rpcb_getport_async in sunrpc can cause oops on Hardy
Bug #224750 reported by
HIRANO Takahito
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
linux (Ubuntu) |
Fix Released
|
High
|
Tim Gardner | ||
Hardy |
Fix Released
|
High
|
Tim Gardner | ||
Intrepid |
Fix Released
|
High
|
Tim Gardner |
Bug Description
The rpcb_getport_async function in the sunrpc module copies larger memory area than the allocated on Ubuntu Hardy.
This can cause oops.
This bug is derived from Linux 2.6.24 in kernel.org.
It seems to be fixed on Linux 2.6.25 in kernel.org by the commit 86d61d8638ddf9c
description: | updated |
Changed in linux: | |
assignee: | nobody → timg-tpi |
importance: | Undecided → High |
status: | New → Fix Committed |
Changed in linux: | |
milestone: | ubuntu-8.04.1 → none |
Changed in linux: | |
milestone: | none → ubuntu-8.04.1 |
To post a comment you must log in.
The log message should be like:
Apr 28 11:37:07 suzu kernel: [791867.915427] Unable to handle kernel paging request at ffff88003f68c000 RIP: conservative cpufreq_ondemand freq_table cpufreq_powersave ipv6 af_packet aes_x86_64 dm_crypt dm_mod evdev ext2 mbcache c+0xb/0x20] [memcpy_c+0xb/0x20] memcpy_c+0xb/0x20 341ca0 EFLAGS: 00010246 0(0000) GS:ffffffff805c 6000(0000) knlGS:000000000 0000000 6d3>] :sunrpc: rpcb_getport_ async+0x1d3/ 0x3d0 b8b>] :sunrpc: __rpc_execute+ 0x6b/0x290 f86>] :sunrpc: rpc_do_ run_task+ 0x76/0xd0 97a>] :lockd: nlm_gc_ hosts+0x5a/ 0x1d0 045>] :sunrpc: rpc_call_ sync+0x15/ 0x40 894>] :lockd: nlmclnt_ call+0xd4/ 0x2e0
Apr 28 11:37:07 suzu kernel: [791867.915445] [memcpy_c+0xb/0x20] memcpy_c+0xb/0x20
Apr 28 11:37:07 suzu kernel: [791867.915455] PGD 1b77067 PUD 1b78067 PMD 1d74067 PTE 0
Apr 28 11:37:07 suzu kernel: [791867.915461] Oops: 0000 [1] SMP
Apr 28 11:37:07 suzu kernel: [791867.915464] CPU 0
Apr 28 11:37:07 suzu kernel: [791867.915467] Modules linked in: fuse nfs lockd nfs_acl sunrpc binfmt_misc rfcomm l2cap bluetooth ppdev parport_pc lp parport autofs4 cpufreq_userspace cpufreq_stats cpufreq_
Apr 28 11:37:07 suzu kernel: [791867.915496] Pid: 31236, comm: pidgin Not tainted 2.6.24-16-xen #1
Apr 28 11:37:07 suzu kernel: [791867.915498] RIP: e030:[memcpy_
Apr 28 11:37:07 suzu kernel: [791867.915502] RSP: e02b:ffff880030
Apr 28 11:37:07 suzu kernel: [791867.915504] RAX: ffff880040445de0 RBX: ffff880040445dc0 RCX: 0000000000000004
Apr 28 11:37:07 suzu kernel: [791867.915507] RDX: 0000000000000000 RSI: ffff88003f68c000 RDI: ffff880040445e40
Apr 28 11:37:07 suzu kernel: [791867.915509] RBP: ffff88003f076800 R08: 0000000000000000 R09: ffff880040445dc0
Apr 28 11:37:07 suzu kernel: [791867.915512] R10: ffffffff804984a0 R11: 0000000000000000 R12: ffff88003eaeca00
Apr 28 11:37:07 suzu kernel: [791867.915514] R13: ffff880040589080 R14: ffff88003eaecc00 R15: 0000000000000070
Apr 28 11:37:07 suzu kernel: [791867.915518] FS: 00007ff5e4a1495
Apr 28 11:37:07 suzu kernel: [791867.915520] CS: e033 DS: 0000 ES: 0000
Apr 28 11:37:07 suzu kernel: [791867.915523] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
Apr 28 11:37:07 suzu kernel: [791867.915525] DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000000
Apr 28 11:37:07 suzu kernel: [791867.915528] Process pidgin (pid: 31236, threadinfo ffff880030340000, task ffff880030306040)
Apr 28 11:37:07 suzu kernel: [791867.915530] Stack: ffffffff881136d3 ffff880040589080 ffffffff8814d670 85e90b856f000002
Apr 28 11:37:07 suzu kernel: [791867.915537] 0000000000000000 0000000000000000 ffff880040589080 ffffffff88119370
Apr 28 11:37:07 suzu kernel: [791867.915542] ffff880040589170 ffff88003dcb3080 ffffffff8810ab8b ffffffff88119370
Apr 28 11:37:07 suzu kernel: [791867.915546] Call Trace:
Apr 28 11:37:07 suzu kernel: [791867.915566] [<ffffffff88113
Apr 28 11:37:07 suzu kernel: [791867.915579] [<ffffffff8810a
Apr 28 11:37:07 suzu kernel: [791867.915592] [<ffffffff88103
Apr 28 11:37:07 suzu kernel: [791867.915600] [<ffffffff8813d
Apr 28 11:37:07 suzu kernel: [791867.915611] [<ffffffff88104
Apr 28 11:37:07 suzu kernel: [791867.915617] [<ffffffff8813c
Apr 28 11:37:07 suzu kernel: [791867...