Public bug reported:

Ubuntu 26.04.1 LTS (resolute), linux-image-7.0.0-34-generic 7.0.0-34.34.
/proc/version_signature: Ubuntu 7.0.0-34.34-generic 7.0.14
Hardware: Lenovo ThinkPad W520, machine type 4284AT3; BIOS 8BET66WW (1.46), 
2018-06-14.

On 2026-09-27 the host panicked during recovery from USB/UAS disk I/O
failures. This report concerns the USB/IOMMU panic, not a separate Btrfs
panic on the next boot.

Observed sequence (PDT):
- USB/UAS resets and read/write errors on one external disk were already 
present before a UPS power test (23:21 onward).
- After mains removal at 23:25, a service stopped Samba and called sync. sync 
remained blocked in writeback. Mains was restored by 23:28, before the panic.
- At 23:31, after stopping the shutdown controller, the affected SCSI disk was 
removed through /sys/block/sdb/device/delete to release stalled I/O. The device 
identity was checked first. systemd reported the Btrfs filesystem unmounted at 
23:31:44.
- The external USB hub was physically unplugged and reconnected. The machine 
panicked around 23:32:29. The exact timing of the physical USB action relative 
to individual kernel events is not instrumented.

Expected: failed disk I/O and device removal should return errors without 
crashing the host.
Actual: NULL dereference at 0x1c, followed by 'Kernel panic - not syncing: 
Fatal exception in interrupt'. Manual reboot was required.

Saved pstore trace:
RIP: iommu_dma_unmap_sg+0x7a/0x170
Call Trace (<IRQ>):
 dma_unmap_sg_attrs+0x123/0x1a0
 usb_hcd_unmap_urb_for_dma+0xc1/0x110
 xhci_unmap_urb_for_dma+0x50/0x170
 __usb_hcd_giveback_urb+0x58/0x130
 usb_giveback_urb_bh+0xba/0x160
 process_one_work+0x1ac/0x3d0
 bh_worker+0x1d4/0x1f0
 workqueue_softirq_action+0x78/0xe0
Taint at first oops: G          I (FIRMWARE_WORKAROUND); no 
proprietary/out-of-tree taint shown.

Storage: two Seagate Expansion Desk USB disks (USB ID 0bc2:331a), using
uas, behind a Genesys Logic USB3 hub (05e3:0626). They are members of a
Btrfs RAID1 filesystem. The affected disk was /dev/sdb on the panic
boot; device names change across boots.

Related but NOT confirmed duplicate: CVE-2025-68331 ('usb: uas: fix urb 
unmapping issue when the uas device is remove during ongoing data transfer'). 
Ubuntu lists resolute/linux as Not affected, and this trace uses 
iommu_dma_unmap_sg rather than dma_direct_unmap_sg. Please investigate whether 
this is a different lifetime/error-recovery bug or regression; we are not 
asserting the CVE applies.
https://ubuntu.com/security/CVE-2025-68331

This signature was observed once during this incident. After subsequent
reboot and cable reseating, each disk completed a 16 GiB buffered
sequential read while unmounted, without new USB errors during those
reads. This does not establish filesystem integrity or resolve the
panic. No mainline-kernel reproduction or bisection has been performed.

Attachments include the saved first-panic pstore output, kernel version, PCI 
details, and current post-reboot USB topology. Pstore output contains 
overlapping Oops/Panic records and part markers as preserved by systemd. A 
separate next-boot Btrfs panic resembles upstream bug 221270 and will be 
reported there separately.
https://bugzilla.kernel.org/show_bug.cgi?id=221270

** Affects: linux (Ubuntu)
     Importance: Undecided
         Status: New


** Tags: iommu kernel-panic resolute uas usb

** Attachment added: "Saved pstore records: USB/IOMMU panic and preceding I/O 
failures"
   
https://bugs.launchpad.net/bugs/2168717/+attachment/6003313/+files/panic1-usb-iommu.log

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2168717

Title:
  [7.0.0-34-generic] ThinkPad W520 panics in iommu_dma_unmap_sg during
  USB/UAS recovery

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2168717/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to