[Oisf-users] Frequent segfaults on Suricata 1.4.1-15ubuntu15

Fernando Sclavo fsclavo at gmail.com
Tue May 21 19:32:23 UTC 2013

Hi, our Suricata box are crashing about once a day with the following BT:

idsuser at suricata:/$ sudo gdb /usr/bin/suricata ./core
GNU gdb (Ubuntu/Linaro 7.4-2012.04-0ubuntu2.1) 7.4-2012.04
Copyright (C) 2012 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.  Type "show copying"
and "show warranty" for details.
This GDB was configured as "x86_64-linux-gnu".
For bug reporting instructions, please see:
Reading symbols from /usr/bin/suricata...Reading symbols from

warning: core file may not match specified executable file.
[New LWP 14778]
[New LWP 18767]
[New LWP 14779]
[New LWP 14783]
[New LWP 14763]
[New LWP 14762]
[New LWP 14745]
[New LWP 14782]
[New LWP 14768]
[New LWP 14765]
[New LWP 14771]
[New LWP 14770]
[New LWP 14769]
[New LWP 14773]
[New LWP 14761]
[New LWP 14766]
[New LWP 14777]
[New LWP 14772]
[New LWP 14780]
[New LWP 14775]
[New LWP 14781]
[New LWP 14776]
[New LWP 14767]
[New LWP 14764]
[New LWP 14774]

warning: Can't read pathname for load map: Input/output error.
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1".
Core was generated by `suricata -D -c /etc/suricata/suricata.yaml
Program terminated with signal 11, Segmentation fault.
#0  0x000000000000000f in ?? ()
(gdb) bt
#0  0x000000000000000f in ?? ()
#1  0x000000000048702b in SigMatchSignatures (th_v=0x2caeed50,
de_ctx=0x7fda40000930, det_ctx=0x7fda23fcc070, p=0x7217750)
    at detect.c:1553
#2  0x0000000000487858 in Detect (tv=0x2caeed50, p=0x7217750,
data=0x7fda23fcc070, pq=0x2f723fb0, postpq=0x0) at detect.c:1794
#3  0x00000000005bdfcd in TmThreadsSlotVarRun (tv=0x2caeed50, p=0x7217750,
slot=0x2ae24fd0) at tm-threads.c:542
#4  0x000000000058113d in TmThreadsSlotProcessPkt (tv=0x2caeed50,
s=0x2ae24fd0, p=0x7217750) at tm-threads.h:139
#5  0x0000000000583476 in AFPReadFromRing (ptv=0x7fe2b40008c0) at
#6  0x000000000058442c in ReceiveAFPLoop (tv=0x2caeed50,
data=0x7fe2b40008c0, slot=0x2b29d530) at source-af-packet.c:1030
#7  0x00000000005be904 in TmThreadsSlotPktAcqLoop (td=0x2caeed50) at
#8  0x00007fe313637e9a in start_thread () from
#9  0x00007fe312efbccd in clone () from /lib/x86_64-linux-gnu/libc.so.6
#10 0x0000000000000000 in ?? ()

Please let me know hoy can I help to solve the issue!
Best regards
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openinfosecfoundation.org/pipermail/oisf-users/attachments/20130521/ed479fcd/attachment.html>

More information about the Oisf-users mailing list