Nick: Hellsenberg E-mail: th3fanbus@gmail.com Board: Acer E5-573-5947 (dmesg after running intelmetool) Contents: [183376.700691] mei_me 0000:00:16.0: less data available than length=00000001. [183376.723912] mei_me 0000:00:16.0: less data available than length=00000002. [183401.272254] mei_me 0000:00:16.0: less data available than length=00000004. [183401.272367] mei_me 0000:00:16.0: less data available than length=00000004. [183405.853890] mei_me 0000:00:16.0: less data available than length=00000007. [183405.876814] mei_me 0000:00:16.0: less data available than length=00000004. [183405.876861] mei_me 0000:00:16.0: less data available than length=00000001. [183407.073129] mei_me 0000:00:16.0: no destination client found 0x001E0430 [183407.073136] mei_me 0000:00:16.0: mei_irq_read_handler ret = -74. [183407.073165] mei_me 0000:00:16.0: unexpected reset: dev_state = ENABLED fw status = 1E000245 6000A306 00000200 00004400 00000000 40000010 [183410.612728] mei_me 0000:00:16.0: no destination client found 0x000082FF [183410.612740] mei_me 0000:00:16.0: mei_irq_read_handler ret = -74. [183410.612788] mei_me 0000:00:16.0: unexpected reset: dev_state = ENABLED fw status = 1E000245 6000A306 00000200 00004400 00000000 40000010 [183410.636866] mei_me 0000:00:16.0: no destination client found 0x00008203 [183410.636874] mei_me 0000:00:16.0: mei_irq_read_handler ret = -74. [183410.636903] mei_me 0000:00:16.0: unexpected reset: dev_state = ENABLED fw status = 1E000245 6000A306 00000200 00004400 00000000 40000010 [183412.765966] mei_me 0000:00:16.0: no destination client found 0x000082FF [183412.765974] mei_me 0000:00:16.0: mei_irq_read_handler ret = -74. [183412.766001] mei_me 0000:00:16.0: unexpected reset: dev_state = ENABLED fw status = 1E000245 6000A306 00000200 00004400 00000000 40000010 [183412.790453] mei_me 0000:00:16.0: corrupted message header 0x00000000 [183412.790460] mei_me 0000:00:16.0: mei_irq_read_handler ret = -74. [183412.790487] mei_me 0000:00:16.0: unexpected reset: dev_state = ENABLED fw status = 1E000245 6000A306 00000200 00004400 00000000 40000010 [183414.118664] mei_me 0000:00:16.0: resetting due to slots overflow. [183414.118678] mei_me 0000:00:16.0: mei_irq_read_handler ret = -34. [183414.118716] mei_me 0000:00:16.0: unexpected reset: dev_state = ENABLED fw status = 1E000245 6000A306 00000200 00004400 00000000 40000010 [183420.122769] mei_me 0000:00:16.0: no destination client found 0x000082FF [183420.122780] mei_me 0000:00:16.0: mei_irq_read_handler ret = -74. [183420.122811] mei_me 0000:00:16.0: unexpected reset: dev_state = ENABLED fw status = 1E000245 6000A306 00000200 00004400 00000000 40000010 [183424.543632] mei_me 0000:00:16.0: no destination client found 0x000082FF [183424.543645] mei_me 0000:00:16.0: mei_irq_read_handler ret = -74. [183424.543684] mei_me 0000:00:16.0: unexpected reset: dev_state = ENABLED fw status = 1E000245 6000A306 00000200 00004400 00000000 40000010 [183429.602773] ------------[ cut here ]------------ [183429.602780] kernel BUG at drivers/misc/mei/hbm.c:1253! [183429.602800] invalid opcode: 0000 [#1] PREEMPT SMP PTI [183429.602810] CPU: 2 PID: 31802 Comm: irq/51-mei_me Not tainted 4.18.14-arch1-1-ARCH #1 [183429.602816] Hardware name: Acer NC-E5-573-5947/ZORO_BH, BIOS V1.37 02/16/2016 [183429.602837] RIP: 0010:mei_hbm_dispatch+0xac/0xc10 [mei] [183429.602841] Code: 54 02 00 00 3c 82 75 22 0f 1f 44 00 00 e9 67 04 00 00 3c 8a 0f 84 c4 02 00 00 3c 90 0f 84 74 01 00 00 3c 87 0f 84 98 02 00 00 <0f> 0b 3c 08 0f 84 9c 04 00 00 76 68 3c 0f 0f 84 78 03 00 00 3c 11 [183429.602962] RSP: 0018:ffffa74d8275bdc0 EFLAGS: 00010212 [183429.602971] RAX: 0000000000000030 RBX: ffff89319337b018 RCX: 0000000000000004 [183429.602978] RDX: ffffa74d810c1004 RSI: ffffa74d810c1004 RDI: 000000008002020c [183429.602985] RBP: ffff89319337b2a8 R08: ffffffffabe05040 R09: 0000a6d405776d28 [183429.602992] R10: 000000000032dcd5 R11: ffff89319ed20aa8 R12: ffffa74d8275be4c [183429.602999] R13: ffff89319337b4a8 R14: ffffa74d8275be50 R15: ffffffffaace49e0 [183429.603008] FS: 0000000000000000(0000) GS:ffff89319ed00000(0000) knlGS:0000000000000000 [183429.603015] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [183429.603023] CR2: 00007f4b76c7e660 CR3: 000000004540a005 CR4: 00000000003606e0 [183429.603029] Call Trace: [183429.603046] ? __switch_to_asm+0x34/0x70 [183429.603065] mei_irq_read_handler+0x2a6/0x5e0 [mei] [183429.603076] ? _raw_spin_unlock_irq+0x1d/0x30 [183429.603087] ? finish_task_switch+0x83/0x2c0 [183429.603099] ? irq_thread_dtor+0x80/0x80 [183429.603112] mei_me_irq_thread_handler+0x140/0x6d0 [mei_me] [183429.603125] ? irq_forced_thread_fn+0x70/0x70 [183429.603133] ? irq_thread_dtor+0x80/0x80 [183429.603142] irq_thread_fn+0x1f/0x50 [183429.603152] ? irq_forced_thread_fn+0x70/0x70 [183429.603160] irq_thread+0x142/0x1a0 [183429.603171] ? wake_threads_waitq+0x30/0x30 [183429.603183] kthread+0x112/0x130 [183429.603204] ? kthread_flush_work_fn+0x10/0x10 [183429.603214] ret_from_fork+0x35/0x40 [183429.603225] Modules linked in: msr ccm arc4 fuse snd_hda_codec_hdmi ath10k_pci ath10k_core ath mac80211 intel_rapl x86_pkg_temp_thermal intel_powerclamp kvm_intel ofpart kvm cmdlinepart joydev intel_spi_platform mousedev intel_spi i915 coretemp spi_nor cfg80211 mtd irqbypass iTCO_wdt crct10dif_pclmul iTCO_vendor_support crc32_pclmul hid_multitouch nls_iso8859_1 ghash_clmulni_intel nls_cp437 wmi_bmof vfat pcbc fat acer_wmi sparse_keymap uvcvideo videobuf2_vmalloc videobuf2_memops btusb videobuf2_v4l2 btrtl videobuf2_common btbcm snd_hda_intel aesni_intel btintel videodev bluetooth snd_hda_codec aes_x86_64 crypto_simd cryptd glue_helper i2c_algo_bit intel_cstate rtsx_usb_ms mei_me drm_kms_helper memstick intel_uncore media intel_rapl_perf input_leds pcspkr snd_hda_core r8169 ecdh_generic mei drm rfkill [183429.603366] mii i2c_i801 lpc_ich snd_hwdep snd_pcm battery intel_gtt snd_timer agpgart snd syscopyarea sysfillrect soundcore sysimgblt wmi fb_sys_fops i2c_hid gpio_lynxpoint 8250_dw spi_pxa2xx_platform evdev pcc_cpufreq ac mac_hid ip_tables x_tables ext4 crc32c_generic crc16 mbcache jbd2 fscrypto rtsx_usb_sdmmc led_class mmc_core rtsx_usb sd_mod ahci serio_raw libahci atkbd libps2 libata scsi_mod crc32c_intel i8042 serio [183429.603508] ---[ end trace 743e3ef27221ab71 ]--- [183429.603527] RIP: 0010:mei_hbm_dispatch+0xac/0xc10 [mei] [183429.603531] Code: 54 02 00 00 3c 82 75 22 0f 1f 44 00 00 e9 67 04 00 00 3c 8a 0f 84 c4 02 00 00 3c 90 0f 84 74 01 00 00 3c 87 0f 84 98 02 00 00 <0f> 0b 3c 08 0f 84 9c 04 00 00 76 68 3c 0f 0f 84 78 03 00 00 3c 11 [183429.603656] RSP: 0018:ffffa74d8275bdc0 EFLAGS: 00010212 [183429.603663] RAX: 0000000000000030 RBX: ffff89319337b018 RCX: 0000000000000004 [183429.603669] RDX: ffffa74d810c1004 RSI: ffffa74d810c1004 RDI: 000000008002020c [183429.603675] RBP: ffff89319337b2a8 R08: ffffffffabe05040 R09: 0000a6d405776d28 [183429.603681] R10: 000000000032dcd5 R11: ffff89319ed20aa8 R12: ffffa74d8275be4c [183429.603687] R13: ffff89319337b4a8 R14: ffffa74d8275be50 R15: ffffffffaace49e0 [183429.603695] FS: 0000000000000000(0000) GS:ffff89319ed00000(0000) knlGS:0000000000000000 [183429.603701] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [183429.603708] CR2: 00007f4b76c7e660 CR3: 000000004540a005 CR4: 00000000003606e0 [183429.603731] kernel tried to execute NX-protected page - exploit attempt? (uid: 0) [183429.603738] BUG: unable to handle kernel paging request at ffffa74d8275bd18 [183429.603744] PGD 256127067 P4D 256127067 PUD 256128067 PMD 245aa7067 PTE 8000000222d6f063 [183429.603760] Oops: 0011 [#2] PREEMPT SMP PTI [183429.603773] CPU: 2 PID: 31802 Comm: irq/51-mei_me Tainted: G D 4.18.14-arch1-1-ARCH #1 [183429.603778] Hardware name: Acer NC-E5-573-5947/ZORO_BH, BIOS V1.37 02/16/2016 [183429.603787] RIP: 0010:0xffffa74d8275bd18 [183429.603791] Code: ff ff 11 00 00 00 00 00 00 00 1a 88 c6 aa ff ff ff ff 46 00 00 00 00 00 00 00 d8 7a aa 85 31 89 ff ff a4 0b 60 ab 01 00 00 00 <00> 5a 85 c7 3e ab d9 73 11 00 00 00 00 00 00 00 18 bd 75 82 4d a7 [183429.603917] RSP: 0018:ffffa74d8275bea0 EFLAGS: 00010282 [183429.603925] RAX: ffffa74d8275bd18 RBX: ffff89319230c3f8 RCX: 0000000000000001 [183429.603931] RDX: 0000000080000001 RSI: 0000000000000000 RDI: ffffa74d8275bed0 [183429.603936] RBP: 0000000000000001 R08: 0000000000000000 R09: 0000000000000000 [183429.603941] R10: 000000000000000f R11: ffffffffac46af2e R12: ffff89319230bc80 [183429.603947] R13: ffffffffac463e50 R14: 0000000000000000 R15: ffffa74d8275bed0 [183429.603954] FS: 0000000000000000(0000) GS:ffff89319ed00000(0000) knlGS:0000000000000000 [183429.603961] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [183429.603968] CR2: ffffa74d8275bd18 CR3: 000000004540a005 CR4: 00000000003606e0 [183429.603974] Call Trace: [183429.603994] ? task_work_run+0x90/0xb0 [183429.604006] ? do_exit+0x3a4/0xab0 [183429.604016] ? kthread+0x112/0x130 [183429.604027] ? rewind_stack_do_exit+0x17/0x20 [183429.604035] Modules linked in: msr ccm arc4 fuse snd_hda_codec_hdmi ath10k_pci ath10k_core ath mac80211 intel_rapl x86_pkg_temp_thermal intel_powerclamp kvm_intel ofpart kvm cmdlinepart joydev intel_spi_platform mousedev intel_spi i915 coretemp spi_nor cfg80211 mtd irqbypass iTCO_wdt crct10dif_pclmul iTCO_vendor_support crc32_pclmul hid_multitouch nls_iso8859_1 ghash_clmulni_intel nls_cp437 wmi_bmof vfat pcbc fat acer_wmi sparse_keymap uvcvideo videobuf2_vmalloc videobuf2_memops btusb videobuf2_v4l2 btrtl videobuf2_common btbcm snd_hda_intel aesni_intel btintel videodev bluetooth snd_hda_codec aes_x86_64 crypto_simd cryptd glue_helper i2c_algo_bit intel_cstate rtsx_usb_ms mei_me drm_kms_helper memstick intel_uncore media intel_rapl_perf input_leds pcspkr snd_hda_core r8169 ecdh_generic mei drm rfkill [183429.604175] mii i2c_i801 lpc_ich snd_hwdep snd_pcm battery intel_gtt snd_timer agpgart snd syscopyarea sysfillrect soundcore sysimgblt wmi fb_sys_fops i2c_hid gpio_lynxpoint 8250_dw spi_pxa2xx_platform evdev pcc_cpufreq ac mac_hid ip_tables x_tables ext4 crc32c_generic crc16 mbcache jbd2 fscrypto rtsx_usb_sdmmc led_class mmc_core rtsx_usb sd_mod ahci serio_raw libahci atkbd libps2 libata scsi_mod crc32c_intel i8042 serio [183429.604251] CR2: ffffa74d8275bd18 [183429.604257] ---[ end trace 743e3ef27221ab72 ]--- [183429.604269] RIP: 0010:mei_hbm_dispatch+0xac/0xc10 [mei] [183429.604272] Code: 54 02 00 00 3c 82 75 22 0f 1f 44 00 00 e9 67 04 00 00 3c 8a 0f 84 c4 02 00 00 3c 90 0f 84 74 01 00 00 3c 87 0f 84 98 02 00 00 <0f> 0b 3c 08 0f 84 9c 04 00 00 76 68 3c 0f 0f 84 78 03 00 00 3c 11 [183429.604356] RSP: 0018:ffffa74d8275bdc0 EFLAGS: 00010212 [183429.604362] RAX: 0000000000000030 RBX: ffff89319337b018 RCX: 0000000000000004 [183429.604366] RDX: ffffa74d810c1004 RSI: ffffa74d810c1004 RDI: 000000008002020c [183429.604370] RBP: ffff89319337b2a8 R08: ffffffffabe05040 R09: 0000a6d405776d28 [183429.604374] R10: 000000000032dcd5 R11: ffff89319ed20aa8 R12: ffffa74d8275be4c [183429.604378] R13: ffff89319337b4a8 R14: ffffa74d8275be50 R15: ffffffffaace49e0 [183429.604383] FS: 0000000000000000(0000) GS:ffff89319ed00000(0000) knlGS:0000000000000000 [183429.604388] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [183429.604392] CR2: ffffa74d8275bd18 CR3: 000000004540a005 CR4: 00000000003606e0 [183429.604396] Fixing recursive fault but reboot is needed!