Project

General

Profile

Actions

Bug #5445

open

RX thread hang in pcap-file mode

Added by jun liu 2 months ago. Updated 2 months ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

Based on suricata 6.0.1 RX thread sometimes hang, so RX can't read pcap file.
Other people have been referred to the same problem´╝Ü
(1) https://redmine.openinfosecfoundation.org/issues/3049
(2) https://redmine.openinfosecfoundation.org/issues/3075
While reading pcap file, function PcapFileDispatch try to call PacketPoolWait,
PacketPoolWait may hang on "SCCondWait(&my_pool->return_stack.cond, &my_pool->return_stack.mutex);".
It seems nobody sends Signal to it.


Files

Actions #1

Updated by jun liu 2 months ago

  • File 2022-07-07-Emotet-infection-with-Cobalt-Strike.pcap added
Actions #2

Updated by jun liu 2 months ago

  • File deleted (2022-07-07-Emotet-infection-with-Cobalt-Strike.pcap)
Actions

Also available in: Atom PDF