compiz crashed with SIGSEGV in malloc_consolidate()

Bug #1304567 reported by Andrew Fladmark
10
This bug affects 1 person
Affects Status Importance Assigned to Milestone
compiz (Ubuntu)
Won't Fix
Medium
Unassigned

Bug Description

Was typing into the dash search. Froze after a few characters for a minute or so totally unresponsive and then only cleared the dash once it crashed.

ProblemType: Crash
DistroRelease: Ubuntu 14.04
Package: compiz-core 1:0.9.11+14.04.20140404-0ubuntu1
ProcVersionSignature: Ubuntu 3.13.0-16.36-generic 3.13.5
Uname: Linux 3.13.0-16-generic x86_64
.tmp.unity.support.test.0:

ApportVersion: 2.14.1-0ubuntu1
Architecture: amd64
CompizPlugins: No value set for `/apps/compiz-1/general/screen0/options/active_plugins'
CompositorRunning: compiz
CompositorUnredirectDriverBlacklist: '(nouveau|Intel).*Mesa 8.0'
CompositorUnredirectFSW: true
CurrentDesktop: Unity
Date: Tue Apr 8 18:22:51 2014
DistUpgraded: 2014-03-10 19:40:43,805 DEBUG enabling apt cron job
DistroCodename: trusty
DistroVariant: ubuntu
EcryptfsInUse: Yes
ExecutablePath: /usr/bin/compiz
GraphicsCard:
 Intel Corporation 2nd Generation Core Processor Family Integrated Graphics Controller [8086:0116] (rev 09) (prog-if 00 [VGA controller])
   Subsystem: ASUSTeK Computer Inc. Device [1043:1682]
 NVIDIA Corporation GF119M [GeForce 610M] [10de:105a] (rev ff) (prog-if ff)
InstallationDate: Installed on 2013-09-28 (192 days ago)
InstallationMedia: Ubuntu 13.10 "Saucy Salamander" - Beta amd64 (20130925.1)
MachineType: ASUSTeK Computer Inc. U36SG
ProcCmdline: compiz
ProcEnviron:
 LANGUAGE=en_GB:en
 PATH=(custom, no user)
 XDG_RUNTIME_DIR=<set>
 LANG=en_GB.UTF-8
 SHELL=/bin/bash
ProcKernelCmdLine: BOOT_IMAGE=/boot/vmlinuz-3.13.0-16-generic root=UUID=f26f9da8-9f71-46b2-ba32-73154517ee8d ro quiet splash
SegvAnalysis:
 Segfault happened at: 0x7fcd4e7a4685 <malloc_consolidate+133>: cmp 0x18(%rax),%r12
 PC (0x7fcd4e7a4685) ok
 source "0x18(%rax)" (0x7fff0cc2f88dac8a) not located in a known VMA region (needed readable region)!
 destination "%r12" ok
 Stack memory exhausted (SP below stack segment)
SegvReason: reading unknown VMA
Signal: 11
SourcePackage: compiz
StacktraceTop:
 malloc_consolidate (av=av@entry=0x7fccf8000020) at malloc.c:4165
 _int_free (av=0x7fccf8000020, p=<optimised out>, have_lock=0) at malloc.c:4057
 FT_Remove_Module () from /usr/lib/x86_64-linux-gnu/libfreetype.so.6
 FT_Done_Library () from /usr/lib/x86_64-linux-gnu/libfreetype.so.6
 FT_Done_FreeType () from /usr/lib/x86_64-linux-gnu/libfreetype.so.6
Title: compiz crashed with SIGSEGV in malloc_consolidate()
UpgradeStatus: Upgraded to trusty on 2014-03-10 (28 days ago)
UserGroups: adm cdrom dip lpadmin plugdev sambashare sudo
dmi.bios.date: 10/19/2011
dmi.bios.vendor: American Megatrends Inc.
dmi.bios.version: U36SG.202
dmi.board.asset.tag: ATN12345678901234567
dmi.board.name: U36SG
dmi.board.vendor: ASUSTeK Computer Inc.
dmi.board.version: 1.0
dmi.chassis.asset.tag: No Asset Tag
dmi.chassis.type: 10
dmi.chassis.vendor: ASUSTeK Computer Inc.
dmi.chassis.version: 1.0
dmi.modalias: dmi:bvnAmericanMegatrendsInc.:bvrU36SG.202:bd10/19/2011:svnASUSTeKComputerInc.:pnU36SG:pvr1.0:rvnASUSTeKComputerInc.:rnU36SG:rvr1.0:cvnASUSTeKComputerInc.:ct10:cvr1.0:
dmi.product.name: U36SG
dmi.product.version: 1.0
dmi.sys.vendor: ASUSTeK Computer Inc.
version.compiz: compiz 1:0.9.11+14.04.20140404-0ubuntu1
version.ia32-libs: ia32-libs N/A
version.libdrm2: libdrm2 2.4.52-1
version.libgl1-mesa-dri: libgl1-mesa-dri 10.1.0-4ubuntu1
version.libgl1-mesa-dri-experimental: libgl1-mesa-dri-experimental N/A
version.libgl1-mesa-glx: libgl1-mesa-glx 10.1.0-4ubuntu1
version.xserver-xorg-core: xserver-xorg-core 2:1.15.0-1ubuntu7
version.xserver-xorg-input-evdev: xserver-xorg-input-evdev 1:2.8.2-1ubuntu2
version.xserver-xorg-video-ati: xserver-xorg-video-ati 1:7.3.0-1ubuntu3
version.xserver-xorg-video-intel: xserver-xorg-video-intel 2:2.99.910-0ubuntu1
version.xserver-xorg-video-nouveau: xserver-xorg-video-nouveau 1:1.0.10-1ubuntu2
xserver.bootTime: Tue Apr 8 17:26:28 2014
xserver.configfile: default
xserver.errors:

xserver.logfile: /var/log/Xorg.0.log
xserver.outputs:
 product id 21060
 vendor COR
xserver.version: 2:1.15.0-1ubuntu7

Revision history for this message
Andrew Fladmark (afladmark) wrote :
information type: Private → Private Security
Revision history for this message
Apport retracing service (apport) wrote :

StacktraceTop:
 malloc_consolidate (av=av@entry=0x7fccf8000020) at malloc.c:4165
 _int_free (av=0x7fccf8000020, p=<optimized out>, have_lock=0) at malloc.c:4057
 Destroy_Driver (driver=<optimized out>) at /build/buildd/freetype-2.5.2/freetype-2.5.2/src/base/ftobjs.c:969
 Destroy_Module (module=<optimized out>) at /build/buildd/freetype-2.5.2/freetype-2.5.2/src/base/ftobjs.c:4195
 FT_Remove_Module (library=0x7fccf8000020, module=0x7fccf80135c0) at /build/buildd/freetype-2.5.2/freetype-2.5.2/src/base/ftobjs.c:4456

Revision history for this message
Apport retracing service (apport) wrote : Stacktrace.txt
Revision history for this message
Apport retracing service (apport) wrote : ThreadStacktrace.txt
Changed in compiz (Ubuntu):
importance: Undecided → Medium
tags: removed: need-amd64-retrace
Revision history for this message
Seth Arnold (seth-arnold) wrote : Bug is not a security issue

Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privilege boundaries nor directly cause loss of data/privacy. Please feel free to report any other bugs you may find.

information type: Private Security → Public
Revision history for this message
Andrew Fladmark (afladmark) wrote :

Sorry, Seth. I'm not sure what happened there. I didn't tick the security issue option when I submitted the bug. I only noticed it had set it private after, but I wasn't sure if there was some other reason for it.

Revision history for this message
Will Cooke (willcooke) wrote :

As part of the big bug clear up for 16.04 LTS I am marking this bug as Wont Fix.
These types of crasher are better handled by errors.ubutnu.com which can collate similar crash reports to help us identify persitent bugs rather than one-off crashes.
Sorry we are not able to help with this specific issue. If you are still experiencing this crash, please re-open the bug and add the tag "desktop-bugscrub-reopened". See https://wiki.ubuntu.com/BigDesktopBugScrub for more information.

Changed in compiz (Ubuntu):
status: New → Won't Fix
tags: added: desktop-bugscrub-autoclosed
To post a comment you must log in.