-
Bug
-
-
Blocker
-
Resolution:
Fixed
-
10.2(EOL), 10.3(EOL), 10.4(EOL), 10.5, 10.6
-
-
-
-
Linux 5.4.0-39-generic #43-Ubuntu SMP Fri Jun 19 10:28:31 UTC 2020 x86_64 x86_64 x86_64 GNU/Linux
Steps to reproduce:
CREATE TEMPORARY TABLE v0 ( v2 TIMESTAMP CHECK ( DEFAULT ( v2 ) IS NOT TRUE ) , v1 TIMESTAMP ) AS SELECT DISTINCT 'x' AS v3 WINDOW CHECKSUM AS ( ) ;
|
Reported by:
Yaoguang Chen of Ant Security Light-Year Lab
Backtrace:
Core was generated by `/home/supersix/fuzz/security/MariaDB/install/bin/mysqld --defaults-file=/home/s'.
Program terminated with signal SIGSEGV, Segmentation fault.
#0 __pthread_kill (threadid=<optimized out>, signo=signo@entry=0xb)
|
at ../sysdeps/unix/sysv/linux/pthread_kill.c:56
|
[Current thread is 1 (Thread 0x7f154c17f300 (LWP 1992265))]
|
gdb-peda$ #0 __pthread_kill (threadid=<optimized out>, signo=signo@entry=0xb)
|
at ../sysdeps/unix/sysv/linux/pthread_kill.c:56
|
#1 0x00005640d742e98f in my_write_core (sig=sig@entry=0xb)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/mysys/stacktrace.c:424
|
#2 0x00005640d5e9b583 in handle_fatal_signal (sig=<optimized out>)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/signal_handler.cc:344
|
#3 <signal handler called>
|
#4 0x00005640d5dfe617 in Field::set_default (this=0x61d0000b9ab8)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/field.cc:2591
|
#5 0x00005640d5f553a6 in Item_default_value::calculate (this=0x6190000f5240)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/item.cc:9468
|
#6 0x00005640d5f55466 in Item_default_value::val_real (this=0x6190000f5240)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/item.cc:9486
|
#7 0x00005640d5bbf3bb in Type_handler_real_result::Item_val_bool (
|
this=<optimized out>, item=<optimized out>)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/sql_type.cc:5080
|
#8 0x00005640d5fa186c in Item_func_truth::val_bool (this=0x6190000f5370)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/item_cmpfunc.cc:1165
|
#9 Item_func_truth::val_int (this=0x6190000f5370)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/item_cmpfunc.cc:1188
|
#10 0x00005640d5966058 in TABLE::verify_constraints (this=0x6190000f4698,
|
ignore_failure=<optimized out>)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/table.cc:6155
|
#11 0x00005640d5966bbd in TABLE_LIST::view_check_option (this=0x62b000085498,
|
thd=<optimized out>, ignore_failure=<optimized out>)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/table.cc:6128
|
#12 0x00005640d5476284 in select_insert::send_data (this=0x62b0000871f0,
|
values=...)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/sql_insert.cc:4061
|
#13 0x00005640d576aafa in select_result_sink::send_data_with_check (
|
u=0x62b0000823d0, sent=0x0, items=..., this=0x62b0000871f0)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/sql_class.h:5609
|
#14 select_result_sink::send_data_with_check (sent=0x0, u=0x62b0000823d0,
|
items=..., this=0x62b0000871f0)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/sql_class.h:5599
|
#15 JOIN::exec_inner (this=0x62b000087340)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/sql_select.cc:4592
|
#16 0x00005640d576bd20 in JOIN::exec (this=0x62b000087340)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/sql_select.cc:4504
|
#17 0x00005640d5762338 in mysql_select (thd=0x62b00007e218,
|
tables=<optimized out>, fields=..., conds=<optimized out>, og_num=0x0,
|
order=<optimized out>, group=0x0, having=0x0, proc_param=0x0,
|
select_options=0x20080040b01, result=0x62b0000871f0, unit=0x62b0000823d0,
|
select_lex=0x62b000086138)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/sql_select.cc:4982
|
#18 0x00005640d5764425 in handle_select (thd=thd@entry=0x62b00007e218,
|
lex=lex@entry=0x62b000082308, result=result@entry=0x62b0000871f0,
|
setup_tables_done_option=setup_tables_done_option@entry=0x0)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/sql_select.cc:544
|
#19 0x00005640d588eb96 in Sql_cmd_create_table_like::execute (
|
this=<optimized out>, thd=0x62b00007e218)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/sql_table.cc:11746
|
#20 0x00005640d5591a67 in mysql_execute_command (thd=<optimized out>,
|
is_called_from_prepared_stmt=<optimized out>)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/sql_parse.cc:5995
|
#21 0x00005640d55508dd in mysql_parse (thd=0x62b00007e218,
|
rawbuf=<optimized out>, length=<optimized out>,
|
parser_state=<optimized out>)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/sql_parse.cc:8028
|
#22 0x00005640d55862a4 in dispatch_command (command=COM_QUERY,
|
thd=0x62b00007e218, packet=<optimized out>, packet_length=<optimized out>,
|
blocking=<optimized out>)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/sql_class.h:233
|
#23 0x00005640d558b704 in do_command (thd=0x62b00007e218,
|
blocking=blocking@entry=0x1)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/sql_parse.cc:1406
|
#24 0x00005640d5a4b14d in do_handle_one_connection (connect=<optimized out>,
|
put_in_cache=<optimized out>)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/sql_connect.cc:1410
|
#25 0x00005640d5a4c807 in handle_one_connection (arg=arg@entry=0x608005322038)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/sql_connect.cc:1312
|
#26 0x00005640d6897ef0 in pfs_spawn_thread (arg=0x617000005118)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/storage/perfschema/pfs.cc:2201
|
#27 0x00007f155f9fb609 in start_thread (arg=<optimized out>)
|
at pthread_create.c:477
|
#28 0x00007f155f5cf293 in clone ()
|
at ../sysdeps/unix/sysv/linux/x86_64/clone.S:95
|
gdb-peda$ quit
|
{"report":{"fcp":1372.5,"ttfb":270.5,"pageVisibility":"visible","entityId":100946,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":32,"apdex":0.5,"journeyId":"703e6bfe-c576-446d-98ae-758978053d08","navigationType":0,"readyForUser":1512.6999998092651,"redirectCount":0,"resourceLoadedEnd":961.5,"resourceLoadedStart":275.40000009536743,"resourceTiming":[{"duration":397.59999990463257,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":275.40000009536743,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":275.40000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":673,"responseStart":0,"secureConnectionStart":0},{"duration":397.59999990463257,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true&whisper-enabled=true","startTime":275.69999980926514,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":275.69999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":673.2999997138977,"responseStart":0,"secureConnectionStart":0},{"duration":404.09999990463257,"initiatorType":"script","name":"https://jira.mariadb.org/s/0917945aaa57108d00c5076fea35e069-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":275.90000009536743,"connectEnd":275.90000009536743,"connectStart":275.90000009536743,"domainLookupEnd":275.90000009536743,"domainLookupStart":275.90000009536743,"fetchStart":275.90000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":275.90000009536743,"responseEnd":680,"responseStart":680,"secureConnectionStart":275.90000009536743},{"duration":461.90000009536743,"initiatorType":"script","name":"https://jira.mariadb.org/s/2d8175ec2fa4c816e8023260bd8c1786-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true&whisper-enabled=true","startTime":276,"connectEnd":276,"connectStart":276,"domainLookupEnd":276,"domainLookupStart":276,"fetchStart":276,"redirectEnd":0,"redirectStart":0,"requestStart":276,"responseEnd":737.9000000953674,"responseStart":737.9000000953674,"secureConnectionStart":276},{"duration":466.7000002861023,"initiatorType":"script","name":"https://jira.mariadb.org/s/a9324d6758d385eb45c462685ad88f1d-CDN/lu2cib/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":276.19999980926514,"connectEnd":276.19999980926514,"connectStart":276.19999980926514,"domainLookupEnd":276.19999980926514,"domainLookupStart":276.19999980926514,"fetchStart":276.19999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":276.19999980926514,"responseEnd":742.9000000953674,"responseStart":742.9000000953674,"secureConnectionStart":276.19999980926514},{"duration":469.69999980926514,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":276.40000009536743,"connectEnd":276.40000009536743,"connectStart":276.40000009536743,"domainLookupEnd":276.40000009536743,"domainLookupStart":276.40000009536743,"fetchStart":276.40000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":276.40000009536743,"responseEnd":746.0999999046326,"responseStart":746.0999999046326,"secureConnectionStart":276.40000009536743},{"duration":470.19999980926514,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":276.59999990463257,"connectEnd":276.59999990463257,"connectStart":276.59999990463257,"domainLookupEnd":276.59999990463257,"domainLookupStart":276.59999990463257,"fetchStart":276.59999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":276.59999990463257,"responseEnd":746.7999997138977,"responseStart":746.7999997138977,"secureConnectionStart":276.59999990463257},{"duration":586.5,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2cib/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":276.69999980926514,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":276.69999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":863.1999998092651,"responseStart":0,"secureConnectionStart":0},{"duration":470.69999980926514,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":276.90000009536743,"connectEnd":276.90000009536743,"connectStart":276.90000009536743,"domainLookupEnd":276.90000009536743,"domainLookupStart":276.90000009536743,"fetchStart":276.90000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":276.90000009536743,"responseEnd":747.5999999046326,"responseStart":747.5999999046326,"secureConnectionStart":276.90000009536743},{"duration":586.5999999046326,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":277,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":277,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":863.5999999046326,"responseStart":0,"secureConnectionStart":0},{"duration":479.30000019073486,"initiatorType":"script","name":"https://jira.mariadb.org/s/5d5e8fe91fbc506585e83ea3b62ccc4b-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":277.19999980926514,"connectEnd":277.19999980926514,"connectStart":277.19999980926514,"domainLookupEnd":277.19999980926514,"domainLookupStart":277.19999980926514,"fetchStart":277.19999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":277.19999980926514,"responseEnd":756.5,"responseStart":756.5,"secureConnectionStart":277.19999980926514},{"duration":608.7999997138977,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":285.5,"connectEnd":285.5,"connectStart":285.5,"domainLookupEnd":285.5,"domainLookupStart":285.5,"fetchStart":285.5,"redirectEnd":0,"redirectStart":0,"requestStart":285.5,"responseEnd":894.2999997138977,"responseStart":894.2999997138977,"secureConnectionStart":285.5},{"duration":676,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":285.5,"connectEnd":285.5,"connectStart":285.5,"domainLookupEnd":285.5,"domainLookupStart":285.5,"fetchStart":285.5,"redirectEnd":0,"redirectStart":0,"requestStart":285.5,"responseEnd":961.5,"responseStart":961.5,"secureConnectionStart":285.5},{"duration":104.30000019073486,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":921.0999999046326,"connectEnd":921.0999999046326,"connectStart":921.0999999046326,"domainLookupEnd":921.0999999046326,"domainLookupStart":921.0999999046326,"fetchStart":921.0999999046326,"redirectEnd":0,"redirectStart":0,"requestStart":921.0999999046326,"responseEnd":1025.4000000953674,"responseStart":1025.4000000953674,"secureConnectionStart":921.0999999046326}],"fetchStart":1,"domainLookupStart":1,"domainLookupEnd":1,"connectStart":1,"connectEnd":1,"requestStart":81,"responseStart":271,"responseEnd":281,"domLoading":274,"domInteractive":1567,"domContentLoadedEventStart":1567,"domContentLoadedEventEnd":1617,"domComplete":1977,"loadEventStart":1977,"loadEventEnd":1978,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":1539.0999999046326},{"name":"bigPipe.sidebar-id.end","time":1540},{"name":"bigPipe.activity-panel-pipe-id.start","time":1540.0999999046326},{"name":"bigPipe.activity-panel-pipe-id.end","time":1541.1999998092651},{"name":"activityTabFullyLoaded","time":1632.7999997138977}],"measures":[],"correlationId":"217ab82d5f6ee6","effectiveType":"4g","downlink":10,"rtt":0,"serverDuration":117,"dbReadsTimeInMs":32,"dbConnsTimeInMs":42,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}