-
Bug
-
-
Major
-
Resolution:
Duplicate
-
10.6.2, 10.5.13, 10.2(EOL), 10.3(EOL), 10.4(EOL), 10.5, 10.6
-
-
-
-
Reported by:
Yaoguang Chen of Ant Security Light-Year Lab
Steps to reproduce:
CREATE TEMPORARY TABLE v0 ( v4 SMALLINT , v3 TINYINT , v2 NCHAR BINARY GENERATED ALWAYS AS ( NULL NOT IN ( 'x' SOUNDS LIKE UTC_TIME ( ) IS NULL IS NULL IS FALSE ) IS NOT FALSE ) , v1 INT ) ;
|
SELECT CONVERT ( CHAR ( 'x' IS FALSE ) * DEFAULT ( v2 ) * 'x' * 62721821.000000 , DATETIME ) REGEXP v1 'x' FROM v0 ;
|
INSERT IGNORE INTO v0 VALUES ( 78470821.000000 , 'x' , -32768 , v1 IN ( 'x' , FALSE NOT REGEXP v3 IS FALSE ) ) ;
|
backtrace:
Core was generated by `/home/supersix/fuzz/security/MariaDB/install_debug/bin/mysqld --defaults-file=/'.
|
Program terminated with signal SIGABRT, Aborted.
|
#0 __pthread_kill (threadid=<optimized out>, signo=signo@entry=0x6)
|
at ../sysdeps/unix/sysv/linux/pthread_kill.c:56
|
56 ../sysdeps/unix/sysv/linux/pthread_kill.c: No such file or directory.
|
[Current thread is 1 (Thread 0x7f8010296700 (LWP 1431325))]
|
gdb-peda$ bt
|
#0 __pthread_kill (threadid=<optimized out>, signo=signo@entry=0x6)
|
at ../sysdeps/unix/sysv/linux/pthread_kill.c:56
|
#1 0x000055ceeec1e94f in my_write_core (sig=sig@entry=0x6)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/mysys/stacktrace.c:424
|
#2 0x000055ceee729d60 in handle_fatal_signal (sig=0x6)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/signal_handler.cc:344
|
#3 <signal handler called>
|
#4 __GI_raise (sig=sig@entry=0x6) at ../sysdeps/unix/sysv/linux/raise.c:50
|
#5 0x00007f8010d68859 in __GI_abort () at abort.c:79
|
#6 0x00007f801113f951 in ?? () from /lib/x86_64-linux-gnu/libstdc++.so.6
|
#7 0x00007f801114b47c in ?? () from /lib/x86_64-linux-gnu/libstdc++.so.6
|
#8 0x00007f801114b4e7 in std::terminate() () from /lib/x86_64-linux-gnu/libstdc++.so.6
|
#9 0x00007f801114c245 in __cxa_pure_virtual () from /lib/x86_64-linux-gnu/libstdc++.so.6
|
#10 0x000055ceee75d6ef in Arg_comparator::compare_real_fixed (this=0x7f7f88115bf0)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/item_cmpfunc.cc:897
|
#11 0x000055ceee76b464 in Arg_comparator::compare (this=0x7f7f88115bf0)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/item_cmpfunc.h:103
|
#12 Item_func_ne::val_int (this=0x7f7f88115b40)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/item_cmpfunc.cc:1788
|
#13 0x000055ceee67b604 in Type_handler_int_result::Item_val_bool (this=<optimized out>,
|
item=<optimized out>) at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/sql_type.cc:5085
|
#14 0x000055ceee75de10 in Item_func_truth::val_bool (this=0x7f7f88115dc0)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/item_cmpfunc.cc:1165
|
#15 0x000055ceee75de81 in Item_func_truth::val_int (this=<optimized out>)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/item_cmpfunc.cc:1188
|
#16 0x000055ceee74f443 in Item::save_int_in_field (this=0x7f7f88115dc0, field=0x7f7f8801ac90,
|
no_conversions=<optimized out>)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/item.cc:6700
|
#17 0x000055ceee7412a7 in Item::save_in_field (this=0x7f7f88115dc0, field=0x7f7f8801ac90,
|
no_conversions=<optimized out>)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/item.cc:6710
|
#18 0x000055ceee5f87a0 in TABLE::update_virtual_fields (this=this@entry=0x7f7f8801a698,
|
h=<optimized out>, update_mode=update_mode@entry=VCOL_UPDATE_FOR_WRITE)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/table.cc:8718
|
#19 0x000055ceee4ba3a5 in fill_record (thd=thd@entry=0x7f7f88000c58,
|
table=table@entry=0x7f7f8801a698, ptr=0x7f7f8801aaf0, ptr@entry=0x7f7f8801aac8, values=...,
|
ignore_errors=ignore_errors@entry=0x0, use_value=use_value@entry=0x0)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/sql_base.cc:8845
|
#20 0x000055ceee4ba444 in fill_record_n_invoke_before_triggers (thd=thd@entry=0x7f7f88000c58,
|
table=table@entry=0x7f7f8801a698, ptr=0x7f7f8801aac8, values=...,
|
ignore_errors=ignore_errors@entry=0x0, event=event@entry=TRG_EVENT_INSERT)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/sql_base.cc:8888
|
#21 0x000055ceee4e6af6 in mysql_insert (thd=thd@entry=0x7f7f88000c58, table_list=<optimized out>,
|
fields=..., values_list=..., update_fields=..., update_values=..., duplic=<optimized out>,
|
ignore=<optimized out>, result=<optimized out>)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/sql_insert.cc:1047
|
#22 0x000055ceee5204e7 in mysql_execute_command (thd=0x7f7f88000c58,
|
is_called_from_prepared_stmt=<optimized out>)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/sql_parse.cc:4568
|
#23 0x000055ceee510287 in mysql_parse (thd=0x7f7f88000c58, rawbuf=<optimized out>,
|
length=<optimized out>, parser_state=<optimized out>)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/sql_parse.cc:8028
|
#24 0x000055ceee51c285 in dispatch_command (command=COM_QUERY, thd=0x7f7f88000c58,
|
packet=<optimized out>, packet_length=<optimized out>, blocking=<optimized out>)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/sql_class.h:1340
|
#25 0x000055ceee51e1a8 in do_command (thd=0x7f7f88000c58, blocking=blocking@entry=0x1)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/sql_parse.cc:1406
|
#26 0x000055ceee624317 in do_handle_one_connection (connect=<optimized out>, put_in_cache=0x1)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/sql_connect.cc:1410
|
#27 0x000055ceee62467d in handle_one_connection (arg=arg@entry=0x55cef0328838)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/sql/sql_connect.cc:1312
|
#28 0x000055ceee96097d in pfs_spawn_thread (arg=0x55cef06008d8)
|
at /home/supersix/fuzz/security/MariaDB/mariadb-10.6.2/storage/perfschema/pfs.cc:2201
|
#29 0x00007f8011291609 in start_thread (arg=<optimized out>) at pthread_create.c:477
|
#30 0x00007f8010e65293 in clone () at ../sysdeps/unix/sysv/linux/x86_64/clone.S:95
|
- duplicates
-
MDEV-26437
Server crashes in Item_args::walk_args
-
-
Closed
- links to
-
Transition |
Time In Source Status |
Execution Times |
Open |
|
Confirmed |
|
13d 7h 18m
|
1
|
Confirmed |
|
Closed |
|
36d 4h 49m
|
1
|
{"report":{"fcp":1077.5,"ttfb":289.6000003814697,"pageVisibility":"visible","entityId":101926,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":0.5,"journeyId":"2ee8e1e7-e3fc-4599-bb2e-5e316e19e019","navigationType":0,"readyForUser":1182.2000002861023,"redirectCount":0,"resourceLoadedEnd":781.2000002861023,"resourceLoadedStart":300.5,"resourceTiming":[{"duration":22.40000009536743,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":300.5,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":300.5,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":322.90000009536743,"responseStart":0,"secureConnectionStart":0},{"duration":22.90000009536743,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true&whisper-enabled=true","startTime":300.7000002861023,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":300.7000002861023,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":323.6000003814697,"responseStart":0,"secureConnectionStart":0},{"duration":259.90000009536743,"initiatorType":"script","name":"https://jira.mariadb.org/s/0917945aaa57108d00c5076fea35e069-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":301,"connectEnd":301,"connectStart":301,"domainLookupEnd":301,"domainLookupStart":301,"fetchStart":301,"redirectEnd":0,"redirectStart":0,"requestStart":327.90000009536743,"responseEnd":560.9000000953674,"responseStart":350.2000002861023,"secureConnectionStart":301},{"duration":476.59999990463257,"initiatorType":"script","name":"https://jira.mariadb.org/s/2d8175ec2fa4c816e8023260bd8c1786-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true&whisper-enabled=true","startTime":301.2000002861023,"connectEnd":301.2000002861023,"connectStart":301.2000002861023,"domainLookupEnd":301.2000002861023,"domainLookupStart":301.2000002861023,"fetchStart":301.2000002861023,"redirectEnd":0,"redirectStart":0,"requestStart":327.5,"responseEnd":777.8000001907349,"responseStart":369,"secureConnectionStart":301.2000002861023},{"duration":53.19999980926514,"initiatorType":"script","name":"https://jira.mariadb.org/s/a9324d6758d385eb45c462685ad88f1d-CDN/lu2cib/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":301.30000019073486,"connectEnd":301.30000019073486,"connectStart":301.30000019073486,"domainLookupEnd":301.30000019073486,"domainLookupStart":301.30000019073486,"fetchStart":301.30000019073486,"redirectEnd":0,"redirectStart":0,"requestStart":329.6000003814697,"responseEnd":354.5,"responseStart":351.40000009536743,"secureConnectionStart":301.30000019073486},{"duration":62.40000009536743,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":301.5,"connectEnd":301.5,"connectStart":301.5,"domainLookupEnd":301.5,"domainLookupStart":301.5,"fetchStart":301.5,"redirectEnd":0,"redirectStart":0,"requestStart":332.1000003814697,"responseEnd":363.90000009536743,"responseStart":354.7000002861023,"secureConnectionStart":301.5},{"duration":64.90000009536743,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":301.7000002861023,"connectEnd":301.7000002861023,"connectStart":301.7000002861023,"domainLookupEnd":301.7000002861023,"domainLookupStart":301.7000002861023,"fetchStart":301.7000002861023,"redirectEnd":0,"redirectStart":0,"requestStart":332.30000019073486,"responseEnd":366.6000003814697,"responseStart":355.6000003814697,"secureConnectionStart":301.7000002861023},{"duration":25.59999990463257,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2cib/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":301.90000009536743,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":301.90000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":327.5,"responseStart":0,"secureConnectionStart":0},{"duration":71.2999997138977,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":302.1000003814697,"connectEnd":302.1000003814697,"connectStart":302.1000003814697,"domainLookupEnd":302.1000003814697,"domainLookupStart":302.1000003814697,"fetchStart":302.1000003814697,"redirectEnd":0,"redirectStart":0,"requestStart":333.40000009536743,"responseEnd":373.40000009536743,"responseStart":364,"secureConnectionStart":302.1000003814697},{"duration":28.799999713897705,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":302.2000002861023,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":302.2000002861023,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":331,"responseStart":0,"secureConnectionStart":0},{"duration":71.5,"initiatorType":"script","name":"https://jira.mariadb.org/s/5d5e8fe91fbc506585e83ea3b62ccc4b-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":302.40000009536743,"connectEnd":302.40000009536743,"connectStart":302.40000009536743,"domainLookupEnd":302.40000009536743,"domainLookupStart":302.40000009536743,"fetchStart":302.40000009536743,"redirectEnd":0,"redirectStart":0,"requestStart":334.90000009536743,"responseEnd":373.90000009536743,"responseStart":364.7000002861023,"secureConnectionStart":302.40000009536743},{"duration":470.59999990463257,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":308.2000002861023,"connectEnd":308.2000002861023,"connectStart":308.2000002861023,"domainLookupEnd":308.2000002861023,"domainLookupStart":308.2000002861023,"fetchStart":308.2000002861023,"redirectEnd":0,"redirectStart":0,"requestStart":376.40000009536743,"responseEnd":778.8000001907349,"responseStart":771.4000000953674,"secureConnectionStart":308.2000002861023},{"duration":472.90000009536743,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":308.30000019073486,"connectEnd":308.30000019073486,"connectStart":308.30000019073486,"domainLookupEnd":308.30000019073486,"domainLookupStart":308.30000019073486,"fetchStart":308.30000019073486,"redirectEnd":0,"redirectStart":0,"requestStart":398.30000019073486,"responseEnd":781.2000002861023,"responseStart":774.6000003814697,"secureConnectionStart":308.30000019073486},{"duration":118.40000009536743,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":722,"connectEnd":722,"connectStart":722,"domainLookupEnd":722,"domainLookupStart":722,"fetchStart":722,"redirectEnd":0,"redirectStart":0,"requestStart":807,"responseEnd":840.4000000953674,"responseStart":839.5,"secureConnectionStart":722},{"duration":131.19999980926514,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":1013.2000002861023,"connectEnd":1013.2000002861023,"connectStart":1013.2000002861023,"domainLookupEnd":1013.2000002861023,"domainLookupStart":1013.2000002861023,"fetchStart":1013.2000002861023,"redirectEnd":0,"redirectStart":0,"requestStart":1114.2000002861023,"responseEnd":1144.4000000953674,"responseStart":1143.6000003814697,"secureConnectionStart":1013.2000002861023},{"duration":229.39999961853027,"initiatorType":"script","name":"https://www.google-analytics.com/analytics.js","startTime":1067.6000003814697,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":1067.6000003814697,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1297,"responseStart":0,"secureConnectionStart":0}],"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":106,"responseStart":289,"responseEnd":302,"domLoading":298,"domInteractive":1303,"domContentLoadedEventStart":1303,"domContentLoadedEventEnd":1372,"domComplete":1527,"loadEventStart":1527,"loadEventEnd":1528,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":1280.8000001907349},{"name":"bigPipe.sidebar-id.end","time":1281.7000002861023},{"name":"bigPipe.activity-panel-pipe-id.start","time":1281.8000001907349},{"name":"bigPipe.activity-panel-pipe-id.end","time":1282.8000001907349},{"name":"activityTabFullyLoaded","time":1387.8000001907349}],"measures":[],"correlationId":"1e3b9bd67742f9","effectiveType":"4g","downlink":10,"rtt":0,"serverDuration":95,"dbReadsTimeInMs":17,"dbConnsTimeInMs":25,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}