Bug 1585381 - [abrt] gputils: gp_processor_rom_width(): gplib killed by SIGSEGV
Summary: [abrt] gputils: gp_processor_rom_width(): gplib killed by SIGSEGV
Keywords:
Status: CLOSED EOL
Alias: None
Product: Fedora
Classification: Fedora
Component: gputils
Version: 27
Hardware: x86_64
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Roy Rankin
QA Contact: Fedora Extras Quality Assurance
URL: https://retrace.fedoraproject.org/faf...
Whiteboard: abrt_hash:8fea6e44536227d81dbbc8f8337...
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2018-06-02 09:11 UTC by lzavacky
Modified: 2019-01-09 12:54 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2018-11-30 21:52:27 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)
File: backtrace (3.65 KB, text/plain)
2018-06-02 09:11 UTC, lzavacky
no flags Details
File: cgroup (289 bytes, text/plain)
2018-06-02 09:11 UTC, lzavacky
no flags Details
File: core_backtrace (1.21 KB, text/plain)
2018-06-02 09:11 UTC, lzavacky
no flags Details
File: cpuinfo (1.05 KB, text/plain)
2018-06-02 09:11 UTC, lzavacky
no flags Details
File: dso_list (225 bytes, text/plain)
2018-06-02 09:11 UTC, lzavacky
no flags Details
File: environ (4.24 KB, text/plain)
2018-06-02 09:11 UTC, lzavacky
no flags Details
File: exploitable (82 bytes, text/plain)
2018-06-02 09:11 UTC, lzavacky
no flags Details
File: limits (1.29 KB, text/plain)
2018-06-02 09:11 UTC, lzavacky
no flags Details
File: maps (1.50 KB, text/plain)
2018-06-02 09:11 UTC, lzavacky
no flags Details
File: mountinfo (3.43 KB, text/plain)
2018-06-02 09:11 UTC, lzavacky
no flags Details
File: open_fds (382 bytes, text/plain)
2018-06-02 09:11 UTC, lzavacky
no flags Details
File: proc_pid_status (1.29 KB, text/plain)
2018-06-02 09:11 UTC, lzavacky
no flags Details

Description lzavacky 2018-06-02 09:11:35 UTC
Version-Release number of selected component:
gputils-1.4.2-3.fc27

Additional info:
reporter:       libreport-2.9.3
backtrace_rating: 4
cmdline:        /usr/bin/gplib -tq /home/zavacky/Desktop/Projects/Eizo_ReVue/API/RevuePlayerLLAPI_Linux_v1.5Beta6/revue_decoder_api/x64/Debug/revue_decoder_api.lib
crash_function: gp_processor_rom_width
executable:     /usr/bin/gplib
journald_cursor: s=a007f21597f84ef0914ffc1ca51e8e74;i=5591b;b=2d71906ba25e43cfbb15658054b17365;m=3de86e61;t=56da4f9e90751;x=643f861ed49bbf00
kernel:         4.16.12-200.fc27.x86_64
rootdir:        /
runlevel:       N 5
type:           CCpp
uid:            1000

Truncated backtrace:
[New LWP 3058]
Core was generated by `/usr/bin/gplib -tq /home/zavacky/Desktop/Projects/Eizo_ReVue/API/RevuePlayerLLA'.
Program terminated with signal SIGSEGV, Segmentation fault.
#0  gp_processor_rom_width (class=0x0) at gpprocessor.c:1460

Thread 1 (LWP 3058):
#0  gp_processor_rom_width (class=0x0) at gpprocessor.c:1460
        __PRETTY_FUNCTION__ = "gp_processor_rom_width"
#1  0x0000557868409fca in _read_opt_header (data=0x557869d48678, file=0x557869d486b4 "_you@Define_the_symbol__ATL_MIXED@@@8", object=0x557869d476e0) at gpreadobj.c:229
        optmagic = <optimized out>
        rom_width = 1600482921
        ram_width = <optimized out>
        vstamp = <optimized out>
        proc_code = 1717912640
        offset = <optimized out>
#2  gp_convert_file (filename=filename@entry=0x7fff983c5360 "e@12@B", data=data@entry=0x557869d48678) at gpreadobj.c:677
        object = 0x557869d476e0
        __func__ = "gp_convert_file"
#3  0x0000557868403044 in gp_archive_make_index (archive=0x557869d48560, definition=0x557869d462d0) at gparchive.c:419
        object = <optimized out>
        name = "e@12@B\000@12@B\000\061\062@B\000@@2HB\000nown@@EQ3@\000d>\000::type_e\000\060\060\061_0005::<unnamed-type-ByObjectId>\000L@@2_NB\000\000\000\371\001\000\200\224\002\000\000\373\001\000\200\231\002\000\000\002\002\000\200\246\002\000\000\003\002\000\200\317\002\000\000\004\002\000\200\370\002\000\000\005\002\000\200!\003\000\000\035\002\000\200\064\003\000\000\036\002\000\200_\003\000\000\"\002\000\200d\003\000\000$\002\000\200n\003\000\000&\002\000\200\204\003\000\000'\002\000\200\213\003\000\000(\002\000\200\240\003\000\000)\002\000"...
        end = <optimized out>
        __PRETTY_FUNCTION__ = "gp_archive_make_index"
#4  0x0000557868402049 in main (argc=<optimized out>, argv=<optimized out>) at gplib.c:309
        c = <optimized out>
        i = <optimized out>
        usage = <optimized out>
        no_index = <optimized out>
        object = <optimized out>
        __PRETTY_FUNCTION__ = "main"
From                To                  Syms Read   Shared Object Library
0x00007fba53b1d770  0x00007fba53c5e3ac  Yes         /lib64/libc.so.6
0x00007fba53eb3d50  0x00007fba53ed04d0  Yes         /lib64/ld-linux-x86-64.so.2
$1 = 0x0
rax            0x0	0
rbx            0x557869d486b4	93975659972276
rcx            0x55786864bde8	93975635869160
rdx            0x0	0
rsi            0x66654440	1717912640
rdi            0x0	0
rbp            0x5f656e69	0x5f656e69
rsp            0x7fff983c52a8	0x7fff983c52a8
r8             0x0	0
r9             0x7f	127
r10            0x0	0
r11            0x0	0
r12            0x66654440	1717912640
r13            0xc	12
r14            0x557869d476e0	93975659968224
r15            0x557869d48678	93975659972216
rip            0x557868409880	0x557868409880 <gp_processor_rom_width>
eflags         0x10246	[ PF ZF IF RF ]
cs             0x33	51
ss             0x2b	43
ds             0x0	0
es             0x0	0
fs             0x0	0
gs             0x0	0
Dump of assembler code for function gp_processor_rom_width:
=> 0x0000557868409880 <+0>:	mov    0x4(%rdi),%eax
   0x0000557868409883 <+3>:	test   %eax,%eax
   0x0000557868409885 <+5>:	jle    0x557868409889 <gp_processor_rom_width+9>
   0x0000557868409887 <+7>:	repz retq 
   0x0000557868409889 <+9>:	lea    0x16c20(%rip),%rcx        # 0x5578684204b0 <__PRETTY_FUNCTION__.6140>
   0x0000557868409890 <+16>:	lea    0x9d69(%rip),%rsi        # 0x557868413600
   0x0000557868409897 <+23>:	lea    0x9e21(%rip),%rdi        # 0x5578684136bf
   0x000055786840989e <+30>:	sub    $0x8,%rsp
   0x00005578684098a2 <+34>:	mov    $0x5b4,%edx
   0x00005578684098a7 <+39>:	callq  0x557868401a50 <__assert_fail@plt>
End of assembler dump.
== EXPLOITABLE ==

Comment 1 lzavacky 2018-06-02 09:11:41 UTC
Created attachment 1446989 [details]
File: backtrace

Comment 2 lzavacky 2018-06-02 09:11:42 UTC
Created attachment 1446990 [details]
File: cgroup

Comment 3 lzavacky 2018-06-02 09:11:43 UTC
Created attachment 1446991 [details]
File: core_backtrace

Comment 4 lzavacky 2018-06-02 09:11:44 UTC
Created attachment 1446992 [details]
File: cpuinfo

Comment 5 lzavacky 2018-06-02 09:11:45 UTC
Created attachment 1446993 [details]
File: dso_list

Comment 6 lzavacky 2018-06-02 09:11:47 UTC
Created attachment 1446994 [details]
File: environ

Comment 7 lzavacky 2018-06-02 09:11:48 UTC
Created attachment 1446995 [details]
File: exploitable

Comment 8 lzavacky 2018-06-02 09:11:49 UTC
Created attachment 1446996 [details]
File: limits

Comment 9 lzavacky 2018-06-02 09:11:51 UTC
Created attachment 1446997 [details]
File: maps

Comment 10 lzavacky 2018-06-02 09:11:52 UTC
Created attachment 1446998 [details]
File: mountinfo

Comment 11 lzavacky 2018-06-02 09:11:53 UTC
Created attachment 1446999 [details]
File: open_fds

Comment 12 lzavacky 2018-06-02 09:11:54 UTC
Created attachment 1447000 [details]
File: proc_pid_status

Comment 13 Ben Cotton 2018-11-27 15:17:25 UTC
This message is a reminder that Fedora 27 is nearing its end of life.
On 2018-Nov-30  Fedora will stop maintaining and issuing updates for
Fedora 27. It is Fedora's policy to close all bug reports from releases
that are no longer maintained. At that time this bug will be closed as
EOL if it remains open with a Fedora  'version' of '27'.

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, simply change the 'version' 
to a later Fedora version.

Thank you for reporting this issue and we are sorry that we were not 
able to fix it before Fedora 27 is end of life. If you would still like 
to see this bug fixed and are able to reproduce it against a later version 
of Fedora, you are encouraged  change the 'version' to a later Fedora 
version prior this bug is closed as described in the policy above.

Although we aim to fix as many bugs as possible during every release's 
lifetime, sometimes those efforts are overtaken by events. Often a 
more recent Fedora release includes newer upstream software that fixes 
bugs or makes them obsolete.

Comment 14 Ben Cotton 2018-11-30 21:52:27 UTC
Fedora 27 changed to end-of-life (EOL) status on 2018-11-30. Fedora 27 is
no longer maintained, which means that it will not receive any further
security or bug fix updates. As a result we are closing this bug.

If you can reproduce this bug against a currently maintained version of
Fedora please feel free to reopen this bug against that version. If you
are unable to reopen this bug, please file a new report against the
current release. If you experience problems, please add a comment to this
bug.

Thank you for reporting this bug and we are sorry it could not be fixed.


Note You need to log in before you can comment on or make changes to this bug.