Crash with kernel 7.0.14-20-pve and passed through em28xx tuner on VM start

Starfire

New Member
Oct 1, 2026
2
0
1
Proxmox VE 9.2.21

After upgrading to kernel 7.0.14-20-pve I get a reproducible crash when starting a VM. This seems to be caused by a passed through em28xx-usb-tuner.
The VM will fail to start and the host is also not fine after that, e.g. it will hang on the 'rebooting now' and needs to be power cycled.

The crash only appeared with 7.0.14-20-pve, with 7.0.14-19-pve everything is good.

Code:
Oct 01 22:01:20 starpve1 kernel: BUG: kernel NULL pointer dereference, address: 0000000000000000
Oct 01 22:01:20 starpve1 kernel: #PF: supervisor read access in kernel mode
Oct 01 22:01:20 starpve1 kernel: #PF: error_code(0x0000) - not-present page
Oct 01 22:01:20 starpve1 kernel: PGD 0 P4D 0
Oct 01 22:01:20 starpve1 kernel: Oops: Oops: 0000 [#1] SMP PTI
Oct 01 22:01:20 starpve1 kernel: CPU: 0 UID: 0 PID: 1199 Comm: kvm Tainted: P           O        7.0.14-20-pve #1 PREEMPT(lazy)
Oct 01 22:01:20 starpve1 kernel: Tainted: [P]=PROPRIETARY_MODULE, [O]=OOT_MODULE
Oct 01 22:01:20 starpve1 kernel: Hardware name: Dell Inc. OptiPlex 3050/0JP3NX, BIOS 1.32.0 09/06/2024
Oct 01 22:01:20 starpve1 kernel: RIP: 0010:em28xx_close_extension+0x80/0x140 [em28xx]
Oct 01 22:01:20 starpve1 kernel: Code: 81 fb 50 82 bf c0 75 cd 49 8b 9c 24 a0 17 00 00 48 85 db 74 4b 48 8b 83 f0 01 00 00 48 8b 93 e8 01 00 00 48 8d bb e8 01 00 00 <48> 3b >
Oct 01 22:01:20 starpve1 kernel: RSP: 0018:ffffce06419d7c80 EFLAGS: 00010286
Oct 01 22:01:20 starpve1 kernel: RAX: 0000000000000000 RBX: ffff8d9614d04000 RCX: 0000000000000000
Oct 01 22:01:20 starpve1 kernel: RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff8d9614d041e8
Oct 01 22:01:20 starpve1 kernel: RBP: ffffce06419d7c90 R08: 0000000000000000 R09: 0000000000000000
Oct 01 22:01:20 starpve1 kernel: R10: 0000000000000000 R11: 0000000000000000 R12: ffff8d960af88000
Oct 01 22:01:20 starpve1 kernel: R13: ffff8d96032f80e0 R14: ffffffffc0bf8590 R15: ffff8d96032f8050
Oct 01 22:01:20 starpve1 kernel: FS:  000072a8916d6880(0000) GS:ffff8d977670a000(0000) knlGS:0000000000000000
Oct 01 22:01:20 starpve1 kernel: CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
Oct 01 22:01:20 starpve1 kernel: CR2: 0000000000000000 CR3: 0000000120382002 CR4: 00000000003726f0
Oct 01 22:01:20 starpve1 kernel: Call Trace:
Oct 01 22:01:20 starpve1 kernel:  <TASK>
Oct 01 22:01:20 starpve1 kernel:  em28xx_usb_disconnect.cold+0x71/0xbf [em28xx]
Oct 01 22:01:20 starpve1 kernel:  usb_unbind_interface+0x9b/0x2e0
Oct 01 22:01:20 starpve1 kernel:  device_remove+0x68/0x80
Oct 01 22:01:20 starpve1 kernel:  device_release_driver_internal+0x206/0x270
Oct 01 22:01:20 starpve1 kernel:  device_release_driver+0x12/0x20
Oct 01 22:01:20 starpve1 kernel:  usb_driver_release_interface+0x53/0xa0
Oct 01 22:01:20 starpve1 kernel:  proc_ioctl+0x20f/0x270
Oct 01 22:01:20 starpve1 kernel:  ? __x64_sys_close+0x3e/0x90
Oct 01 22:01:20 starpve1 kernel:  usbdev_ioctl+0x776/0x15b0
Oct 01 22:01:20 starpve1 kernel:  ? __x64_sys_read+0x19/0x30
Oct 01 22:01:20 starpve1 kernel:  ? x64_sys_call+0x1ff1/0x2390
Oct 01 22:01:20 starpve1 kernel:  ? do_syscall_64+0x148/0x14e0
Oct 01 22:01:20 starpve1 kernel:  ? kmem_cache_free+0x251/0x390
Oct 01 22:01:20 starpve1 kernel:  __x64_sys_ioctl+0xa5/0x100
Oct 01 22:01:20 starpve1 kernel:  ? fput_close_sync+0x3d/0xa0
Oct 01 22:01:20 starpve1 kernel:  x64_sys_call+0x103b/0x2390
Oct 01 22:01:20 starpve1 kernel:  do_syscall_64+0x10b/0x14e0
Oct 01 22:01:20 starpve1 kernel:  ? exc_page_fault+0x92/0x1c0
Oct 01 22:01:20 starpve1 kernel:  entry_SYSCALL_64_after_hwframe+0x76/0x7e
Oct 01 22:01:20 starpve1 kernel: RIP: 0033:0x72a89490f65b
Oct 01 22:01:20 starpve1 kernel: Code: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c2 >
Oct 01 22:01:20 starpve1 kernel: RSP: 002b:00007ffcd5318070 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
Oct 01 22:01:20 starpve1 kernel: RAX: ffffffffffffffda RBX: 000056facec1dac0 RCX: 000072a89490f65b
Oct 01 22:01:20 starpve1 kernel: RDX: 00007ffcd53180d0 RSI: 00000000c0105512 RDI: 0000000000000028
Oct 01 22:01:20 starpve1 kernel: RBP: 0000000000000028 R08: 00007ffcd5318110 R09: 0000000000000007
Oct 01 22:01:20 starpve1 kernel: R10: 000056facec1dc38 R11: 0000000000000246 R12: 0000000000000000
Oct 01 22:01:20 starpve1 kernel: R13: 000056fa8eaaa237 R14: 000056fa8ea85d7a R15: 000056fa8fb7b7e0
Oct 01 22:01:20 starpve1 kernel:  </TASK>
Oct 01 22:01:20 starpve1 kernel: Modules linked in: ebtable_filter ebtables ip_set ip6table_raw iptable_raw ip6table_filter ip6_tables iptable_filter scsi_transport_iscsi nf>
Oct 01 22:01:20 starpve1 kernel:  r8169 i2c_i801 realtek xhci_pci i2c_mux ahci phylink xhci_hcd video i2c_smbus libahci wmi
Oct 01 22:01:20 starpve1 kernel: CR2: 0000000000000000
Oct 01 22:01:20 starpve1 kernel: ---[ end trace 0000000000000000 ]---
Oct 01 22:01:20 starpve1 kernel: RIP: 0010:em28xx_close_extension+0x80/0x140 [em28xx]
Oct 01 22:01:20 starpve1 kernel: Code: 81 fb 50 82 bf c0 75 cd 49 8b 9c 24 a0 17 00 00 48 85 db 74 4b 48 8b 83 f0 01 00 00 48 8b 93 e8 01 00 00 48 8d bb e8 01 00 00 <48> 3b >
Oct 01 22:01:20 starpve1 kernel: RSP: 0018:ffffce06419d7c80 EFLAGS: 00010286
Oct 01 22:01:20 starpve1 kernel: RAX: 0000000000000000 RBX: ffff8d9614d04000 RCX: 0000000000000000
Oct 01 22:01:20 starpve1 kernel: RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff8d9614d041e8
Oct 01 22:01:20 starpve1 kernel: RBP: ffffce06419d7c90 R08: 0000000000000000 R09: 0000000000000000
Oct 01 22:01:20 starpve1 kernel: R10: 0000000000000000 R11: 0000000000000000 R12: ffff8d960af88000
Oct 01 22:01:20 starpve1 kernel: R13: ffff8d96032f80e0 R14: ffffffffc0bf8590 R15: ffff8d96032f8050
Oct 01 22:01:20 starpve1 kernel: FS:  000072a8916d6880(0000) GS:ffff8d977670a000(0000) knlGS:0000000000000000
Oct 01 22:01:20 starpve1 kernel: CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
Oct 01 22:01:20 starpve1 kernel: CR2: 0000000000000000 CR3: 0000000120382002 CR4: 00000000003726f0
Oct 01 22:01:20 starpve1 kernel: note: kvm[1199] exited with irqs disabled

I guess the error would also happen if I just unplug the USB-device, but I haven't tested that.
 
Last edited:
Just a note: If you don't need the em28xx-tuner on the Proxmox-host because it is only passed through to a VM (like in my case) you can get around the crash by blacklisting em28xx on the Proxmox-host.