New issue
Advanced search Search tips

Issue 599629 link

Starred by 0 users

Issue metadata

Status: Duplicate
Merged: issue 599458
Owner:
Closed: May 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Security



Sign in to add a comment

Use-of-uninitialized-value in sk_sse41::blit_row_s32a_opaque

Project Member Reported by ClusterFuzz, Mar 31 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5314109058318336

Fuzzer: inferno_canvas_wrecker
Job Type: linux_msan_chrome
Platform Id: linux

Crash Type: Use-of-uninitialized-value
Crash Address: 
Crash State:
  sk_sse41::blit_row_s32a_opaque
  SkARGB32_Shader_Blitter::blitAntiH
  SkRectClipBlitter::blitAntiH
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_msan_chrome&range=361453:361496

Minimized Testcase (0.99 Kb): https://cluster-fuzz.appspot.com/download/AMIfv945_pEjwYir151z968rmLwK-5MKJlA1GbOkzj1gWlw5zBAnbwc3Xh-AOEuTjkKvQLw048GV19ivB5h2OtyWSRa_UmNEEqNiKQFveDyiUMLLPqh9Ukh0_4EU0kxsAz9vpndrpTqY6HZ_WIzPqHfwqYI3DKerIQ

Filer: inferno

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Project Member

Comment 1 by ClusterFuzz, Mar 31 2016

Labels: Pri-1
Cc: mtkl...@chormium.org hcm@chromium.org
Mike, Heather,

I'm hoping one of you could help to assign this security bug appropriately.

Thanks much!
Cc: -mtkl...@chormium.org
Labels: M-50
Owner: mtkl...@chormium.org
Status: Assigned (was: Available)
mtklein, could you please take a look when you get the chance?
Components: Internals>Skia
Project Member

Comment 5 by sheriffbot@chromium.org, Apr 21 2016

mtklein: Uh oh! This issue still open and hasn't been updated in the last 20 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers?

If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one?

If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 6 by sheriffbot@chromium.org, May 6 2016

mtklein: Uh oh! This issue still open and hasn't been updated in the last 35 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers?

If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one?

If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Mergedinto: 599458
Status: Duplicate (was: Assigned)
This looks like a dupe.

Comment 8 by jww@chromium.org, May 25 2016

Owner: mtklein@chromium.org
Fixing the owner's email address
Project Member

Comment 9 by ClusterFuzz, Jun 9 2016

ClusterFuzz has detected this issue as fixed in range 396253:396347.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5314109058318336

Fuzzer: inferno_canvas_wrecker
Job Type: linux_msan_chrome
Platform Id: linux

Crash Type: Use-of-uninitialized-value
Crash Address: 
Crash State:
  sk_sse41::blit_row_s32a_opaque
  SkARGB32_Shader_Blitter::blitAntiH
  SkRectClipBlitter::blitAntiH
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_msan_chrome&range=361453:361496
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_msan_chrome&range=396253:396347

Minimized Testcase (0.99 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97jpHJnQSmQvvostG0NNmdRDrT_ppdh2Bo2Vqm9P--a547BRodPscJcio83SHzCulbOhFwhjFhwo5WOxvZJyKl_B7NTjLqoqMjHU_erEc5UlJivJMSFfWYEyL6L-O7SmMx3B8VGAzlznCjZhv1eghxAYA5V8w

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 10 by sheriffbot@chromium.org, Sep 3 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 11 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 12 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment