Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1755749AbaFPRuZ (ORCPT ); Mon, 16 Jun 2014 13:50:25 -0400 Received: from mail-ve0-f179.google.com ([209.85.128.179]:45614 "EHLO mail-ve0-f179.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1753785AbaFPRuW convert rfc822-to-8bit (ORCPT ); Mon, 16 Jun 2014 13:50:22 -0400 MIME-Version: 1.0 In-Reply-To: <539F2B2D.6050105@gmx.de> References: <539F1C59.6070308@gmx.de> <539F297F.7010904@nod.at> <539F2B2D.6050105@gmx.de> From: Andy Lutomirski Date: Mon, 16 Jun 2014 10:50:01 -0700 Message-ID: Subject: Re: 3.15: kernel BUG at kernel/auditsc.c:1525! To: =?UTF-8?Q?Toralf_F=C3=B6rster?= , Eric Paris Cc: Richard Weinberger , Richard Weinberger , Linux Kernel Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8BIT Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org cc: eparis. This might be a new audit bug. On Mon, Jun 16, 2014 at 10:36 AM, Toralf Förster wrote: > On 06/16/2014 07:32 PM, Andy Lutomirski wrote: >> On Mon, Jun 16, 2014 at 10:29 AM, Richard Weinberger wrote: >>> Am 16.06.2014 19:25, schrieb Andy Lutomirski: >>>> On Mon, Jun 16, 2014 at 10:21 AM, Richard Weinberger >>>> wrote: >>>>> On Mon, Jun 16, 2014 at 6:33 PM, Toralf Förster wrote: >>>>>> $ cat syscall.c >>>>>> #include >>>>>> #include >>>>>> int main(){return syscall(1000)!=-1;} >>>> >>>> What architecture are you building for? On i386 and x86_64, 1000 >>>> shouldn't be big enough to trigger this. >>> >>> Toralf, is this an UML kernel? >>> >> >> I'm also interested in the userspace architecture. If it's x32 >> userspace, then I'm not surprised that there's a problem. > > It is a x86 system (ThinkPad T420) - not x32. I don't think this is CVE-2014-3917. It looks like you're hitting this BUG: BUG_ON(context->in_syscall || context->name_count); Can you send the output of: auditctl -l [run as root] and dmesg |grep audit Are you using ptrace or anything like that (e.g. strace) when you trigger this? Are you using a funny glibc version? Do you have selinux or something like that enabled? --Andy -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/