From: Andrea Righi BUG: at include/linux/slub_def.h:77 kmalloc_index() [] get_slab+0x1d0/0x260 [] __kmalloc+0x16/0x70 [] sysenter_setup+0x6f/0x330 [] mtrr_bp_init+0xcd/0x270 [] unknown_bootoption+0x0/0x250 [] unknown_bootoption+0x0/0x250 [] check_bugs+0x8/0x160 [] proc_sys_init+0xc/0x30 [] start_kernel+0x21f/0x2b0 [] unknown_bootoption+0x0/0x250 ======================= Reproduced running 2.6.22-rc2 (using SLUB) in a virtual machine with qemu 0.9.0 + kqemu 1.3.0pre11. It occurs only using "-kernel-kqemu" option (full virtualization mode). In this case mtrr is supported by the real cpu, but no mtrr range is found, resulting in a kmalloc(0, GFP_KERNEL) in get_mtrr_state() and init_table(). Signed-off-by: Andrea Righi Signed-off-by: Andrew Morton --- arch/i386/kernel/cpu/mtrr/generic.c | 3 +++ arch/i386/kernel/cpu/mtrr/main.c | 5 +++++ 2 files changed, 8 insertions(+) diff -puN arch/i386/kernel/cpu/mtrr/generic.c~bug-in-i386-mtrr-initialization arch/i386/kernel/cpu/mtrr/generic.c --- a/arch/i386/kernel/cpu/mtrr/generic.c~bug-in-i386-mtrr-initialization +++ a/arch/i386/kernel/cpu/mtrr/generic.c @@ -84,6 +84,9 @@ void __init get_mtrr_state(void) struct mtrr_var_range *vrs; unsigned lo, dummy; + if (!num_var_ranges) + return; + if (!mtrr_state.var_ranges) { mtrr_state.var_ranges = kmalloc(num_var_ranges * sizeof (struct mtrr_var_range), GFP_KERNEL); diff -puN arch/i386/kernel/cpu/mtrr/main.c~bug-in-i386-mtrr-initialization arch/i386/kernel/cpu/mtrr/main.c --- a/arch/i386/kernel/cpu/mtrr/main.c~bug-in-i386-mtrr-initialization +++ a/arch/i386/kernel/cpu/mtrr/main.c @@ -120,6 +120,11 @@ static void __init init_table(void) { int i, max; + if (!num_var_ranges) { + printk(KERN_ERR "mtrr: no MTRR range found.\n"); + return; + } + max = num_var_ranges; if ((usage_table = kmalloc(max * sizeof *usage_table, GFP_KERNEL)) == NULL) { _