Bug 211237
| Summary: | kernel squashfs trying to free a free buffer | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Steve Grubb <sgrubb> | ||||||
| Component: | kernel | Assignee: | Kernel Maintainer List <kernel-maint> | ||||||
| Status: | CLOSED CURRENTRELEASE | QA Contact: | Brian Brock <bbrock> | ||||||
| Severity: | medium | Docs Contact: | |||||||
| Priority: | medium | ||||||||
| Version: | rawhide | CC: | phillip, phillip.lougher, security-response-team, spacewar, wtogami | ||||||
| Target Milestone: | --- | ||||||||
| Target Release: | --- | ||||||||
| Hardware: | All | ||||||||
| OS: | Linux | ||||||||
| Whiteboard: | |||||||||
| Fixed In Version: | 2.6.18-1.2869 | Doc Type: | Bug Fix | ||||||
| Doc Text: | Story Points: | --- | |||||||
| Clone Of: | Environment: | ||||||||
| Last Closed: | 2007-01-23 18:30:59 UTC | Type: | --- | ||||||
| Regression: | --- | Mount Type: | --- | ||||||
| Documentation: | --- | CRM: | |||||||
| Verified Versions: | Category: | --- | |||||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||||
| Embargoed: | |||||||||
| Attachments: |
|
||||||||
|
Description
Steve Grubb
2006-10-18 00:05:20 UTC
Created attachment 139667 [details]
problematic image
Attached problematic image.
Hm, that may not be the image that caused this exact problem, there are a few of these floating around w/ different problems. The tool steve is using is at http://projects.info-pull.com/mokb/fsfuzzer-0.6-lmh.tgz Point it at squashfs and you'll probably eventually hit the original signature here. I've fixed this bug. I'm still tracking down another bug thrown up by fsfuzzer, when I've fixed that I'll attach a patch. What version of Squashfs are you using? Phillip 3.1 I think, but we've got a few tweaks in there to cope with the changes other patches in our tree have made (we backported the inode diet stuff from .19 for eg). btw, infamy! http://projects.info-pull.com/mokb/MOKB-02-11-2006.html Infamy, infamy, they've all got it in for me :-) (apologies to the non-Brits). A listing on MOKB, and the second bug too... Sadly not my idea of a good advertisement. I've submitted my current fufuzz fixes to Squashfs CVS (along with support for NFS). Unfortunately, I've run of time this weekend to do a patch that I could attach here. Created attachment 141292 [details]
Patch for fsfuzz triggered crashes (against Squashfs 3.1)
I have attached a patch that fixes this bug, and all other bugs that fsfuzz
triggers. With this patch applied Squashfs survived 14 consecutive runs of
fsfuzz (I stopped it after 14 runs).
Phillip
I built a kernel based off of 2849 + this patch. The kernel does not work. I don't think it makes it to the point where you see the message about decrompressing the kernel and immediately goes back to the BIOS. "I built a kernel based off of 2849 + this patch. The kernel does not work." This isn't anything to do with my patch. My patch touches three files, all within the Squashfs filesystem. Changes in these won't cause the issues you describe. Phillip I belive this was fixed in build 2869. Closing. |