Bernhard Kaindl noticed a race in the lockless receive path of msgrcv(): If a signal wakes up the thread that sleeps in msgrcv(), then pipelined_send() can access an already invalid structure. This can cause oopses during wake_up_process(). http://marc.theaimsgroup.com/?l=linux-kernel&m=103599896511067&w=2 The simplest solution is to remove the lockless receive, and always acquire the spinlock during receive. Unfortunately this would increase the number of spinlock operations for ipc/msg.c by up to 50%. (from 2 to 3 spinlock calls for msgrcv()+msgsnd()) Any other ideas? Are there workloads that heavily rely on sysv msg? Patch against 2.5.46 is attached. -- Manfred