Bug 1538865
Summary: | [abrt] [composer-autosave] Use-after-free during snapshot save to file | ||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Matt McAdoo <fedorabugs> | ||||||||||||||||||||||||||
Component: | evolution | Assignee: | Milan Crha <mcrha> | ||||||||||||||||||||||||||
Status: | CLOSED NEXTRELEASE | QA Contact: | Fedora Extras Quality Assurance <extras-qa> | ||||||||||||||||||||||||||
Severity: | unspecified | Docs Contact: | |||||||||||||||||||||||||||
Priority: | unspecified | ||||||||||||||||||||||||||||
Version: | 28 | CC: | alexl, caillon+fedoraproject, fedora, jappleii, jwilliams, lucilanga, mcrha, rhughes, rstrode | ||||||||||||||||||||||||||
Target Milestone: | --- | Keywords: | Reopened | ||||||||||||||||||||||||||
Target Release: | --- | ||||||||||||||||||||||||||||
Hardware: | x86_64 | ||||||||||||||||||||||||||||
OS: | Unspecified | ||||||||||||||||||||||||||||
URL: | https://retrace.fedoraproject.org/faf/reports/bthash/7bd649eb6a98de514fc97ecc65600616fee7aeb3 | ||||||||||||||||||||||||||||
Whiteboard: | abrt_hash:480c8bcc95aaeee5b47fed2d3c8609a784be33fe;VARIANT_ID=workstation; | ||||||||||||||||||||||||||||
Fixed In Version: | evolution-3.28.3 | Doc Type: | If docs needed, set a value | ||||||||||||||||||||||||||
Doc Text: | Story Points: | --- | |||||||||||||||||||||||||||
Clone Of: | Environment: | ||||||||||||||||||||||||||||
Last Closed: | 2018-05-29 11:24:49 UTC | Type: | --- | ||||||||||||||||||||||||||
Regression: | --- | Mount Type: | --- | ||||||||||||||||||||||||||
Documentation: | --- | CRM: | |||||||||||||||||||||||||||
Verified Versions: | Category: | --- | |||||||||||||||||||||||||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||||||||||||||||||||||
Cloudforms Team: | --- | Target Upstream Version: | |||||||||||||||||||||||||||
Embargoed: | |||||||||||||||||||||||||||||
Attachments: |
|
Description
Matt McAdoo
2018-01-26 00:55:19 UTC
Created attachment 1386390 [details]
File: backtrace
Created attachment 1386391 [details]
File: cgroup
Created attachment 1386392 [details]
File: core_backtrace
Created attachment 1386393 [details]
File: cpuinfo
Created attachment 1386394 [details]
File: dso_list
Created attachment 1386395 [details]
File: environ
Created attachment 1386396 [details]
File: exploitable
Created attachment 1386397 [details]
File: limits
Created attachment 1386398 [details]
File: maps
Created attachment 1386399 [details]
File: open_fds
Created attachment 1386400 [details]
File: proc_pid_status
Created attachment 1386401 [details]
File: var_log_messages
Thanks for a bug report. It looks like a coincidence, when you finished the message and sent it there also triggered an autosave of it, which had been accessing already freed memory or something like that. I've been able to reproduce this by cheating in the code, to have time to close the composer while it was saving the content. It's fixed for the next release with: Created commit 79dd568d6d in evo master (3.27.90+) [1] Created commit 963e2b721a in evo gnome-3-26 (3.26.5+) [1] https://git.gnome.org/browse/evolution/commit/?id=79dd568d6d It looks like I didn't fix it completely, I just noticed something odd. I'll investigate it further and then update this bug report. Hrm, while it seemed like I'm able to reproduce this just by sending the message yesterday, I'm not able to reproduce it today. I'll keep watching for this issue and update the bug if I find anything. *** Bug 1543644 has been marked as a duplicate of this bug. *** *** Bug 1554144 has been marked as a duplicate of this bug. *** *** Bug 1554146 has been marked as a duplicate of this bug. *** I'm reopening this bug report, both due comment #15 and due to the duplicates. I'm still not able to reproduce this reliably. It looks like one of the prerequisites is to close the composer while it is auto-saving the message, thus when the auto-save is done the composer window is gone. *** Bug 1583000 has been marked as a duplicate of this bug. *** I made some enhancements in the previous change which might help with this. I hope. Created commit 2179125d83 in evo master (3.29.3+) [1] Created commit f5f57a0f05 in evo gnome-3-28 (3.28.3+) [1] https://gitlab.gnome.org/GNOME/evolution/commit/2179125d83 |