The Samba-Bugzilla – Attachment 16704 Details for
Bug 14770
CVE-2021-3671 [SECURITY] Samba, Heimdal and MIT Kerberos crash on missing sname in TGS-REQ
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Requests
|
Help
|
New Account
|
Log In
[x]
|
Forgot Password
Login:
[x]
backtrace for current MIT Kerberos
mit_backtrace.txt (text/plain), 4.77 KB, created by
Joseph Sutton
on 2021-07-29 23:05:01 UTC
(
hide
)
Description:
backtrace for current MIT Kerberos
Filename:
MIME Type:
Creator:
Joseph Sutton
Created:
2021-07-29 23:05:01 UTC
Size:
4.77 KB
patch
obsolete
>#0 get_local_tgt (context=0x555555ccd630, realm=realm@entry=0x8, candidate=0x5555559aa400, alias_out=alias_out@entry=0x7fffffffb310, storage_out=storage_out@entry=0x7fffffffb318, key_out=key_out@entry=0x7fffffffb3c0) at kdc_util.c:494 > ret = <optimized out> > princ = 0x0 > storage = 0x0 > tgt = <optimized out> >#1 0x0000555555560048 in process_tgs_req (request=<optimized out>, pkt=pkt@entry=0x555555a2d590, from=from@entry=0x555555f0ee40, kdc_active_realm=0x555555e1cb70, response=response@entry=0x7fffffffb598) at do_tgs_req.c:208 > subkey = 0x555555bae150 > header_key = 0x555555e8b7a0 > stkt_server_key = 0x0 > subject_key = <optimized out> > server = 0x0 > stkt_server = 0x0 > subject_server = <optimized out> > reply = {magic = 0, msg_type = 0, padata = 0x0, client = 0x0, ticket = 0x0, enc_part = {magic = 0, enctype = 0, kvno = 0, ciphertext = {magic = 0, length = 0, data = 0x0}}, enc_part2 = 0x0} > reply_encpart = {magic = 0, msg_type = 0, session = 0x0, last_req = 0x0, nonce = 0, key_exp = 0, flags = 0, times = {authtime = 0, starttime = 0, endtime = 0, renew_till = 0}, server = 0x0, caddrs = 0x0, enc_padata = 0x0} > ticket_reply = {magic = 0, server = 0x0, enc_part = {magic = 0, enctype = 0, kvno = 0, ciphertext = {magic = 0, length = 0, data = 0x0}}, enc_part2 = 0x0} > header_ticket = 0x5555569bd0d0 > stkt = 0x0 > enc_tkt_reply = {magic = 0, flags = 0, session = 0x0, client = 0x0, transited = {magic = 0, tr_type = 0 '\000', tr_contents = {magic = 0, length = 0, data = 0x0}}, times = {authtime = 0, starttime = 0, endtime = 0, renew_till = 0}, caddrs = 0x0, authorization_data = 0x0} > newtransited = 0 > retval = 0 > server_keyblock = {magic = 0, enctype = 0, length = 0, contents = 0x0} > encrypting_key = <optimized out> > kdc_time = 32767 > authtime = 0 > session_key = {magic = 2, enctype = 0, length = 3145715456, contents = 0x0} > local_tgt_key = {magic = 0, enctype = 0, length = 0, contents = 0x0} > reply_key = 0x0 > cprinc = 0x555555a7d9f0 > sprinc = 0x0 > altcprinc = 0x0 > authdata_client = <optimized out> > stkt_authdata_client = 0x0 > nolrarray = {0x2000000040, 0x55550000000c} > nolrentry = {magic = 32767, lr_type = -135819000, value = 32767} > errcode = 0 > status = 0x0 > header_enc_tkt = 0x0 > subject_tkt = 0x0 > client = 0x0 > header_server = 0x5555559aa400 > local_tgt = 0x0 > local_tgt_storage = 0x0 > s4u_x509_user = 0x0 > c_flags = 0 > s_flags = 0 > is_referral = <optimized out> > is_crossrealm = <optimized out> > emsg = 0x0 > ticket_kvno = 0 > state = 0x555556530070 > pa_tgs_req = 0x5555561a57a0 > scratch = {magic = 0, length = 1406, data = 0x55555686c460 "\340\243\026VUU"} > e_data = 0x0 > au_state = 0x5555567d02c0 > auth_indicators = 0x0 > ad_info = 0x0 > stkt_ad_info = 0x0 > __PRETTY_FUNCTION__ = "process_tgs_req" >#2 0x000055555555d2ee in dispatch (cb=0x55555557b1d0 <shandle>, local_addr=local_addr@entry=0x555555a2d578, remote_addr=remote_addr@entry=0x555555f0ee40, pkt=pkt@entry=0x555555a2d590, is_tcp=is_tcp@entry=1, vctx=vctx@entry=0x55555565ca00, respond=0x55555556f5a7 <process_tcp_response>, arg=0x555555a2d4e0) at dispatch.c:196 > retval = 0 > req = 0x555555db0960 > response = 0x0 > state = 0x555555c028e0 > handle = 0x55555557b1d0 <shandle> > kdc_err_context = 0x555555ccd630 >#3 0x0000555555570e2f in process_tcp_connection_read (ctx=0x55555565ca00, ev=<optimized out>) at net-server.c:1359 > local_saddrlen = 16 > state = 0x555555a2d4e0 > conn = 0x555555f0ed50 > nread = <optimized out> > len = 267 >#4 0x00007ffff7e003c7 in verto_fire (ev=0x555555f4cd40) at verto.c:1006 > priv = <optimized out> > __PRETTY_FUNCTION__ = "verto_fire" >#5 0x00007ffff7e0104c in libev_callback (loop=<optimized out>, w=0x55555624dcb0, revents=1) at verto-k5ev.c:133 > state = <optimized out> >#6 0x00007ffff7e0056b in k5ev_invoke_pending (loop=0x7ffff7e079a0 <default_loop_struct>) at ev.c:3295 > p = <optimized out> >#7 0x00007ffff7e02f4f in k5ev_run (loop=0x7ffff7e079a0 <default_loop_struct>, flags=flags@entry=0) at ev.c:3695 > __PRETTY_FUNCTION__ = "k5ev_run" >#8 0x00007ffff7e033c1 in k5ev_ctx_run (ctx=<optimized out>) at verto-k5ev.c:91 >No locals. >#9 0x00007ffff7dffa47 in verto_run (ctx=0x55555565ca00) at verto.c:630 >No locals. >#10 0x0000555555569d47 in main (argc=1, argv=<optimized out>) at main.c:1055 > retval = 0 > kcontext = 0x55555557d530 > realm = <optimized out> > ctx = 0x55555565ca00 > tcp_listen_backlog = 5 > i = <optimized out>
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Raw
Actions:
View
Attachments on
bug 14770
:
16703
| 16704