Regression running ssllabs.com/ssltest causes 2 apache process to eat up 100% cpu, easy DoS
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
apache2 (Ubuntu) |
Invalid
|
Undecided
|
Unassigned | ||
Bionic |
Fix Released
|
Critical
|
Andreas Hasenack | ||
Cosmic |
Fix Released
|
Critical
|
Andreas Hasenack | ||
Disco |
Invalid
|
Undecided
|
Unassigned | ||
Eoan |
Invalid
|
Undecided
|
Unassigned |
Bug Description
[Impact]
With latest apache 2.4.29-1ubuntu4.7 published to 18.04 LTS bionic, when running ssllabs.com/ssltest against it to verify the configuration it leaves 2 apache processes using 100% indefinitely.
Downgrading to 2.4.29-1ubuntu4.6 make it not reproducible anymore.
[Test Case]
We didn't find a reproducer that didn't involve https:/
On a test system that has a public IP and is reachable via https on a hostname (not just IP):
sudo apt update
sudo apt install apache2
sudo a2enmod ssl
sudo a2ensite default-ssl.conf
sudo service apache2 restart
In a terminal, monitor the apache2 processes CPU usage with top.
Go to https:/
After a few minutes, the test will finish and you will get a report. Go back to the terminal where top is running, and the apache2 processes will be spinning and using CPU, even though there isn't anymore traffic.
With the fixed packages, the apache processes will remain idle.
[Regression Potential]
This upload is already fixing a regression which fixed a previous regression (#1833039), which shows that the situation is tricky. The fix here (clear-
The second patch, for http/2 errors with openssl 1.1.1, unfortunately has no test case, and deals with error status and is specific to openssl 1.1.1. It's been applied upstream (and backported to the 2.4.x branch) for many months now. The trunk commit at http://
We do have a DEP8 test that covers HTTP/2 SSL downloads, and it passes. But it also passed before this patch. I also manually tried such downloads of varying sizes (up to 10Mbytes) with no failures.
[Other Info]
While investigating this issue, another fix for an openssl 1.1.1 issue was found in the apache upstream git repo which involves http2 and how the code handles SSL_read() return values: https:/
No upstream bug was found, nor could I come up with a reproducer case, but it seemed sensible to include that patch in this SRU, which was, after all, triggered by the openssl 1.1.1 upgrade in bionic.
The d/t/run-test-suite DEP8 test is falsely returning success, but it's not running due to being called as root, and it doesn't fail either. I filed bug #1836898 about this, and ran it manually for both cosmic and bionic. There is one test failure, but it's a silly one, introduced by a patch that added a comment. The test actually parses C comments in that particular header file. The bug has the details.
cosmic patched to actually run the testsuite, showing that failure:
http://
Same for bionic:
http://
[Original Description]
With latest apache 2.4.29-1ubuntu4.7 published to 18.04 LTS bionic, when running ssllabs.com/ssltest against it to verify the configuration it leaves 2 apache processes using 100% indefinitely.
Downgrading to 2.4.29-1ubuntu4.6 make it not reproducible anymore.
So far i do not know if it is easy/likely to hit this case in normal https usage or only triggered by that testing site.
But given that this is backported to LTS and allows easy DoS maybe the 4.7 should be backed out?
So likely regression in the update to 4.7 having only single fix:
https:/
Extra info observed when that ssltest is over but processes are still there using up cpu:
/server-status shows both processes 25234,25235 here in 'Reading' state:
Srv PID Acc M CPU SS Req Conn Child Slot Client Protocol VHost Request
0-0 25234 0/0/0 W 0.00 0 0 0.0 0.00 0.00 127.0.0.1 http/1.1 ip-172-
0-0 25234 0/0/0 R 0.00 641 0 0.0 0.00 0.00 64.41.200.107 http/1.1
1-0 25235 0/1/1 _ 0.00 505 2 0.0 0.00 0.00 64.41.200.107 http/1.1
1-0 25235 0/1/1 _ 0.00 501 0 0.0 0.00 0.00 64.41.200.107 http/1.1
1-0 25235 0/1/1 _ 0.00 500 0 0.0 0.00 0.00 64.41.200.107 http/1.1
1-0 25235 0/1/1 _ 0.00 494 0 0.0 0.00 0.00 64.41.200.107 http/1.1
1-0 25235 0/1/1 _ 0.00 604 0 0.0 0.00 0.00 64.41.200.106 http/1.1
1-0 25235 0/1/1 _ 0.00 604 0 0.0 0.00 0.00 64.41.200.107 http/1.1
1-0 25235 0/1/1 _ 16.93 596 0 0.0 0.00 0.00 64.41.200.107 http/1.1
1-0 25235 0/1/1 _ 0.01 595 1 0.0 0.00 0.00 64.41.200.106 http/1.1
1-0 25235 0/0/0 R 0.00 679 0 0.0 0.00 0.00 64.41.200.106 http/1.1
netstat on system:
tcp6 1 0 172.30.1.57:443 64.41.200.106:58658 CLOSE_WAIT
tcp6 1 0 172.30.1.57:443 64.41.200.107:60842 CLOSE_WAIT
with on other connections to 443 port.
Related branches
- Bryce Harrington (community): Approve
- Canonical Server packageset reviewers: Pending requested
-
Diff: 216 lines (+188/-0)4 files modifieddebian/changelog (+9/-0)
debian/patches/clear-retry-flags-before-abort.patch (+67/-0)
debian/patches/series (+2/-0)
debian/patches/ssl-read-rc-value-openssl-1.1.1.patch (+110/-0)
- Bryce Harrington (community): Approve
- Canonical Server packageset reviewers: Pending requested
-
Diff: 216 lines (+188/-0)4 files modifieddebian/changelog (+9/-0)
debian/patches/clear-retry-flags-before-abort.patch (+67/-0)
debian/patches/series (+2/-0)
debian/patches/ssl-read-rc-value-openssl-1.1.1.patch (+110/-0)
tags: | added: regression-update |
Changed in apache2 (Ubuntu): | |
status: | Incomplete → In Progress |
information type: | Public → Public Security |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
description: | updated |
tags: | added: bionic-openssl-1.1 |
Andreas said (on the other bug) he wants to look into this today - assigning him and set prio to high according to the discussion so far.
@Stefan - since https:/ /www.ssllabs. com/ssltest/ index.html is external have you found anything else, maybe something reproducible locally without needing to expose the test host to the internet that would trigger the same?