Hi, On Sun, Jul 06, 2025 at 12:32:31PM -0300, Carlos Henrique Lima Melara wrote: > > Anyway, I'm having a bad time trying to reproduce the buffer overflow on > a trixie vm, basically doing accton on; lastcomm; dump-acct > /var/log/account/pacct; works just fine. All the reports [1][2][3] > says I should see a core dump either in lastcomm or dump-acct, but thing > just work (tm) and I'm a bit confused hahahahahaha
For completeness sake, we were able to reproduce the issue and confirm the fix. It requires building acct with FORTIFY_SOURCE=3 and that was why I wasn't able to reproduce it in Debian. A quick rebuild got me the core dump and applying the proposed patch fixed it. Cheers, Charles
