Changes between Initial Version and Version 1 of Ticket #2431


Ignore:
Timestamp:
12/26/22 12:37:52 (16 months ago)
Author:
bullerdu@…
Comment:

Legend:

Unmodified
Added
Removed
Modified
  • Ticket #2431 – Description

    initial v1  
    22READ of size 6 at 0x61e00004a4a0 thread T0
    33
    4     #0 0x4e9d7e in __interceptor_memcpy.part.41 (/home/admin/tengine/bin/t-coresystem-tengine-cdn-debug+0x4e9d7e)
     4    #0 0x4e9d7e in __interceptor_memcpy.part.41 (nginx +0x4e9d7e)
    55    #1 0x82b1af in ngx_http_v3_insert src/http/v3/ngx_http_v3_table.c:231
    66    #2 0x82cd6f in ngx_http_v3_duplicate src/http/v3/ngx_http_v3_table.c:421
     
    1717    #13 0x5864fc in main src/core/nginx.c:448
    1818    #14 0x7fe4638fd444 in __libc_start_main (/lib64/libc.so.6+0x22444)
    19     #15 0x4ac228  (/home/admin/tengine/bin/t-coresystem-tengine-cdn-debug+0x4ac228)
     19    #15 0x4ac228  (nginx +0x4ac228)
    2020
    2121freed by thread T0 here:
    22     #0 0x54e7e0 in free (/home/admin/tengine/bin/t-coresystem-tengine-cdn-debug+0x54e7e0)
     22    #0 0x54e7e0 in free (nginx+0x54e7e0)
    2323    #1 0x82aded in ngx_http_v3_evict src/http/v3/ngx_http_v3_table.c:381
    2424    #2 0x82afec in ngx_http_v3_insert src/http/v3/ngx_http_v3_table.c:210
     
    3838
    3939previously allocated by thread T0 here:
    40     #0 0x54eaf8 in malloc (/home/admin/tengine/bin/t-coresystem-tengine-cdn-debug+0x54eaf8)
     40    #0 0x54eaf8 in malloc (nginx+0x54eaf8)
    4141    #1 0x5fc3a3 in ngx_alloc src/os/unix/ngx_alloc.c:22
    4242    #2 0x82b12d in ngx_http_v3_insert src/http/v3/ngx_http_v3_table.c:221
     
    5656    #16 0x7fe4638fd444 in __libc_start_main (/lib64/libc.so.6+0x22444)
    5757
    58 SUMMARY: AddressSanitizer: heap-use-after-free (/home/admin/tengine/bin/t-coresystem-tengine-cdn-debug+0x4e9d7e) in __interceptor_memcpy.part.41
     58SUMMARY: AddressSanitizer: heap-use-after-free (nginx+0x4e9d7e) in __interceptor_memcpy.part.41
    5959Shadow bytes around the buggy address:
    6060  0x0c3c80001440: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd