Hello, syzkaller hit the following crash on 37759fa6d0fa9e4d6036d19ac12f555bfc0aeafd git://git.cmpxchg.org/linux-mmots.git/master compiler: gcc (GCC) 7.1.1 20170620 .config is attached Raw console output is attached. C reproducer is attached syzkaller reproducer is attached. See https://goo.gl/kgGztJ for information about syzkaller reproducers IMPORTANT: if you fix the bug, please add the following tag to the commit: Reported-by: syzbot+1d7d9ce4ce4a23cb7d3b@syzkaller.appspotmail.com It will help syzbot understand when the bug is fixed. See footer for details. If you forward the report, please keep this part and the footer. WARNING: CPU: 0 PID: 3192 at ./arch/x86/include/asm/fpu/internal.h:340 paravirt_write_msr arch/x86/include/asm/paravirt.h:21 [inline] WARNING: CPU: 0 PID: 3192 at ./arch/x86/include/asm/fpu/internal.h:340 wrmsrl arch/x86/include/asm/paravirt.h:149 [inline] WARNING: CPU: 0 PID: 3192 at ./arch/x86/include/asm/fpu/internal.h:340 load_seg_legacy arch/x86/kernel/process_64.c:255 [inline] WARNING: CPU: 0 PID: 3192 at ./arch/x86/include/asm/fpu/internal.h:340 __switch_to+0x10bd/0x13c0 arch/x86/kernel/process_64.c:455 Kernel panic - not syncing: panic_on_warn set ... CPU: 0 PID: 3192 Comm: syzkaller835319 Not tainted 4.15.0-rc4-mm1+ #49 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011 Call Trace: Shutting down cpus with NMI kasan: CONFIG_KASAN_INLINE enabled kasan: GPF could be caused by NULL-ptr deref or user [me m or41y .3ac65ce0s98s ] Rebooting in 86400 seconds.. ---[ end trace 2d2aa5997809e25d ]--- --- This bug is generated by a dumb bot. It may contain errors. See https://goo.gl/tpsmEJ for details. Direct all questions to syzkaller@googlegroups.com. syzbot will keep track of this bug report. If you forgot to add the Reported-by tag, once the fix for this bug is merged into any tree, please reply to this email with: #syz fix: exact-commit-title If you want to test a patch for this bug, please reply with: #syz test: git://repo/address.git branch and provide the patch inline or as an attachment. To mark this as a duplicate of another syzbot report, please reply with: #syz dup: exact-subject-of-another-report If it's a one-off invalid bug report, please reply with: #syz invalid Note: if the crash happens again, it will cause creation of a new bug report. Note: all commands must start from beginning of the line in the email body.