Project

General

Profile

Actions

Bug #1751

closed

Suricata segfault caused by java download

Added by Michael Dods about 8 years ago. Updated almost 8 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Target version:
-
Affected Versions:
Effort:
Difficulty:
Label:

Description

The segfault is reproducable and occurs when a PC downstream of the IDS/IPS tries to initiate a Java update. The java download never actually starts. In my case Java 8 update 77. Refer the following link.
http://javadl.oracle.com/webapps/download/AutoDL?BundleId=207231

This is Suricata version 3.0 RELEASE
Mar 25 11:17:35 10.0.0.151 kernel: [SysLog]: [Site allowed: oracle.112.2o7.net] from source 10.0.0.9,
Mar 25 11:17:38 10.0.0.151 kernel: [SysLog]: [Site allowed: javadl.oracle.com] from source 10.0.0.9,
Mar 25 11:17:38 SELKS kernel: [61860.202241] AFPacketeth2430767: segfault at 2 ip 00007ff353084a6c sp 00007ff3397ef260 error 4
Mar 25 11:17:38 SELKS kernel: [61860.601737] device eth1 left promiscuous mode
Mar 25 11:17:39 SELKS kernel: [61861.007224] device eth2 left promiscuous mode

The issue started about one week ago, where I performed an apt update of the system.

It can be fixed with a 'service suricata restart', until the next time it fails.

More detail in the attachments.


Files

suricata-segfault-25032015.txt (5 KB) suricata-segfault-25032015.txt AFPacketeth24[30767]: segfault Michael Dods, 03/24/2016 08:23 PM
java update.jpg (45.9 KB) java update.jpg screen capture of download request Michael Dods, 03/24/2016 08:35 PM
crash with IDS-IPS-line 48.pcapng (30.7 KB) crash with IDS-IPS-line 48.pcapng Michael Dods, 04/12/2016 08:03 AM
Actions

Also available in: Atom PDF