New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 599854 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: May 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Security



Sign in to add a comment

Crash in sk_ssse3::blit_mask_d32_a8

Project Member Reported by ClusterFuzz, Apr 1 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6308354359558144

Fuzzer: inferno_twister
Job Type: linux_asan_chrome_media
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x102cd6bef206
Crash State:
  sk_ssse3::blit_mask_d32_a8
  SkBlitMask::BlitColor
  SkARGB32_Opaque_Blitter::blitMask
  
Recommended Security Severity: Medium

Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_media&range=383194:384380

Minimized Testcase (0.12 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv94r4KgbvaY9y9uZOYhIgGJ76xjO9mCC3zrWrJ_f-lNGeQWYPVPP4izTzFQYtyluiZQ6yRsSfDMcjsZIzVXCvqTykDigq_i9aYR6U3TvBgMgI-eVeX2geIOUN9Qbr3557DUCpK_M9w7PDPMpcVfUcxPJcFYCNg
=&#xe61a;h&#xec2a;<style>
* { animation-name: cfpulse95; letter-spacing: 1.94037781097e+38ex; writing-mode: vertical-lr;


Filer: mmoroz

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: mmoroz@chromium.org mbarbe...@chromium.org
Components: Internals>Skia
Owner: mtkl...@chormium.org
mtklein@, looks like it came from your CLs, but I may be wrong.
Project Member

Comment 2 by ClusterFuzz, Apr 1 2016

Labels: Pri-1
Status: Assigned (was: Available)
Labels: M-50
Labels: -M-50 M-51
Project Member

Comment 5 by ClusterFuzz, Apr 5 2016

Labels: ReleaseBlock-Beta
This medium+ severity security issue is a regression on trunk.

Please fix this asap. If you are unable to look into this soon, please revert your change.

- Your friendly ClusterFuzz
We're about 2 weeks away from M51 Beta launch. Your bug is labelled as Beta ReleaseBlock, pls make sure to land the fix and get it merged ASAP. 

Comment 7 by gov...@chromium.org, Apr 12 2016

M51 Beta is launching very soon! Your bug is labelled as Beta ReleaseBlock, pls make sure to land the fix and get it merged ASAP. All changes MUST be merged into the release branch by 5pm on Apr-19th to make into the desktop Beta build cut. Thanks!
Project Member

Comment 8 by sheriffbot@chromium.org, Apr 14 2016

Labels: -Security_Impact-Head Security_Impact-Beta

Comment 9 by gov...@chromium.org, Apr 18 2016

We're VERY close to M51 Beta candidate cut on Wednesday @ 5:00 PM PST. Any update here?
Cc: sshruthi@chromium.org timwillis@chromium.org
mtklein: can you please ack that this is on your radar?
Labels: -ReleaseBlock-Beta ReleaseBlock-Stable
Moving to RBS as M51 Beta candidate cuts today.
Project Member

Comment 13 by sheriffbot@chromium.org, Apr 21 2016

mtklein: Uh oh! This issue still open and hasn't been updated in the last 19 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers?

If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one?

If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 14 by sheriffbot@chromium.org, May 6 2016

mtklein: Uh oh! This issue still open and hasn't been updated in the last 34 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers?

If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one?

If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
A friendly reminder that M51 Stable is launching soon! Your bug is labelled as Stable ReleaseBlock, pls make sure to land the fix and get it merged into the release branch by May 17. All changes MUST be merged into the release branch by 5pm on May 20 to make into the desktop Stable final build cut. Thanks!
We're getting closer to M51 Stable launch. Please update the bug with the current status. 

Comment 17 Deleted

M51 Stable is launching very soon! Your bug is labelled as Stable ReleaseBlock, pls make sure to land the fix and get it merged ASAP. All changes MUST be merged into the release branch by 5pm on May 20 to make into the desktop Stable final build cut. Thank you!
Any update on this bug? Please note that we're getting very close to M51 stable launch.
Project Member

Comment 20 by ClusterFuzz, May 20 2016

ClusterFuzz has detected this issue as fixed in range 394779:394807.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6308354359558144

Fuzzer: inferno_twister
Job Type: linux_asan_chrome_media
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x102cd6bef206
Crash State:
  sk_ssse3::blit_mask_d32_a8
  SkBlitMask::BlitColor
  SkARGB32_Opaque_Blitter::blitMask
  
Recommended Security Severity: Medium

Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_media&range=383194:384380
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_media&range=394779:394807

Minimized Testcase (0.12 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv94r4KgbvaY9y9uZOYhIgGJ76xjO9mCC3zrWrJ_f-lNGeQWYPVPP4izTzFQYtyluiZQ6yRsSfDMcjsZIzVXCvqTykDigq_i9aYR6U3TvBgMgI-eVeX2geIOUN9Qbr3557DUCpK_M9w7PDPMpcVfUcxPJcFYCNg
=&#xe61a;h&#xec2a;<style>
* { animation-name: cfpulse95; letter-spacing: 1.94037781097e+38ex; writing-mode: vertical-lr;


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Labels: -ReleaseBlock-Stable -M-51 Release-NA merge-na
Status: Fixed (was: Assigned)
Given that ClusterFuzz cannot reproduce the issue, I assume that it has been fixed by some unrelated fix. Marking as Merge-NA and Release-NA.

Please fix me if I'm wrong.
Project Member

Comment 22 by sheriffbot@chromium.org, May 20 2016

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify

Comment 23 by rmis...@google.com, Jun 13 2016

Owner: mtklein@chromium.org
Project Member

Comment 24 by sheriffbot@chromium.org, Aug 26 2016

Labels: -Restrict-View-SecurityNotify
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 25 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 26 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment