Undefined-shift in WebRtcIlbcfix_GetLspPoly |
||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6293977053003776 Fuzzer: libfuzzer_audio_decoder_ilbc_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Undefined-shift Crash Address: Crash State: WebRtcIlbcfix_GetLspPoly WebRtcIlbcfix_Lsf2Poly WebRtcIlbcfix_LspInterpolate2PolyDec Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=386932:386961 Minimized Testcase (0.04 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97GHFv4KOfA3U34xZeRhDdBUTTgt6u_A62U2RYIyf3ZFB718yVtiSml0W1QxoCFjOfuC44WReACCITzMiAqBr5iLjvlyvSRCN4Jbn4ZtD7ASaEvi-jMzpJrWTD3gWkddC8BCKfO3A3traVRQjrZPVDfRuU23Q Filer: mmoroz See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Apr 14 2016
,
May 17 2016
The following revision refers to this bug: https://chromium.googlesource.com/external/webrtc.git/+/9b2228fdfc63ad0280de4f12eb9f12bc38d291f4 commit 9b2228fdfc63ad0280de4f12eb9f12bc38d291f4 Author: kwiberg <kwiberg@webrtc.org> Date: Tue May 17 13:40:41 2016 Fix UBSan errors (left shift of negative value) BUG= chromium:603501 Review-Url: https://codereview.webrtc.org/1988723002 Cr-Commit-Position: refs/heads/master@{#12775} [modify] https://crrev.com/9b2228fdfc63ad0280de4f12eb9f12bc38d291f4/webrtc/modules/audio_coding/codecs/ilbc/get_lsp_poly.c [modify] https://crrev.com/9b2228fdfc63ad0280de4f12eb9f12bc38d291f4/webrtc/modules/audio_coding/codecs/ilbc/hp_output.c
,
May 17 2016
According to my manual testing, that CL should have fixed the bug.
,
May 19 2016
ClusterFuzz has detected this issue as fixed in range 394360:394410. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6293977053003776 Fuzzer: libfuzzer_audio_decoder_ilbc_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Undefined-shift Crash Address: Crash State: WebRtcIlbcfix_GetLspPoly WebRtcIlbcfix_Lsf2Poly WebRtcIlbcfix_LspInterpolate2PolyDec Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=386932:386961 Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=394360:394410 Minimized Testcase (0.04 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97GHFv4KOfA3U34xZeRhDdBUTTgt6u_A62U2RYIyf3ZFB718yVtiSml0W1QxoCFjOfuC44WReACCITzMiAqBr5iLjvlyvSRCN4Jbn4ZtD7ASaEvi-jMzpJrWTD3gWkddC8BCKfO3A3traVRQjrZPVDfRuU23Q See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
||||
►
Sign in to add a comment |
||||
Comment 1 by mmoroz@chromium.org
, Apr 14 2016Owner: pbos@chromium.org