FreeRad crashing (RHEL 9.4, jut patched
Stefan Paetow
Stefan.Paetow at jisc.ac.uk
Mon Aug 19 16:47:06 UTC 2024
Hi,
FYI - The core dump comes from a Status-Server request not being handled correctly. FR v3.2.6 will fix it (confirmed by Alan D in the Devel list), so I would venture to guess that the FR folks will also roll a next version of 3.0.x for that? If so, switch to that... it tends to take RedHat a while to update (backport) fixes.
:-)
Stefan Paetow
Federated Roaming Technical Specialist
eduroam(UK), Jisc
email/teams: stefan.paetow at jisc.ac.uk
gpg: 0x3FCE5142
jisc.ac.uk
Jisc is a registered charity (number 1149740) and a company limited by guarantee which is registered in England under Company No. 5747339, VAT No. GB 197 0632 86. Jisc’s registered office is: 4 Portwall Lane, Bristol, BS1 6NB Tel: 020 3697 5800.
On 16/08/2024, 11:08, "Freeradius-Users on behalf of James Potter via Freeradius-Users" <freeradius-users-bounces+stefan.paetow=jisc.ac.uk at lists.freeradius.org <mailto:jisc.ac.uk at lists.freeradius.org> on behalf of freeradius-users at lists.freeradius.org <mailto:freeradius-users at lists.freeradius.org>> wrote:
Hi team,
Is anyone else experiencing FreeRad core dumping on RHEL 9.4 with the latest patch?
Tum history info 59 gives:
Packages Altered:
Upgrade freeradius-3.0.21-40.el9_4.x86_64 @rhel-9-for-x86_64-appstream-rpms
Upgraded freeradius-3.0.21-39.el9_3.x86_64 @@System
Upgrade freeradius-ldap-3.0.21-40.el9_4.x86_64 @rhel-9-for-x86_64-appstream-rpms
Upgraded freeradius-ldap-3.0.21-39.el9_3.x86_64 @@System
This appears to be related to status_check = status-server set in proxies (commenting it out seems to cause less/no crashes).
With these lines commented out it runs fine, with these present service dies after ~5+ mins of running (running radiusd -X waiting for it to die again, its taking its time...)
Change from v39 -> v40 appears to be related to BlastRADIUS vulnerability. Is there any issue with the fix for Blast + status_server checks?
Thanks,
Jim Potter
Jisc
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html <http://www.freeradius.org/list/users.html>
More information about the Freeradius-Users
mailing list