bluetoothd crashed with SIGSEGV in malloc_consolidate() from _int_malloc() from _int_realloc() from __GI___libc_realloc() from g_realloc() from g_string_maybe_expand() from g_string_append_vprintf()

Bug #1727867 reported by Christophe Meron
20
This bug affects 2 people
Affects Status Importance Assigned to Milestone
bluez (Ubuntu)
Fix Released
Medium
Unassigned

Bug Description

https://errors.ubuntu.com/problem/61214d7f12303ee9de1d1b8a7621c6f5dc47d8f0

---

While trying to pair with a mouse (microsoft sculpt mouse)

ProblemType: Crash
DistroRelease: Ubuntu 17.10
Package: bluez 5.46-0ubuntu3
ProcVersionSignature: Ubuntu 4.13.0-16.19-generic 4.13.4
Uname: Linux 4.13.0-16-generic x86_64
ApportVersion: 2.20.7-0ubuntu3
Architecture: amd64
Date: Thu Oct 26 23:42:52 2017
ExecutablePath: /usr/lib/bluetooth/bluetoothd
InstallationDate: Installed on 2017-06-22 (125 days ago)
InstallationMedia: Ubuntu 17.04 "Zesty Zapus" - Release amd64 (20170412)
InterestingModules: rfcomm bnep btusb bluetooth
MachineType: LENOVO 20FBCTO1WW
ProcCmdline: /usr/lib/bluetooth/bluetoothd
ProcEnviron:
 LANG=fr_FR.UTF-8
 PATH=(custom, no user)
ProcKernelCmdLine: BOOT_IMAGE=/vmlinuz-4.13.0-16-generic.efi.signed root=/dev/mapper/vg--hostname-root--ubuntu ro quiet splash vt.handoff=7
SegvAnalysis:
 Segfault happened at: 0x7f6907f6d108 <malloc_consolidate+312>: mov 0x8(%rbx),%rax
 PC (0x7f6907f6d108) ok
 source "0x8(%rbx)" (0x100000007) not located in a known VMA region (needed readable region)!
 destination "%rax" ok
SegvReason: reading unknown VMA
Signal: 11
SourcePackage: bluez
StacktraceTop:
 malloc_consolidate (av=av@entry=0x7f69082bec20 <main_arena>) at malloc.c:4489
 _int_malloc (av=av@entry=0x7f69082bec20 <main_arena>, bytes=bytes@entry=1025) at malloc.c:3705
 _int_realloc (av=av@entry=0x7f69082bec20 <main_arena>, oldp=oldp@entry=0x559621487250, oldsize=oldsize@entry=544, nb=nb@entry=1040) at malloc.c:4626
 __GI___libc_realloc (oldmem=0x559621487260, bytes=1024) at malloc.c:3245
 g_realloc () from /lib/x86_64-linux-gnu/libglib-2.0.so.0
Title: bluetoothd crashed with SIGSEGV in malloc_consolidate()
UpgradeStatus: Upgraded to artful on 2017-10-09 (17 days ago)
UserGroups:

dmi.bios.date: 04/18/2016
dmi.bios.vendor: LENOVO
dmi.bios.version: N1FET40W (1.14 )
dmi.board.asset.tag: Not Available
dmi.board.name: 20FBCTO1WW
dmi.board.vendor: LENOVO
dmi.board.version: SDK0J40709 WIN
dmi.chassis.asset.tag: No Asset Information
dmi.chassis.type: 10
dmi.chassis.vendor: LENOVO
dmi.chassis.version: None
dmi.modalias: dmi:bvnLENOVO:bvrN1FET40W(1.14):bd04/18/2016:svnLENOVO:pn20FBCTO1WW:pvrThinkPadX1Carbon4th:rvnLENOVO:rn20FBCTO1WW:rvrSDK0J40709WIN:cvnLENOVO:ct10:cvrNone:
dmi.product.family: ThinkPad X1 Carbon 4th
dmi.product.name: 20FBCTO1WW
dmi.product.version: ThinkPad X1 Carbon 4th
dmi.sys.vendor: LENOVO
hciconfig:
 hci0: Type: Primary Bus: USB
  BD Address: E4:A4:71:4F:31:79 ACL MTU: 1021:4 SCO MTU: 96:6
  UP RUNNING PSCAN ISCAN
  RX bytes:980135 acl:0 sco:0 events:12127 errors:0
  TX bytes:605335 acl:0 sco:0 commands:2477 errors:0

Revision history for this message
Christophe Meron (chris+launchpad-ielf) wrote :
Revision history for this message
Apport retracing service (apport) wrote :

StacktraceTop:
 malloc_consolidate (av=av@entry=0x7f69082bec20 <main_arena>) at malloc.c:4489
 _int_malloc (av=av@entry=0x7f69082bec20 <main_arena>, bytes=bytes@entry=1025) at malloc.c:3705
 _int_realloc (av=av@entry=0x7f69082bec20 <main_arena>, oldp=oldp@entry=0x559621487250, oldsize=oldsize@entry=544, nb=nb@entry=1040) at malloc.c:4626
 __GI___libc_realloc (oldmem=0x559621487260, bytes=bytes@entry=1024) at malloc.c:3245
 g_realloc (mem=<optimized out>, n_bytes=1024) at ../../../../glib/gmem.c:159

Revision history for this message
Apport retracing service (apport) wrote : Stacktrace.txt
Revision history for this message
Apport retracing service (apport) wrote : StacktraceSource.txt
Revision history for this message
Apport retracing service (apport) wrote : ThreadStacktrace.txt
Changed in bluez (Ubuntu):
importance: Undecided → Medium
tags: removed: need-amd64-retrace
summary: - bluetoothd crashed with SIGSEGV in malloc_consolidate()
+ bluetoothd crashed with SIGSEGV in malloc_consolidate() from
+ _int_malloc() from _int_realloc() from __GI___libc_realloc() from
+ g_realloc() from g_string_maybe_expand() from g_string_append_vprintf()
information type: Private → Public
Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in bluez (Ubuntu):
status: New → Confirmed
Revision history for this message
Daniel van Vugt (vanvugt) wrote :
description: updated
Revision history for this message
Daniel van Vugt (vanvugt) wrote :

Fix Released, apparently. Zero reports of this crash after 17.10.

Changed in bluez (Ubuntu):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.