377.383651] RSP: 0018:ffffafdcc09f3bd8 EFLAGS: 00010246 [ 1377.387123] RAX: 0000000000000058 RBX: 000000000000006e RCX: 0000000000000000 [ 1377.391619] RDX: 0000000000000000 RSI: ffff8caa3dc19808 RDI: ffff8caa3dc19808 [ 1377.396061] RBP: ffffafdcc09f3bf0 R08: 0000000000000264 R09: ffffafdcc0318810 [ 1377.400474] R10: ffff8caa3b977bc0 R11: 0000000000000002 R12: 0000000000000000 [ 1377.404912] R13: 0000000000000000 R14: 000000000000006e R15: 000000000000006e [ 1377.409348] FS: 00007f6355cd6600(0000) GS:ffff8caa3dc00000(0000) knlGS:0000000000000000 [ 1377.414247] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 1377.417957] CR2: 00007f6355d0c000 CR3: 0000000032062000 CR4: 00000000000006f0 [ 1377.422406] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 1377.426843] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400