[Bug 1481388] [NEW] NTP : Use-after-free in routing socket code after dropping root

eric.desrochers eric.desrochers at canonical.com
Tue Aug 4 15:14:32 UTC 2015


Public bug reported:

We have 1 server (among hundreds) that its ntp service is crashing.

A few minute/seconds after a start attempts we can see the following in syslog:
Jul 1 05:33:28 svpr-stk67 ntpd[2729]: peers refreshed
Jul 1 05:33:28 svpr-stk67 ntpd[2729]: Listening on routing socket on fd #49 for interface updates
Jul 1 05:36:32 svpr-stk67 ntpd[2729]: i/o error on routing socket No buffer space available - disabling
Jul 1 05:36:32 svpr-stk67 kernel: [157516.495224] ntpd[2729]: segfault at 31 ip 0000000000000031 sp 00007ffff9f11788 error 14 in libpthread-2.15.so[7f967a5d9000+18000]

OS: Ubuntu 12.04.4 LTS
Kernel: 3.11.0-19-generic

I tried to compare it to other servers, and the only thing I could find that is different is that while it's up (before it crashes) I can see the following when running "lsof | grep ntp":
ntpd 2729 ntp 49u sock 0,7 0t0 2473952565 can't identify protocol.

** Affects: ntp (Ubuntu)
     Importance: Undecided
     Assignee: eric.desrochers (eric-desrochers-z)
         Status: New

** Changed in: ntp (Ubuntu)
     Assignee: (unassigned) => eric.desrochers (eric-desrochers-z)

** Summary changed:

- Use-after-free in routing socket code after dropping root
+ NTP : Use-after-free in routing socket code after dropping root

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to ntp in Ubuntu.
https://bugs.launchpad.net/bugs/1481388

Title:
  NTP : Use-after-free in routing socket code after dropping root

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ntp/+bug/1481388/+subscriptions



More information about the Ubuntu-server-bugs mailing list