Bug 1393102

Summary: [abrt] systemd: prioq_new(): systemd-hostnamed killed by SIGSEGV
Product: [Fedora] Fedora Reporter: Lluis <luic78>
Component: systemdAssignee: systemd-maint
Status: CLOSED EOL QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 24CC: johannbg, lnykryn, msekleta, muadda, ssahani, s, systemd-maint, zbyszek
Target Milestone: ---   
Target Release: ---   
Hardware: x86_64   
OS: Unspecified   
URL: https://retrace.fedoraproject.org/faf/reports/bthash/35d122191755f4a6b52cf58bcb22c286f17cca5f
Whiteboard: abrt_hash:5424e1640d82c75287a2948c25caf7eb080adc2b;
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-08-08 19:11:00 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Attachments:
Description Flags
File: backtrace
none
File: cgroup
none
File: core_backtrace
none
File: dso_list
none
File: environ
none
File: exploitable
none
File: limits
none
File: maps
none
File: mountinfo
none
File: namespaces
none
File: open_fds
none
File: proc_pid_status
none
File: var_log_messages none

Description Lluis 2016-11-08 21:03:47 UTC
Version-Release number of selected component:
systemd-229-16.fc24

Additional info:
reporter:       libreport-2.7.2
backtrace_rating: 4
cmdline:        /usr/lib/systemd/systemd-hostnamed
crash_function: prioq_new
executable:     /usr/lib/systemd/systemd-hostnamed
global_pid:     916
kernel:         4.7.6-200.fc24.x86_64
pkg_fingerprint: 73BD E983 81B4 6521
pkg_vendor:     Fedora Project
runlevel:       unknown
type:           CCpp
uid:            0

Truncated backtrace:
[New LWP 916]
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib64/libthread_db.so.1".
Core was generated by `/usr/lib/systemd/systemd-hostnamed'.
Program terminated with signal SIGSEGV, Segmentation fault.
#0  0x00007f33f66bff3c in ?? () at ../sysdeps/x86_64/multiarch/memset.S:40 from /lib64/libc.so.6
40	2:	ret

Thread 1 (Thread 0x7f33f7459880 (LWP 916)):
#0  0x00007f33f66bff3c in ?? () at ../sysdeps/x86_64/multiarch/memset.S:40 from /lib64/libc.so.6
No locals.
#1  0x00007f33f66b5d1a in __libc_calloc (n=<optimized out>, elem_size=<optimized out>) at malloc.c:3295
        av = <optimized out>
        oldtop = <optimized out>
        p = 0x56086939c270
        bytes = 24
        sz = 24
        csz = 34359738400
        oldtopsize = <optimized out>
        mem = 0x56086939c280
        clearsize = 34359738392
        nclears = 94594125120128
        d = 0x56086939c280
        hook = <optimized out>
#2  0x0000560867b6c2f2 in prioq_new () at src/basic/prioq.c:52
No locals.
#3  prioq_ensure_allocated (q=<optimized out>, compare_func=<optimized out>, compare_func=<optimized out>, q=<optimized out>) at src/basic/prioq.c:76
        compare_func = 0x560867b6d2c0 <pending_prioq_compare.lto_priv.177>
        q = 0x56086939c3c0
        __PRETTY_FUNCTION__ = "prioq_ensure_allocated"
#4  0x0000560867b660bf in sd_event_new (ret=<synthetic pointer>) at src/libsystemd/sd-event/sd-event.c:443
        e = 0x56086939c3b0
        r = <optimized out>
#5  sd_event_default (ret=0x7ffe60ed70c8) at src/libsystemd/sd-event/sd-event.c:2809
        default_event = 0x0
        e = 0x0
#6  0x0000560867b4e9fc in main (argc=<optimized out>, argv=<optimized out>) at src/hostname/hostnamed.c:717
        context = {data = {0x0 <repeats 12 times>}, polkit_registry = 0x0}
        event = 0x0
        bus = 0x0
        r = <optimized out>
        __func__ = "main"
From                To                  Syms Read   Shared Object Library
                                        No          linux-vdso.so.1
0x00007f33f70373d0  0x00007f33f704d47f  Yes         /lib64/libselinux.so.1
0x00007f33f6e2b0b0  0x00007f33f6e2e09f  Yes         /lib64/librt.so.1
0x00007f33f6c14ab0  0x00007f33f6c24905  Yes         /lib64/libgcc_s.so.1
0x00007f33f69fb9e0  0x00007f33f6a082f1  Yes         /lib64/libpthread.so.0
0x00007f33f6653920  0x00007f33f67a30d4  Yes         /lib64/libc.so.6
0x00007f33f7258ad0  0x00007f33f7275a90  Yes         /lib64/ld-linux-x86-64.so.2
0x00007f33f63c25c0  0x00007f33f6414661  Yes         /lib64/libpcre.so.1
0x00007f33f61bdda0  0x00007f33f61be9ae  Yes         /lib64/libdl.so.2
$1 = 0x0
rax            0x56086939c280	94594125120128
rbx            0x7f33f69f0b00	139861157677824
rcx            0x56086939c2c0	94594125120192
rdx            0x800000018	34359738392
rsi            0x0	0
rdi            0x56086939c280	94594125120128
rbp            0x56086939c280	0x56086939c280
rsp            0x7ffe60ed6fa8	0x7ffe60ed6fa8
r8             0x7f33f69f1348	139861157679944
r9             0x0	0
r10            0x56086939c280	94594125120128
r11            0x7f33f69f1348	139861157679944
r12            0x18	24
r13            0x12930	76080
r14            0x5608693eb6d0	94594125444816
r15            0x0	0
rip            0x7f33f66bff3c	0x7f33f66bff3c
eflags         0x10206	[ PF IF RF ]
cs             0x33	51
ss             0x2b	43
ds             0x0	0
es             0x0	0
fs             0x0	0
gs             0x0	0
== EXPLOITABLE ==

Comment 1 Lluis 2016-11-08 21:03:56 UTC
Created attachment 1218704 [details]
File: backtrace

Comment 2 Lluis 2016-11-08 21:03:57 UTC
Created attachment 1218705 [details]
File: cgroup

Comment 3 Lluis 2016-11-08 21:03:59 UTC
Created attachment 1218706 [details]
File: core_backtrace

Comment 4 Lluis 2016-11-08 21:04:01 UTC
Created attachment 1218707 [details]
File: dso_list

Comment 5 Lluis 2016-11-08 21:04:04 UTC
Created attachment 1218708 [details]
File: environ

Comment 6 Lluis 2016-11-08 21:04:07 UTC
Created attachment 1218709 [details]
File: exploitable

Comment 7 Lluis 2016-11-08 21:04:09 UTC
Created attachment 1218710 [details]
File: limits

Comment 8 Lluis 2016-11-08 21:04:12 UTC
Created attachment 1218711 [details]
File: maps

Comment 9 Lluis 2016-11-08 21:04:14 UTC
Created attachment 1218712 [details]
File: mountinfo

Comment 10 Lluis 2016-11-08 21:04:16 UTC
Created attachment 1218713 [details]
File: namespaces

Comment 11 Lluis 2016-11-08 21:04:18 UTC
Created attachment 1218714 [details]
File: open_fds

Comment 12 Lluis 2016-11-08 21:04:20 UTC
Created attachment 1218715 [details]
File: proc_pid_status

Comment 13 Lluis 2016-11-08 21:04:22 UTC
Created attachment 1218716 [details]
File: var_log_messages

Comment 14 Fedora End Of Life 2017-07-25 23:48:47 UTC
This message is a reminder that Fedora 24 is nearing its end of life.
Approximately 2 (two) weeks from now Fedora will stop maintaining
and issuing updates for Fedora 24. It is Fedora's policy to close all
bug reports from releases that are no longer maintained. At that time
this bug will be closed as EOL if it remains open with a Fedora  'version'
of '24'.

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, simply change the 'version'
to a later Fedora version.

Thank you for reporting this issue and we are sorry that we were not
able to fix it before Fedora 24 is end of life. If you would still like
to see this bug fixed and are able to reproduce it against a later version
of Fedora, you are encouraged  change the 'version' to a later Fedora
version prior this bug is closed as described in the policy above.

Although we aim to fix as many bugs as possible during every release's
lifetime, sometimes those efforts are overtaken by events. Often a
more recent Fedora release includes newer upstream software that fixes
bugs or makes them obsolete.

Comment 15 Fedora End Of Life 2017-08-08 19:11:00 UTC
Fedora 24 changed to end-of-life (EOL) status on 2017-08-08. Fedora 24 is
no longer maintained, which means that it will not receive any further
security or bug fix updates. As a result we are closing this bug.

If you can reproduce this bug against a currently maintained version of
Fedora please feel free to reopen this bug against that version. If you
are unable to reopen this bug, please file a new report against the
current release. If you experience problems, please add a comment to this
bug.

Thank you for reporting this bug and we are sorry it could not be fixed.