Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-88167

oscap segfaults when --report option is used

Linking RHIVOS CVEs to...Migration: Automation ...Sync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Duplicate
    • Icon: Undefined Undefined
    • None
    • rhel-9.5
    • libxslt
    • None
    • No
    • Important
    • rhel-display-desktop-foundation
    • ssg_display
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      What were you trying to do that didn't work?

      Running oscap with the --report option segfaults:

      Title   Use Only Strong MACs
      Rule    xccdf_org.ssgproject.content_rule_sshd_use_strong_macs
      Ident   CCE-86769-7
      Result  fail
      
      realloc failed !
      Segmentation fault (core dumped)
      

      Log:

      Apr 23 12:06:50 localhost kernel: oscap[56615]: segfault at 0 ip 00007f8d5de40f4d sp 00007ffe4043f5c0 error 4 in libxslt.so.1.1.34[7f8d5de3c000+2a000] likely on CPU 0 (core 0, socket 0)
      Apr 23 12:06:50 localhost kernel: Code: ba 00 00 00 45 31 ed eb 17 0f 1f 40 00 8b 83 38 01 00 00 49 83 c5 01 44 39 e8 0f 8e 9e 00 00 00 48 8b 83 30 01 00 00 4c 89 e6 <4a> 8b 3c e8 e8 1a c8 ff ff 85 c0 74 d6 48 8b 44 24 08 48 89 ef ff
      

      The issue is only reproducible with 'libxslt-1.1.34-9.el9_5.2.x86_64', it doesn't happen with version 'libxslt-1.1.34-9.el9_5.1.x86_64'.

      Please provide the package NVR for which the bug is seen:

      openscap-1.3.10-2.el9_3.x86_64
      openscap-scanner-1.3.10-2.el9_3.x86_64
      libxslt-1.1.34-9.el9_5.2.x86_64
      scap-security-guide-0.1.76-1.el9.noarch

      How reproducible is this bug?:

      Always

      Steps to reproduce

      1. Set up a freshly installed RHEL 9.5 or update the system.
      2. Run oscap with the --report option. For example:
        oscap xccdf eval --fetch-remote-resources --profile xccdf_org.ssgproject.content_profile_cis_server_l1 --report /tmp/report.html /usr/share/xml/scap/ssg/content/ssg-rhel9-ds.xml
        

              dking@redhat.com David King
              rhn-support-jeperez Jesus Perez
              David King David King
              Tomas Pelka Tomas Pelka
              Votes:
              0 Vote for this issue
              Watchers:
              9 Start watching this issue

                Created:
                Updated:
                Resolved: