Project

General

Profile

Actions

Bug #2422

closed

[4.0.3] af_packet: a leak that (possibly) breaks an inline channel

Added by Alexander Gozman almost 7 years ago. Updated over 6 years ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

Some days ago we have found an interesting bug with inline mode in Suricata 4.0.3 (probably earlier versions are affected too). The testcase is:

1. Start suricata in inline mode on two interfaces. E.g., on eth3 and eth4.
2. Bring eth3 down with 'ifconfig eth3 down'
3. Suricata detects that interface isdown and tries to reopen it
4. Bring eth3 up with 'ifconfig eth3 up'
5. Suricata detects that interface is up but... traffic is not received on eth3 anymore. As a result an inline channel is broken until we restart suricata.

Furthermore, we have found that the number of lines in /proc/net/packet increases when we bring interface down and then up. It looks like a leak that is not detected by valgrind.

Actions #1

Updated by Alexander Gozman almost 7 years ago

  • Assignee set to Alexander Gozman
  • Target version set to 4.0.4
Actions #2

Updated by Alexander Gozman almost 7 years ago

  • Status changed from New to Resolved
Actions #3

Updated by Alexander Gozman almost 7 years ago

  • % Done changed from 0 to 100
Actions #4

Updated by Victor Julien over 6 years ago

  • Status changed from Resolved to Closed
Actions

Also available in: Atom PDF