gnutls_ext_register causing memory corruption

Martin von Gagern Martin.vGagern at gmx.net
Sat Jun 6 19:47:37 CEST 2009


Hi folks!

There seems to be some evidence that the latest gnutls might be involved
in instabilities of the adobe flash plugin for mozilla firefox on gentoo
linux.

I myself got this error message and back trace at one point:

*** glibc detected *** /usr/lib/mozilla-firefox/firefox: realloc():
invalid next size: 0x1026c8f0 ***
======= Backtrace: =========
/lib/libc.so.6[0x4c59d7c4]
/lib/libc.so.6[0x4c5a2c24]
/lib/libc.so.6(realloc+0xdd)[0x4c5a2fbd]
/usr/lib/libgnutls.so.26(gnutls_ext_register+0x38)[0xb7b0185e]
/usr/lib/libgnutls.so.26[0xb7b01920]
/usr/lib/libgnutls.so.26(gnutls_global_init+0x1a0)[0xb7b08513]
/usr/lib/libcurl.so.4(Curl_gtls_init+0x2c)[0xb2d33037]
/usr/lib/libcurl.so.4(Curl_ssl_init+0x33)[0xb2d348fa]
/usr/lib/libcurl.so.4(curl_global_init+0x88)[0xb2d28d9d]
/opt/netscape/plugins/libflashplayer.so[0xb213de16]

http://bugs.gentoo.org/272388#c7 lists a similar back trace, with
"double free or corruption (!prev)" instead of "invalid next size".
http://bugs.gentoo.org/260630 might be dealing with the same bug.

In all these cases, the latest (and rather recently released) closed
source flash player was involved as well, so I cannot rule out a problem
with that code. You might wish to investigate the issue on the gnutls
side nevertheless, and maybe subscribe to those bugs to stay tuned.

Greetings,
 Martin von Gagern

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 261 bytes
Desc: OpenPGP digital signature
URL: </pipermail/attachments/20090606/12a18876/attachment.pgp>


More information about the Gnutls-devel mailing list