Project

General

Profile

Actions

Bug #14898

closed

Suricata core dumps with signal 11

Added by Marcos M 9 months ago. Updated 7 months ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
Suricata
Target version:
-
Start date:
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
Affected Version:
Affected Plus Version:
23.09
Affected Architecture:
amd64

Description

I installed Suricata on a system with previous config using Legacy Mode, Enable/Disable/Drop SID lists. After attempting to start it without performing other actions, it crashed:

Oct 19 10:38:12 kernel pid 18065 (suricata), jid 0, uid 0: exited on signal 11 (core dumped)

I then went to Services > Suricata > SID Management, checked Rebuild, and saved. That caused it to rebuild, but it crashed again (log reversed):

Oct 19 10:44:20 kernel pid 38878 (suricata), jid 0, uid 0: exited on signal 11 (core dumped)
Oct 19 10:44:20 php 31813 [Suricata] Suricata START for WAN...
Oct 19 10:44:19 php 31813 [Suricata] Building new sid-msg.map file for ISP1...
Oct 19 10:44:19 php 31813 [Suricata] Enabling any flowbit-required rules for: ISP1...
Oct 19 10:44:17 php 31813 [Suricata] Updating rules configuration for: ISP1 ...
Oct 19 10:44:16 php-fpm 410 Starting Suricata on ISP1 per user request...

Manually starting it again then succeeded (and continued to work after rebooting):

root 58585 0.2 7.2 651116 596984 - Ss 10:47 1:04.36 |-- /usr/local/bin/suricata -i vmx1 -D -c /usr/local/etc/suricata/suricata_41734_vmx1/suricata.yaml --pidfile /var/run/suricata_vmx141734.pid


Files

coredump.7z (644 KB) coredump.7z Marcos M, 10/19/2023 04:55 PM
suricata.zip (1.8 MB) suricata.zip Marcos M, 10/31/2023 11:33 PM
Actions

Also available in: Atom PDF