Bug#1142578: Segmentation fault when connecting to Loongson board in UEFI firmware setting

Kexy Biscuit kexybiscuit at aosc.io
Wed Jul 22 09:45:32 BST 2026


Package: minicom
Version: 2.11.1-2
X-Debbugs-CC: minicom-devel at alioth-lists.debian.net
When connecting to the serial console of Loongson XA612A0
(firmware version V1.0_V5.0.0532_stable202605_dbg) and entering UEFI
firmware setting, at the moment of entering, segmentation fault
happens, with the following backtrace.
#0  _write (c=9472 L'─', doit=<optimizedout>, x=<optimizedout>, 
y=<optimizedout>, attr=<optimizedout>, color=<optimizedout>) at 
/var/cache/acbs/build/acbs.6le_6fsq/minicom/src/window.c:383
         e = 0xfff7f67ff8
         cwidth = <optimizedout>
         x0 = -3
         y0 = 0
         attr0 = 2 '\002'
         color0 = 116 't'
         c0 = 9472
#1  0x000000aaaaab6bdc in mc_wputc (win=0xaaaab11610, c=<optimizedout>) 
at /var/cache/acbs/build/acbs.6le_6fsq/minicom/src/window.c:1022
         cwidth = <optimizedout>
         mv = <optimizedout>
#2  0x000000aaaaacc834 in vt_out (ch=<optimizedout>, wc=<optimizedout>) 
at /var/cache/acbs/build/acbs.6le_6fsq/minicom/src/vt100.c:1096
         f = <optimizedout>
         c = 226 '\342'
         go_on = <optimizedout>
         last_ch = 226 '\342'
         tmstmp_last = {tv_sec = 0, tv_usec = 0}
#3  0x000000aaaaaabf50 in do_terminal () at 
/var/cache/acbs/build/acbs.6le_6fsq/minicom/src/main.c:992
         wc = 9472 L'─'
         len = 3
         c = <optimizedout>
         obuf = 
"\001\000\000\000\000\000\000\000\262\034\002\020\000\000\000\000\000\003\034\177\025\001\005\000\000\021\023\032\000\022\017\027\026\004", 
'\000' <repeats19times>, "\302\001\000\000\302\001", '\000' 
<repeats29times>, "af`j", '\000' <repeats 12 times>, "cf`j", '\000' 
<repeats12times>, "L9Pj\000\000\000"
         ptr = 0xfffffe6949 "─", <incompletesequence\342>
         buf = "\214──\342\000geCommo\000723B EF\00000000\r\n\000 Data 
H\000\000\000\000\000\000\000\000\330X\371\367\377", '\000' 
<repeats11times>, "\230X\371\367\377\000\000\000\250X\371\367\377", 
'\000' <repeats27times>, 
"\270X\371\367\377\000\000\000\310X\371\367\377\000\000\000\000\000\000\000\000\000\000"
         buf_offset = <optimizedout>
         c = <optimizedout>
         x = 1
         blen = 7
         zauto = 68
         zpos = 0
         s = <optimizedout>
         error_on_open_window = <optimizedout>
         dirty_goto = <optimizedout>
         zsig = <optimizedout>
#4  main (argc=<optimizedout>, argv=<optimizedout>) at 
/var/cache/acbs/build/acbs.6le_6fsq/minicom/src/minicom.c:1748
         c = <optimizedout>
         quit = 0
         s = <optimizedout>
         bufp = <optimizedout>
         doinit = <optimizedout>
         capname = 
"minicom.cap\000\000\000\000\000\230>\376\367\377\000\000\000xx\373\367\377\000\000\000\177", 
'\000' <repeats16times>, "@\371\367\377\000\000\000\250o\376\377\377", 
'\000' <repeats19times>, 
"0\300\376\367\377\000\000\000\220h\376\377\377\000\000\000 at Q\373\367\377\000\000\000@\000\252\252\252\000\000\000\f\000\000\000\000\000\000\000`䪪\252\000\000"
         pwd = <optimizedout>
         use_port = <optimizedout>
         args = {0xaaaaad7a88 "minicom", 0xfffffe7345 "-D", 0xfffffe7348 
"/dev/ttyS0", 0x0, 0xfffffe7040 "\003", 0x7e 
<error:Cannotaccessmemoryataddress0x7e>, 0xfff7fec030 
<error:Cannotaccessmemoryataddress0xfff7fec030>, 0xfffffe68f0 
"\030V\376\367\377",
           0xfff7fb6584 <_dl_start_final+396> "\b", 0xfff7fe5618 
<_dl_rtld_map> "", 0xfff7fe3e98 <_rtld_global_ro> "", 0xfff1 
<error:Cannotaccessmemoryataddress0xfff1>, 0xfff7fec030 
<error:Cannotaccessmemoryataddress0xfff7fec030>, 0xfffffe6920 "",
           0xfff7fb6d08 <_dl_start+536> "%\350\300\003\b\a\277", 
<incompletesequence\337>, 0xfff7f94000 "\177ELF\002\001\001", 0x0, 
0xfff7f95888 "\016", 0x0, 0x0}
         args_buffer = <optimizedout>
         argk = <optimizedout>
         mc = <optimizedout>
         env_args = <optimizedout>
         cmd_dial = <optimizedout>
         alt_code = <optimizedout>
         cmdline_baudrate = <optimizedout>
         cmdline_device = <optimizedout>
         remote_charset = <optimizedout>
         pseudo = '\000' <repeats40times>, 
"\230>\376\367\377\000\000\000\210>\376\367\377\000\000\000\210H\376\367\377\000\000"
         ss = {__val = {8192, 0, 0, 1099377300752, 1099377302752, 0, 
1099377251776, 0, 0, 1099377164288, 1099376986344, 1099377069184, 0, 0, 
0, 1099377294960}}
         dirty_goto = <optimizedout>
__PRETTY_FUNCTION__= "main"
         long_options = {{name = 0xaaaaad93a0 "setup", has_arg = 0, flag 
= 0x0, val = 115}, {name = 0xaaaaad93a8 "help", has_arg = 0, flag = 0x0, 
val = 104}, {name = 0xaaaaad93b0 "ptty", has_arg = 1, flag = 0x0, val = 
112}, {name = 0xaaaaad93b8 "metakey", has_arg = 0,
             flag = 0x0, val = 109}, {name = 0xaaaaad93c0 "metakey8", 
has_arg = 0, flag = 0x0, val = 77}, {name = 0xaaaaad93d0 "ansi", has_arg 
= 0, flag = 0x0, val = 108}, {name = 0xaaaaad93d8 "iso", has_arg = 0, 
flag = 0x0, val = 76}, {name = 0xaaaaad93e0 "term", has_arg = 1,
             flag = 0x0, val = 116}, {name = 0xaaaaad93e8 "noinit", 
has_arg = 0, flag = 0x0, val = 111}, {name = 0xaaaaad93f0 "color", 
has_arg = 1, flag = 0x0, val = 99}, {name = 0xaaaaad93f8 "attrib", 
has_arg = 1, flag = 0x0, val = 97}, {name = 0xaaaaad9400 "dial", has_arg 
= 1,
             flag = 0x0, val = 100}, {name = 0xaaaaad9408 "statline", 
has_arg = 0, flag = 0x0, val = 122}, {name = 0xaaaaad9418 "capturefile", 
has_arg = 1, flag = 0x0, val = 67}, {name = 0xaaaaad9428 "script", 
has_arg = 1, flag = 0x0, val = 83}, {name = 0xaaaaad9430 "7bit",
             has_arg = 0, flag = 0x0, val = 55}, {name = 0xaaaaad9438 
"8bit", has_arg = 0, flag = 0x0, val = 56}, {name = 0xaaaaad9440 
"version", has_arg = 0, flag = 0x0, val = 118}, {name = 0xaaaaad9448 
"wrap", has_arg = 0, flag = 0x0, val = 119}, {
             name = 0xaaaaad8ef8 "displayhex", has_arg = 0, flag = 0x0, 
val = 72}, {name = 0xaaaaad9450 "disabletime", has_arg = 0, flag = 0x0, 
val = 84}, {name = 0xaaaaad8c20 "baudrate", has_arg = 1, flag = 0x0, val 
= 98}, {name = 0xaaaaad9460 "device", has_arg = 1, flag = 0x0,
             val = 68}, {name = 0xaaaaad9468 "remotecharset", has_arg = 
1, flag = 0x0, val = 82}, {name = 0xaaaaad9478 "option", has_arg = 1, 
flag = 0x0, val = 79}, {name = 0xaaaaad9480 "statlinefmt", has_arg = 1, 
flag = 0x0, val = 70}, {
             name = 0xaaaaad9490 "capturefile-buffer-mode", has_arg = 1, 
flag = 0x0, val = 256}, {name = 0x0, has_arg = 0, flag = 0x0, val = 0}}
         OPT_CAP_BUF_MODE = OPT_CAP_BUF_MODE
The following patch was generated by MiMo Code, using model
mimo-v2.5-pro, and was tested myself by hand. It resolves the
segmentation fault, and no regression occurs so far.
I am using AOSC OS instead of Debian, which builds minicom based on
https://salsa.debian.org/minicom-team/minicom/-/releases/2.11.1
 From 98535e4f65d8d1dd5fce238b029fbe71a3edb409 Mon Sep 17 00:00:00 2001
From: Kexy Biscuit <kexybiscuit at aosc.io>
Date: Wed, 22 Jul 2026 15:33:56 +0800
Subject: [PATCH 2/2] vt100: fix segfault on multi-byte UTF-8 input
When do_terminal() receives multi-byte UTF-8 characters (e.g. U+2500
BOX DRAWINGS LIGHT HORIZONTAL), it decodes them to wchar_t via
one_mbtowc() and passes both the raw first byte (ch) and the decoded
wide character (wc) to vt_out().
However, vt_out() always processes the raw byte through vt_inmap[] and
vt_trans[] translation tables before checking whether wc is already set.
For multi-byte sequences, these byte-level translations corrupt the
first byte (e.g. 0xe2 becomes a different value), and the subsequent
wc value passed to mc_wputc() may no longer correspond to the intended
character.
Repeated occurrences corrupt the terminal cursor state (win->curx),
eventually driving it negative.  The _write() function's bounds check
(x < COLS && y < LINES) did not guard against negative coordinates,
so a negative x was used to index into gmap[], causing a segmentation
fault.
Fix by moving the byte-level translation (vt_inmap/vt_trans) inside
the wc == 0 branch so it is only applied when no pre-decoded wide
character is available.  Also add x >= 0 && y >= 0 guards to _write()
as a defensive measure.
This commit is authored with assistance from AI/LLM:
-Model: xiaomi/mimo-v2.5-pro
-Platform: Xiaomi MiMo
-Agent platform: MiMoCode
-Prompt:
   Investigate the reason of a segmentation fault on version 2.11.1
   with the provided backtrace.
Assisted-by: MiMo <noreply at xiaomi.com>
---
  src/vt100.c  | 13 +++++++------
  src/window.c |  4 ++--
  2 files changed, 9 insertions(+), 8 deletions(-)
diff --git a/src/vt100.c b/src/vt100.c
index 2f0f62e..3b1eba6 100644
--- a/src/vt100.c
+++ b/src/vt100.c
@@ -1083,13 +1083,14 @@ void vt_out(int ch, wchar_t wc)
      case 0: /* Normal character */
        if (vt_docap == 1)
          fputc(P_CONVCAP[0] == 'Y' ? vt_inmap[c] : c, capfp);
-     if (!using_iconv()) {
-       c = vt_inmap[c];    /* conversion 04.09.97 / jl */
-       if (vt_type == VT100 && vt_trans[vt_charset] && vt_asis == 0)
-         c = vt_trans[vt_charset][c];
-     }
-     if (wc == 0)
+     if (wc == 0) {
+       if (!using_iconv()) {
+         c = vt_inmap[c];    /* conversion 04.09.97 / jl */
+         if (vt_type == VT100 && vt_trans[vt_charset] && vt_asis == 0)
+           c = vt_trans[vt_charset][c];
+       }
          one_mbtowc (&wc, (char *)&c, 1); /* returns 1 */
+     }
        if (vt_insert)
          mc_winschar2(vt_win, wc, 1);
        else
diff --git a/src/window.c b/src/window.c
index a41b928..80d4c53 100644
--- a/src/window.c
+++ b/src/window.c
@@ -351,9 +351,9 @@ static int _write(wchar_t c, int doit, int x, int y, 
char attr, char color)
      oldc.color = color;
    }
  #ifdef ST_LINE
- if (x < COLS && y <= LINES)
+ if (x >= 0 && y >= 0 && x < COLS && y <= LINES)
  #else
- if (x < COLS && y < LINES)
+ if (x >= 0 && y >= 0 && x < COLS && y < LINES)
  #endif
    {
      if (doit != 0) {
-- 
2.55.0.windows.3



More information about the minicom-devel mailing list