RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.
Bug 1462160 - rsyslogd segfaults on invalid set statement
Summary: rsyslogd segfaults on invalid set statement
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: rsyslog
Version: 7.4
Hardware: Unspecified
OS: Unspecified
high
medium
Target Milestone: rc
: ---
Assignee: Radovan Sroka
QA Contact: Stefan Dordevic
URL:
Whiteboard:
: 1509987 1553599 (view as bug list)
Depends On:
Blocks: 1408473
TreeView+ depends on / blocked
 
Reported: 2017-06-16 10:45 UTC by Karel Srot
Modified: 2021-06-10 12:27 UTC (History)
8 users (show)

Fixed In Version: rsyslog-8.24.0-13.el7
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2018-04-10 15:26:37 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)
proposed patch (5.52 KB, patch)
2017-07-25 11:22 UTC, Marek Tamaskovic
no flags Details | Diff
proposed patch v2 (5.57 KB, patch)
2017-07-26 11:26 UTC, Marek Tamaskovic
no flags Details | Diff
final patch (5.30 KB, patch)
2017-08-28 12:59 UTC, Radovan Sroka
no flags Details | Diff


Links
System ID Private Priority Status Summary Last Updated
Red Hat Bugzilla 1188503 1 None None None 2021-01-20 06:05:38 UTC
Red Hat Product Errata RHBA-2018:0856 0 None None None 2018-04-10 15:27:12 UTC

Internal Links: 1188503

Description Karel Srot 2017-06-16 10:45:30 UTC
Description of problem:

rsyslogd segfault when set statement is not valid.

# cat /etc/rsyslog.d/test.conf
set $testvar;
# rsyslogd -n -d
Segmentation fault
# rpm -q rsyslog
rsyslog-8.24.0-12.el7.x86_64

Same result also for statement
set $testvar=;

gdb says:
Program received signal SIGSEGV, Segmentation fault.
[Switching to Thread 0x7ffff3cd0700 (LWP 11806)]
0x00007ffff639f4b7 in readjournal () at imjournal.c:326
326		if (sys_iden == NULL && !cs.dfltTag[0]) {

This is a regression against the upstream version.
I have confirmed that the issue is caused by our downstream patch 
  rsyslog-8.24.0-rhbz1188503-imjournal-default-tag.patch

Comment 2 Marek Tamaskovic 2017-07-25 11:22:26 UTC
Created attachment 1304172 [details]
proposed patch

Some guy was dereferencing pointer which was NULL in that specific case.
I fixed that condition but some addition tests are required because I am not sure if it doesn't change functionality in other use cases.

Comment 3 Radovan Sroka 2017-07-26 08:47:04 UTC
I think that previous version check only if default tag was empty string and doesn't check what this pointer was valid. Now the condition checks whether pointer is valid but not occurrence of the empty string. 

I think that condition should cover both cases.

Comment 4 Marek Tamaskovic 2017-07-26 11:26:33 UTC
Created attachment 1304713 [details]
proposed patch v2

Added string check as well.

Comment 6 Radovan Sroka 2017-08-28 12:59:13 UTC
Created attachment 1319072 [details]
final patch

Comment 11 Jiří Vymazal 2017-11-10 09:11:30 UTC
*** Bug 1509987 has been marked as a duplicate of this bug. ***

Comment 15 Jiří Vymazal 2018-03-20 09:47:54 UTC
*** Bug 1553599 has been marked as a duplicate of this bug. ***

Comment 17 errata-xmlrpc 2018-04-10 15:26:37 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2018:0856


Note You need to log in before you can comment on or make changes to this bug.