[Oisf-devel] Segfault on Suricata 1.2dev, PF_RING 5.2.1. and listening on a bonded interface

Victor Julien victor at inliniac.net
Fri Jan 13 15:42:21 UTC 2012


On 01/13/2012 04:37 PM, David.R.Wharton at regions.com wrote:
> DecodeEthernet (tv=0xbfa89c0, dtv=0xda8fe48, p=0x8f27070, pkt=0x1a00ffff
> <Address 0x1a00ffff out of bounds>, len=64, pq=0xd533dd0) at
> decode-ethernet.c:56
> 56            switch (ntohs(p->ethh->eth_type)) {
> (gdb) backtrace
> #0  DecodeEthernet (tv=0xbfa89c0, dtv=0xda8fe48, p=0x8f27070,
> pkt=0x1a00ffff <Address 0x1a00ffff out of bounds>, len=64, pq=0xd533dd0)
> at decode-ethernet.c:56
> #1  0x0805ded8 in DecodePfring (tv=0xbfa89c0, p=0x8f27070,
> data=0xda8fe48, pq=0xd533dd0, postpq=0x0) at source-pfring.c:482

If you monitor the link with wireshark/tshark what is the link type? Do
the packets come in as straight ethernet packets or are they wrapped in
something else?

-- 
---------------------------------------------
Victor Julien
http://www.inliniac.net/
PGP: http://www.inliniac.net/victorjulien.asc
---------------------------------------------




More information about the Oisf-devel mailing list