Guest

Preview Tool

Cisco Bug: CSCur70169 - Fatal Signal 11: Segmentation fault PC: [f7e64dd4/X]

Last Modified

Dec 26, 2016

Products (1)

  • Cisco ASR 5000 Series

Known Affected Releases

15.0(19)

Description (partial)

Symptom:
Crash

Conditions:
Fatal Signal 11: Segmentation fault
  PC: [f7e64dd4/X] libc.so.6/chunk_free()
  Faulty address: 0x4845415c
  Signal from: kernel
  Signal detail: address not mapped to object
  Process: card=12 cpu=0 arch=X pid=6699 cpu=~3% argv0=sessmgr
  Crash time: 2014-Sep-10+23:39:53 UTC
  Recent errno: 11 Resource temporarily unavailable
  Stack (64408@0xfffee000):
    [f7e64dd4/X] libc.so.6/chunk_free() sp=0xfffee598
    [f7e64c7e/X] libc.so.6/free() sp=0xfffee5b8
    [0ab408a9/X] free_acct() sp=0xfffee5f8
    [f7e64c0e/X] libc.so.6/free() sp=0xfffee628
    [08e11a13/X] sn_acct_api_free_gtpp_container_list() sp=0xfffee658
    [08e139d8/X] sn_aaa_acct_api_send_msg() sp=0xfffee6e8
    [08e10740/X] sn_aaa_acct_api_handle_active() sp=0xfffee728
    [08e105cc/X] sn_acct_api_handle_acct() sp=0xfffee768
    [0626ce76/X] sessmgr_acct_api_open() sp=0xfffeebe8
    [06262490/X] sessmgr_aaa_sgsn_scdr_sess_acct_start() sp=0xfffeee88
    [041456fa/X] sessmgr_gprs_process_sub_session_connected() sp=0xfffef2d8
    [0416b01b/X] sessmgr_gprs_callline_state_connected() sp=0xfffef3b8
    [0416d9de/X] sessmgr_gprs_callline_fsm() sp=0xfffef3e8
    [04232aa3/X] sessmgr_gprs_send_sub_sess_connect_event() sp=0xfffef548
    [042189a8/X] sessmgr_gprs_fsm_substate_cpc_res_pend() sp=0xfffef638
    [041ea3dd/X] sessmgr_gprs_substate_fsm() sp=0xfffef668
    [042180d8/X] sessmgr_gprs_fsm_substate_cpc_res_pend() sp=0xfffef758
    [041ea3dd/X] sessmgr_gprs_substate_fsm() sp=0xfffef788
    [041c425b/X] sessmgr_gprs_fsm_state_ready() sp=0xfffef978
    [041d70c7/X] sessmgr_gprs_fsm() sp=0xffff00c8
    [0416aef8/X] sessmgr_gprs_callline_state_connected() sp=0xffff01a8
    [0416d9de/X] sessmgr_gprs_callline_fsm() sp=0xffff01d8
    [066a2f7c/X] sm_gprs_handle_cpc_resp_success() sp=0xffff0248
    [0671a846/X] sessmgr_gprs_gtp_callback() sp=0xffff0688
  Registers:
          gs       fs       es       ds
    00000000 00000000 0000002b 0000002b
         edi      esi      ebp      esp
    00002fd8 00002f58 fffee598 fffee570
         ebx      edx      ecx      eax
    f7f05958 48454150 00002f78 17985630
        trap      err      eip       cs
    0000000e 00000006 f7e64dd4 00000023
         efl     uesp       ss
    00010217 fffee570 0000002b
  Recent inbound med header (28@0xeb2a3048):
       0: 106000000b01c025 0b000000013b6641 .`.....% .....;fA
      16: 0000000000000000 00000094         ........ ....    
  Recent inbound med packet (138@0xeb2a3064):
       0: 00006e1d00ce0126 0a14002016820fa0 ..n....& ... ....
      16: 138e1553032ab000 44c79608b8f8c100 ...S.*.. D.......
      32: 1781040a8204030d 8829031005104476 ........ .)....Dv
      48: 310081000ec241c0 0d8a42030b136212 1.....A. ..B...b.
      64: 73966e6e7406ffff 042b0601210a091b s.nnt... .+..!...
      80: 60271f8080210a03 01000a81060a017d `'...!.. .......}
      96: 0680210a0401000a 8306000000000005 ..!..... ........
     112: 010134010061ab8f 966e6e7406ffffb8 ..4..a.. .nnt....
     128: 000100fb00040a5e 4d35             .......^ M5      
  Address Map:
    boxer                    0x00048000    0x10b57f34
    libstdc++.so.5           0xf7f2d000    0xf7fc82d0
    libm.so.6                0xf7f0c000    0xf7f2b4b3
    libc.so.6                0xf7e09000    0xf7f02be8
    ld-linux.so.2            0xf7fec000    0xf7ffd000
    libgcc_s.so.1            0xf7e01000    0xf7e07844
  Recent heap activity (oldest first):
   Ops    Ptr           Size       Caller
    F      18ba3be0      212       gmm_update_peer()   
    M      19820f20    16420       xtcp_conn_read()    
    F      19820f20    16420       sn_msg_handle_issue_response()
    M      19820f20    16420       xtcp_conn_read()    
    F      19820f20    16420       sn_msg_handle_issue_response()
    M      19820f20    16420       xtcp_conn_read()    
    F      19820f20    16420       sn_msg_handle_issue_response()
    M      19376d18      212       sessmgr_gprs_gmm_psf_peer_create_new_mscb()
    F      19376d18      212       gmm_update_peer()   
    M      17578268       52       sn_msg_call_nonblocking_vector_internal()
    M      1772ecb8      652       sgsn_db_send_data() 
    F      1772ecb8      652       sgsn_db_send_data() 
    F      181d3da0       52       dns_dealloc_rdata() 
    F      181d8270       28       dns_cache_hash_remove()
    M      184ea8f8       60       dns_util_query_by_ns()
    M      1842b080       52       libc.so.6/strdup()  
    M      181d0b98      580       libc.so.6/xdr_array()
    M      1929eee8      804       libc.so.6/xdr_array()
    M      18111d48      804       libc.so.6/xdr_array()
    M      185db8d0       52       libc.so.6/strdup()  
    M      17e60068       28       dns_cache_hash_insert()
    F      183feb50       28       dns_cache_hash_remove()
    M      181d8270       28       dns_cache_hash_insert()
    F      184ea8f8       60       vpnapi_query_cbk()  
    F      1842b080       52       dns_pq_dequeue()    
    F      1929eee8      804       libc.so.6/xdr_array()
    F      18111d48      804       libc.so.6/xdr_array()
    F      181d0b98      580       libc.so.6/xdr_array()
    F      17578268       52       sn_deliver_nonblocking_vector()
    M      179855d8       92       sn_acct_api_close_gtpp_container()
  Recent events (oldest first):
    [07b757e0/X] skTskHdlr()
    [07b75e30/X] skTmrHdlr()
    [06f4ac00/X] smgr_db_backup_bounce_handler_towards_aaamgr()
    [08948e00/X] vpnapi_query_cbk()
    [04132ee0/X] sessmgr_updt_gb_flc_data()
    [09226af0/X] sn_flowaggr_clnt_flow_list_add_del_mod_callback()
    [07b757e0/X] skTskHdlr()
    [07b75e30/X] skTmrHdlr()
    [0aafd890/X] xtcp_wagg_tick()
    [08e31170/X] sn_aaa_api_fast_service()
    [04132ee0/X] sessmgr_updt_gb_flc_data()
    [04132ee0/X] sessmgr_updt_gb_flc_data()
    [07b757e0/X] skTskHdlr()
    [07b75e30/X] skTmrHdlr()
    [07b757e0/X] skTskHdlr()
    [07b75e30/X] skTmrHdlr()
  Profile depth=1:
     12.2%        125  libc.so.6/poll()
      4.6%         47  libc.so.6/writev()
      4.2%         43  libc.so.6/memset()
      3.1%         32  xdrmsg_putint32()
      3.0%         31  glFcsCalc()
      2.8%         29  cmHashListFind()
      2.5%         26  libc.so.6/memcpy()
      2.1%         22  cmPrcTmr()
      2.1%         21  libc.so.6/recvfrom()
      2.0%         20  sn_loop_run()
  Profile depth=4:
      3.1%         32  libc.so.6/writev()
                       [0aaec1b5/X] xtcp_conn_write()
                       [0aafe8db/X] sn_msg_xtcp_send_request()
                       [0aabb424/X] sn_msg_call_internal()
      2.3%         24  glFcsCalc()
                       [0c335623/X] glFcsGen()
                       [0c3257c1/X] glBuildUIFrame()
                       [0c327516/X] glSgsnBuildFrame()
      2.1%         21  libc.so.6/recvfrom()
                       [05da131b/X] sessmgr_med_data_receive()
                       [0ab168b7/X] sn_loop_run()
                       [0a9000d4/X] main()
      2.1%         21  xdrmsg_putint32()
                       [+00d582d/X] libc.so.6/xdr_int()
                       [+00d5ba4/X] libc.so.6/xdr_char()
                       [+00d63a3/X] libc.so.6/xdr_vector()
      1.9%         19  libc.so.6/readv()
                       [0aaf4048/X] xtcp_conn_read()
                       [0aafb040/X] xtcp_conn_event()
                       [0ab17beb/X] sn_loop_run()
      1.6%         16  libc.so.6/memset()
                       [0c57c249/X] raFlushErrInfo()
                       [0c576f38/X] raChkRangeProtIEId()
                       [0c2be02f/X] cmPAsnDecElm()
      1.5%         15  libc.so.6/send()
                       [05dacba1/X] sessmgr_med_data_receive()
                       [0ab168b7/X] sn_loop_run()
                       [0a9000d4/X] main()
      1.5%         15  cmPrcTmr()
                       [0c2cf579/X] ggActvTmr()
                       [07b75dc9/X] skTskHdlr()
                       [0ab16426/X] sn_loop_run()
      1.5%         15  libc.so.6/writev()
                       [0aaec1b5/X] xtcp_conn_write()
                       [0ab01cd0/X] sn_msg_xtcp_send_reply()
                       [0aad419b/X] sn_msg_handle_issue_response()
      0.7%          7  xtcp_conn_read()
                       [0aafb040/X] xtcp_conn_event()
                       [0ab17beb/X] sn_loop_run()
                       [0a9000d4/X] main()
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.