Summary: | use-after-free crash on closing ktnef after opening a non-TNEF file | ||
---|---|---|---|
Product: | [Applications] ktnef | Reporter: | Santhiar <santhiar.anirudh> |
Component: | general | Assignee: | kdepim bugs <kdepim-bugs> |
Status: | RESOLVED DUPLICATE | ||
Severity: | crash | CC: | montel |
Priority: | NOR | ||
Version: | unspecified | ||
Target Milestone: | --- | ||
Platform: | Compiled Sources | ||
OS: | Linux | ||
Latest Commit: | Version Fixed In: | ||
Sentry Crash Report: | |||
Attachments: | screenshot showing that the error dialog is not application modal |
Description
Santhiar
2015-12-17 03:58:29 UTC
Created attachment 96137 [details]
screenshot showing that the error dialog is not application modal
In earlier versions of ktnef, the error can be reproduced by issuing a quit via the GUI rather than the terminal (as the attached screenshot demonstrates).
The crash is a use-after-free bug. I built a version of ktnef using AddressSanitizer and here is the report generated by AddressSanitizer for this bug:
=================================================================
==23263==ERROR: AddressSanitizer: heap-use-after-free on address 0x60c0000b9900 at pc 0x46e008 bp 0x7fff05913b70 sp 0x7fff05913b68
READ of size 8 at 0x60c0000b9900 thread T0
#0 0x46e007 in KTNEFMain::loadFile(QString const&) (KDE/install-asan/bin/ktnef+0x46e007)
#1 0x46f807 in KTNEFMain::openFile() (KDE/install-asan/bin/ktnef+0x46f807)
#2 0x494412 in KTNEFMain::qt_static_metacall(QObject*, QMetaObject::Call, int, void**) (KDE/install-asan/bin/ktnef+0x494412)
#3 0x7f9f84909606 in QMetaObject::activate(QObject*, QMetaObject const*, int, void**) (install/qt4/lib/libQtCore.so.4+0x255606)
#4 0x7f9f85e3741c in QAction::triggered(bool) (install/qt4/lib/libQtGui.so.4+0x22541c)
#5 0x7f9f85e37231 in QAction::activate(QAction::ActionEvent) (install/qt4/lib/libQtGui.so.4+0x225231)
#6 0x7f9f85e396c9 in QAction::trigger() (install/qt4/lib/libQtGui.so.4+0x2276c9)
#7 0x7f9f86597f92 in QToolButton::nextCheckState() (install/qt4/lib/libQtGui.so.4+0x985f92)
#8 0x7f9f864521c3 in QAbstractButtonPrivate::click() (install/qt4/lib/libQtGui.so.4+0x8401c3)
#9 0x7f9f8645375b in QAbstractButton::mouseReleaseEvent(QMouseEvent*) (install/qt4/lib/libQtGui.so.4+0x84175b)
#10 0x7f9f86597853 in QToolButton::mouseReleaseEvent(QMouseEvent*) (install/qt4/lib/libQtGui.so.4+0x985853)
#11 0x7f9f85ed097d in QWidget::event(QEvent*) (install/qt4/lib/libQtGui.so.4+0x2be97d)
#12 0x7f9f86453580 in QAbstractButton::event(QEvent*) (install/qt4/lib/libQtGui.so.4+0x841580)
#13 0x7f9f86598028 in QToolButton::event(QEvent*) (install/qt4/lib/libQtGui.so.4+0x986028)
#14 0x7f9f85e4748e in QApplicationPrivate::notify_helper(QObject*, QEvent*) (install/qt4/lib/libQtGui.so.4+0x23548e)
#15 0x7f9f85e4a892 in QApplication::notify(QObject*, QEvent*) (install/qt4/lib/libQtGui.so.4+0x238892)
#16 0x7f9f87709340 in KApplication::notify(QObject*, QEvent*) KDE/kde/kdelibs/kdeui/kernel/kapplication.cpp:311
#17 0x7f9f848e1dc5 in QCoreApplication::notifyInternal(QObject*, QEvent*) (install/qt4/lib/libQtCore.so.4+0x22ddc5)
#18 0x7f9f85e5202e in QCoreApplication::sendSpontaneousEvent(QObject*, QEvent*) (install/qt4/lib/libQtGui.so.4+0x24002e)
#19 0x7f9f85e48530 in QApplicationPrivate::sendMouseEvent(QWidget*, QMouseEvent*, QWidget*, QWidget*, QWidget**, QPointer<QWidget>&, bool) (install/qt4/lib/libQtGui.so.4+0x236530)
#20 0x7f9f85f195e4 in QETWidget::translateMouseEvent(_XEvent const*) (install/qt4/lib/libQtGui.so.4+0x3075e4)
#21 0x7f9f85f14ff5 in QApplication::x11ProcessEvent(_XEvent*) (install/qt4/lib/libQtGui.so.4+0x302ff5)
#22 0x7f9f85f5f455 in QEventDispatcherX11::processEvents(QFlags<QEventLoop::ProcessEventsFlag>) (install/qt4/lib/libQtGui.so.4+0x34d455)
#23 0x7f9f848dcf6b in QEventLoop::processEvents(QFlags<QEventLoop::ProcessEventsFlag>) (install/qt4/lib/libQtCore.so.4+0x228f6b)
#24 0x7f9f848dd331 in QEventLoop::exec(QFlags<QEventLoop::ProcessEventsFlag>) (install/qt4/lib/libQtCore.so.4+0x229331)
#25 0x7f9f848e25ed in QCoreApplication::exec() (install/qt4/lib/libQtCore.so.4+0x22e5ed)
#26 0x7f9f85e49525 in QApplication::exec() (install/qt4/lib/libQtGui.so.4+0x237525)
#27 0x483563 in main (KDE/install-asan/bin/ktnef+0x483563)
#28 0x7f9f834d876c (/lib/x86_64-linux-gnu/libc.so.6+0x2176c)
#29 0x454e7c in _start (KDE/install-asan/bin/ktnef+0x454e7c)
0x60c0000b9900 is located 64 bytes inside of 128-byte region [0x60c0000b98c0,0x60c0000b9940)
freed by thread T0 here:
#0 0x44049a in operator delete(void*) (KDE/install-asan/bin/ktnef+0x44049a)
#1 0x46bf34 in KTNEFMain::~KTNEFMain() (KDE/install-asan/bin/ktnef+0x46bf34)
#2 0x7f9f84902e3d in qDeleteInEventHandler(QObject*) (install/qt4/lib/libQtCore.so.4+0x24ee3d)
#3 0x7f9f849029a7 in QObject::event(QEvent*) (install/qt4/lib/libQtCore.so.4+0x24e9a7)
#4 0x7f9f85ed2345 in QWidget::event(QEvent*) (install/qt4/lib/libQtGui.so.4+0x2c0345)
#5 0x7f9f864f3f72 in QMainWindow::event(QEvent*) (install/qt4/lib/libQtGui.so.4+0x8e1f72)
#6 0x7f9f87a29133 in KMainWindow::event(QEvent*) KDE/kde/kdelibs/kdeui/widgets/kmainwindow.cpp:1126
#7 0x7f9f87b2f0b2 in KXmlGuiWindow::event(QEvent*) KDE/kde/kdelibs/kdeui/xmlgui/kxmlguiwindow.cpp:126
#8 0x7f9f85e4748e in QApplicationPrivate::notify_helper(QObject*, QEvent*) (install/qt4/lib/libQtGui.so.4+0x23548e)
#9 0x7f9f85e4d32b in QApplication::notify(QObject*, QEvent*) (install/qt4/lib/libQtGui.so.4+0x23b32b)
#10 0x7f9f87709340 in KApplication::notify(QObject*, QEvent*) KDE/kde/kdelibs/kdeui/kernel/kapplication.cpp:311
#11 0x7f9f848e1dc5 in QCoreApplication::notifyInternal(QObject*, QEvent*) (install/qt4/lib/libQtCore.so.4+0x22ddc5)
#12 0x7f9f848e6549 in QCoreApplication::sendEvent(QObject*, QEvent*) (install/qt4/lib/libQtCore.so.4+0x232549)
#13 0x7f9f848e33f3 in QCoreApplicationPrivate::sendPostedEvents(QObject*, int, QThreadData*) (install/qt4/lib/libQtCore.so.4+0x22f3f3)
#14 0x7f9f849342f6 in QEventDispatcherUNIX::processEvents(QFlags<QEventLoop::ProcessEventsFlag>) (install/qt4/lib/libQtCore.so.4+0x2802f6)
#15 0x7f9f85f5f669 in QEventDispatcherX11::processEvents(QFlags<QEventLoop::ProcessEventsFlag>) (install/qt4/lib/libQtGui.so.4+0x34d669)
#16 0x7f9f848dcf6b in QEventLoop::processEvents(QFlags<QEventLoop::ProcessEventsFlag>) (install/qt4/lib/libQtCore.so.4+0x228f6b)
#17 0x7f9f848dd331 in QEventLoop::exec(QFlags<QEventLoop::ProcessEventsFlag>) (install/qt4/lib/libQtCore.so.4+0x229331)
#18 0x7f9f865fbc8a in QDialog::exec() (install/qt4/lib/libQtGui.so.4+0x9e9c8a)
#19 0x7f9f874959dc in KMessageBox::createKMessageBox(KDialog*, QIcon const&, QString const&, QStringList const&, QString const&, bool*, QFlags<KMessageBox::Option>, QString const&, QMessageBox::Icon) KDE/kde/kdelibs/kdeui/dialogs/kmessagebox.cpp:344
#20 0x7f9f87492fe1 in KMessageBox::createKMessageBox(KDialog*, QMessageBox::Icon, QString const&, QStringList const&, QString const&, bool*, QFlags<KMessageBox::Option>, QString const&) KDE/kde/kdelibs/kdeui/dialogs/kmessagebox.cpp:158
#21 0x7f9f874a3d4a in KMessageBox::errorListWId(unsigned long, QString const&, QStringList const&, QString const&, QFlags<KMessageBox::Option>) KDE/kde/kdelibs/kdeui/dialogs/kmessagebox.cpp:854
#22 0x7f9f874a340b in KMessageBox::error(QWidget*, QString const&, QString const&, QFlags<KMessageBox::Option>) KDE/kde/kdelibs/kdeui/dialogs/kmessagebox.cpp:821
#23 0x46db45 in KTNEFMain::loadFile(QString const&) (KDE/install-asan/bin/ktnef+0x46db45)
#24 0x46f807 in KTNEFMain::openFile() (KDE/install-asan/bin/ktnef+0x46f807)
#25 0x494412 in KTNEFMain::qt_static_metacall(QObject*, QMetaObject::Call, int, void**) (KDE/install-asan/bin/ktnef+0x494412)
#26 0x7f9f84909606 in QMetaObject::activate(QObject*, QMetaObject const*, int, void**) (install/qt4/lib/libQtCore.so.4+0x255606)
#27 0x7f9f85e3741c in QAction::triggered(bool) (install/qt4/lib/libQtGui.so.4+0x22541c)
#28 0x7f9f85e37231 in QAction::activate(QAction::ActionEvent) (install/qt4/lib/libQtGui.so.4+0x225231)
#29 0x7f9f85e396c9 in QAction::trigger() (install/qt4/lib/libQtGui.so.4+0x2276c9)
#30 0x7f9f86597f92 in QToolButton::nextCheckState() (install/qt4/lib/libQtGui.so.4+0x985f92)
#31 0x7f9f864521c3 in QAbstractButtonPrivate::click() (install/qt4/lib/libQtGui.so.4+0x8401c3)
#32 0x7f9f8645375b in QAbstractButton::mouseReleaseEvent(QMouseEvent*) (install/qt4/lib/libQtGui.so.4+0x84175b)
#33 0x7f9f86597853 in QToolButton::mouseReleaseEvent(QMouseEvent*) (install/qt4/lib/libQtGui.so.4+0x985853)
#34 0x7f9f85ed097d in QWidget::event(QEvent*) (install/qt4/lib/libQtGui.so.4+0x2be97d)
#35 0x7f9f86453580 in QAbstractButton::event(QEvent*) (install/qt4/lib/libQtGui.so.4+0x841580)
#36 0x7f9f86598028 in QToolButton::event(QEvent*) (install/qt4/lib/libQtGui.so.4+0x986028)
#37 0x7f9f85e4748e in QApplicationPrivate::notify_helper(QObject*, QEvent*) (install/qt4/lib/libQtGui.so.4+0x23548e)
#38 0x7f9f85e4a892 in QApplication::notify(QObject*, QEvent*) (install/qt4/lib/libQtGui.so.4+0x238892)
#39 0x7f9f87709340 in KApplication::notify(QObject*, QEvent*) KDE/kde/kdelibs/kdeui/kernel/kapplication.cpp:311
#40 0x7f9f848e1dc5 in QCoreApplication::notifyInternal(QObject*, QEvent*) (install/qt4/lib/libQtCore.so.4+0x22ddc5)
#41 0x7f9f85e5202e in QCoreApplication::sendSpontaneousEvent(QObject*, QEvent*) (install/qt4/lib/libQtGui.so.4+0x24002e)
#42 0x7f9f85e48530 in QApplicationPrivate::sendMouseEvent(QWidget*, QMouseEvent*, QWidget*, QWidget*, QWidget**, QPointer<QWidget>&, bool) (install/qt4/lib/libQtGui.so.4+0x236530)
#43 0x7f9f85f195e4 in QETWidget::translateMouseEvent(_XEvent const*) (install/qt4/lib/libQtGui.so.4+0x3075e4)
#44 0x7f9f85f14ff5 in QApplication::x11ProcessEvent(_XEvent*) (install/qt4/lib/libQtGui.so.4+0x302ff5)
#45 0x7f9f85f5f455 in QEventDispatcherX11::processEvents(QFlags<QEventLoop::ProcessEventsFlag>) (install/qt4/lib/libQtGui.so.4+0x34d455)
#46 0x7f9f848dcf6b in QEventLoop::processEvents(QFlags<QEventLoop::ProcessEventsFlag>) (install/qt4/lib/libQtCore.so.4+0x228f6b)
#47 0x7f9f848dd331 in QEventLoop::exec(QFlags<QEventLoop::ProcessEventsFlag>) (install/qt4/lib/libQtCore.so.4+0x229331)
#48 0x7f9f848e25ed in QCoreApplication::exec() (install/qt4/lib/libQtCore.so.4+0x22e5ed)
#49 0x7f9f85e49525 in QApplication::exec() (install/qt4/lib/libQtGui.so.4+0x237525)
#50 0x483563 in main (KDE/install-asan/bin/ktnef+0x483563)
#51 0x7f9f834d876c (/lib/x86_64-linux-gnu/libc.so.6+0x2176c)
#52 0x454e7c in _start (KDE/install-asan/bin/ktnef+0x454e7c)
previously allocated by thread T0 here:
#0 0x44021a in operator new(unsigned long) (KDE/install-asan/bin/ktnef+0x44021a)
#1 0x4833b4 in main (KDE/install-asan/bin/ktnef+0x4833b4)
#2 0x7f9f834d876c (/lib/x86_64-linux-gnu/libc.so.6+0x2176c)
#3 0x454e7c in _start (KDE/install-asan/bin/ktnef+0x454e7c)
SUMMARY: AddressSanitizer: heap-use-after-free ??:0 KTNEFMain::loadFile(QString const&)
Shadow bytes around the buggy address:
0x0c188000f2d0: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd
0x0c188000f2e0: fa fa fa fa fa fa fa fa fd fd fd fd fd fd fd fd
0x0c188000f2f0: fd fd fd fd fd fd fd fd fa fa fa fa fa fa fa fa
0x0c188000f300: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd
0x0c188000f310: fa fa fa fa fa fa fa fa fd fd fd fd fd fd fd fd
=>0x0c188000f320:[fd]fd fd fd fd fd fd fd fa fa fa fa fa fa fa fa
0x0c188000f330: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0x0c188000f340: fa fa fa fa fa fa fa fa 00 00 00 00 00 00 00 00
0x0c188000f350: 00 00 00 00 00 00 00 07 fa fa fa fa fa fa fa fa
0x0c188000f360: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd
0x0c188000f370: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
Shadow byte legend (one shadow byte represents 8 application bytes):
Addressable: 00
Partially addressable: 01 02 03 04 05 06 07
Heap left redzone: fa
Heap right redzone: fb
Freed heap region: fd
Stack left redzone: f1
Stack mid redzone: f2
Stack right redzone: f3
Stack partial redzone: f4
Stack after return: f5
Stack use after scope: f8
Global redzone: f9
Global init order: f6
Poisoned by user: f7
ASan internal: fe
==23263==ABORTING
Why did you open the same bug as 356351 that I fixed ??? Oops, really sorry, forgot I'd already filed this one. *** This bug has been marked as a duplicate of bug 356351 *** |