Closed juergenthomann closed 7 months ago
I have the same / similar issue on Ubutnu server: VM on HyperV Distributor ID: Ubuntu Description: Ubuntu 22.04.3 LTS Release: 22.04 Codename: jammy Kernel: 5.15.0-88-generic
Sysmon version: v1.3.1
After install it runs for a bit then just stops, no specifc time interval. If a system is under load and I do a fresh install of sysmon it will not start at all.
In my case it does not start again after stopping.
sudo service sysmon status Reason for failing: sysmon.service: Main process exited, code=dumped, status=6/ABRT sysmon.service: Failed with result 'core-dump'.
To get it manually running again sudo service sysmon restart
It fails within a few seconds.
Thanks @ITSecOps-404. Do you see the same " stack smashing detected : terminated" error in the log? I'm wrapping up an issue in ProcDump for Linux right now but as soon as that I done, I will take a look at this.
Thanks @ITSecOps-404. Do you see the same " stack smashing detected : terminated" error in the log? I'm wrapping up an issue in ProcDump for Linux right now but as soon as that I done, I will take a look at this.
Yes, apologies I see the screenshot did not link.
Hi all - While I can't reproduce the issue, I think I have a fix. Would you be willing to try it out using https://github.com/mariohewardt/SysmonForLinux? You would have to build locally to try it.
Describe the bug Sysmon is terminated after some time with "stack smashing detected". It depends on the server but on 2 it gets terminated nearly instantly. On others it runs with luck some days.
To Reproduce Install Sysmon on Debian 11 and use the config below during "sysmon -i"
Sysmon version We tried 1.2, 1.3 and also 1.3.1.
Distro/kernel version Debian 11 with linux-image-5.10.0-25-amd64, but previous versions are also affected.
Sysmon configuration for Testing we currently use the following config. But without any special config it happens as well
Logs
Expected behavior sysmon schould not stop with stack smashing errors
Additional context The coredump points always to the same place. This could be a problem in sysmonCommon, but as the stack problems could be caused from a different code location, I think it the best to start here with the inventigation.