New issue
Advanced search Search tips

Issue 612159 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 611198
Owner: ----
Closed: May 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug



Sign in to add a comment

Security: AddressSanitizer: FPE on unknown address 0x557911655e20

Reported by marcin.t...@gmail.com, May 16 2016

Issue description

VERSION
Chrome Version: asan-symbolized-linux-release-386315
Operating System: Ubuntu 14.04 LTS x64

CHROME:
asan-symbolized-linux-release-386315 : ./chrome --no-sandbox



ASAN:DEADLYSIGNAL
=================================================================
==30047==ERROR: AddressSanitizer: FPE on unknown address 0x557911655e20 (pc 0x557911655e20 bp 0x7ffe93444580 sp 0x7ffe93444530 T0)
    #0 0x557911655e1f in ?? third_party/pdfium/core/fxge/dib/fx_dib_engine.cpp:343:45
    #1 0x557911657fba in ?? third_party/pdfium/core/fxge/dib/fx_dib_engine.cpp:843:3
    #2 0x5579116572e7 in ?? third_party/pdfium/core/fxge/dib/fx_dib_engine.cpp:830:10
    #3 0x5579115dd337 in ?? third_party/pdfium/core/fxge/agg/fx_agg_driver.cpp:1758:7
    #4 0x5579116844b7 in ?? third_party/pdfium/core/fxge/ge/fx_ge_device.cpp:475:10
    #5 0x55791129c7c8 in StartBitmapAlpha third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render_image.cpp:819:7
    #6 0x55791129a56e in ?? third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render_image.cpp:367:12
    #7 0x557911294ffa in ?? third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render_image.cpp:490:10
    #8 0x557911294bd8 in ?? third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render_image.cpp:34:7
    #9 0x557911281bbb in ?? third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render.cpp:402:14
    #10 0x55791127eb65 in ?? third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render.cpp:302:3
    #11 0x55791127e2b8 in RenderObjectList third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render.cpp:281:5
    #12 0x5579112894fc in ?? third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render.cpp:1029:7
    #13 0x5579112cc21e in ?? third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render_pattern.cpp:992:3
    #14 0x5579112c9ee7 in DrawTilingPattern third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render_pattern.cpp:1119:22
    #15 0x5579112cc468 in ?? third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render_pattern.cpp:1191:5
    #16 0x5579112cc71c in ?? third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render_pattern.cpp:1212:7
    #17 0x5579112839a0 in ?? third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render.cpp:507:3
    #18 0x557911281b6c in ?? third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render.cpp:399:14
    #19 0x5579112822d9 in ContinueSingleObject third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render.cpp:339:3
    #20 0x55791128b5b3 in Continue third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render.cpp:1103:13
    #21 0x55791128a903 in ?? third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render.cpp:1064:3
    #22 0x5579110dcb06 in ?? third_party/pdfium/fpdfsdk/fpdfview.cpp:935:3
    #23 0x5579110eb1d4 in ?? third_party/pdfium/fpdfsdk/fpdf_progressive.cpp:61:3
    #24 0x557902dade61 in ContinuePaint pdf/pdfium/pdfium_engine.cc:2711:10
    #25 0x557902dac72b in Paint pdf/pdfium/pdfium_engine.cc:958:11
    #26 0x557902e0b38e in OnPaint pdf/out_of_process_instance.cc:719:7
    #27 0x557902e22702 in DoPaint pdf/paint_manager.cc:204:3
    #28 0x557902e24720 in ?? pdf/paint_manager.cc:291:5
    #29 0x557902e2516d in ?? ppapi/utility/completion_callback_factory.h:607:9
    #30 0x557902e24ec9 in ?? ppapi/utility/completion_callback_factory.h:584:7
    #31 0x55790b09d476 in ?? ppapi/shared_impl/proxy_lock.h:135:10
    #32 0x55790b09c288 in ?? ppapi/shared_impl/tracked_callback.cc:141:7
    #33 0x55790f93e86b in ?? base/bind_internal.h:311:5
    #34 0x55790f96011f in OnReplyReceived ppapi/proxy/plugin_resource.cc:54:5
    #35 0x55790f95d523 in ?? ppapi/proxy/plugin_message_filter.cc:116:3
    #36 0x55790f95f420 in ?? base/bind_internal.h:311:5
    #37 0x557903094470 in ?? base/debug/task_annotator.cc:51:3
    #38 0x557902efb669 in ?? base/message_loop/message_loop.cc:479:3
    #39 0x557902efc58d in DeferOrRunPendingTask base/message_loop/message_loop.cc:488:5
    #40 0x557902efcc85 in DoWork base/message_loop/message_loop.cc:600:13
    #41 0x557902f0a1e2 in ?? base/message_loop/message_pump_default.cc:33:21
    #42 0x557902efab84 in RunHandler base/message_loop/message_loop.cc:443:3
    #43 0x557902f6e8c4 in ?? base/run_loop.cc:35:3
    #44 0x557902ef82f8 in ?? base/message_loop/message_loop.cc:295:3
    #45 0x557911ce9486 in PpapiPluginMain content/ppapi_plugin/ppapi_plugin_main.cc:162:3
    #46 0x557902d99860 in RunZygote content/app/content_main_runner.cc:306:14
    #47 0x557902d9ad5f in RunNamedProcessTypeMain content/app/content_main_runner.cc:389:12
    #48 0x557902d9dfc5 in ?? content/app/content_main_runner.cc:742:12
    #49 0x557902d9895d in ContentMain content/app/content_main.cc:20:15
    #50 0x55790199bd0c in ?? chrome/app/chrome_main.cc:84:12
    #51 0x7f30dde53ec4 in __libc_start_main /build/eglibc-3GlaMS/eglibc-2.19/csu/libc-start.c:287:0

AddressSanitizer can not provide additional info.

PDFIUM_TEST: build on May 15th.
./pdfium_test crash4.pdf


ASAN:DEADLYSIGNAL
=================================================================
==26113==ERROR: AddressSanitizer: FPE on unknown address 0x000000b2d0cc (pc 0x000000b2d0cc bp 0x7ffd930b79f0 sp 0x7ffd930b79b0 T0)
    #0 0xb2d0cb in StartStretchHorz third_party/pdfium/core/fxge/dib/fx_dib_engine.cpp:365:45
    #1 0xb2f9db in StartStretch third_party/pdfium/core/fxge/dib/fx_dib_engine.cpp:858:3
    #2 0xb2ea7b in Start third_party/pdfium/core/fxge/dib/fx_dib_engine.cpp:845:10
    #3 0xac3e96 in StretchDIBits third_party/pdfium/core/fxge/agg/fx_agg_driver.cpp:1759:7
    #4 0xb5db0d in StretchBitMask third_party/pdfium/core/fxge/ge/fx_ge_device.cpp:475:10
    #5 0x70a4ed in StartBitmapAlpha third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render_image.cpp:819:7
    #6 0x7087b7 in StartRenderDIBSource third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render_image.cpp:366:12
    #7 0x70371b in ProcessImage third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render_image.cpp:33:7
    #8 0x6f252b in ?? third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render.cpp:356:14
    #9 0x6ee8c7 in RenderSingleObject third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render.cpp:260:3
    #10 0x6ee098 in RenderObjectList third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render.cpp:239:5
    #11 0x6fac0c in Render third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render.cpp:983:7
    #12 0x73379f in DrawPatternBitmap third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render_pattern.cpp:1004:3
    #13 0x73188f in DrawTilingPattern third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render_pattern.cpp:1126:9
    #14 0x733c7d in DrawPathWithPattern third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render_pattern.cpp:1203:5
    #15 0x733c7d in ProcessPathPattern third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render_pattern.cpp:1222:0
    #16 0x6f4ae2 in ProcessPath third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render.cpp:461:3
    #17 0x6f24dc in ?? third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render.cpp:353:14
    #18 0x6f2c52 in ContinueSingleObject third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render.cpp:297:3
    #19 0x6fce19 in Continue third_party/pdfium/core/fpdfapi/fpdf_render/fpdf_render.cpp:1057:13
    #20 0x4f9dd8 in FPDF_RenderPage_Retail third_party/pdfium/fpdfsdk/fpdfview.cpp:936:3
    #21 0x4f94de in FPDF_RenderPageBitmap third_party/pdfium/fpdfsdk/fpdfview.cpp:669:3
    #22 0x4e71c3 in RenderPage third_party/pdfium/samples/pdfium_test.cc:517:3
    #23 0x4e90ba in ?? third_party/pdfium/samples/pdfium_test.cc:694:9
    #24 0x4eaa08 in main third_party/pdfium/samples/pdfium_test.cc:835:5
    #25 0x7fb3f44e6ec4 in __libc_start_main /build/eglibc-3GlaMS/eglibc-2.19/csu/libc-start.c:287:0

AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: FPE (/home/mtowalski/chromium/src/out/Release/pdfium_test+0xb2d0cb)

 
crash4.pdf
2.0 KB Download
Components: Internals>Plugins>PDF
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
FPEs tend not to be security bugs. Removing view restrictions and reclassifying.
Mergedinto: 611198
Status: Duplicate (was: Unconfirmed)
Clusterfuzz beat you to it.
No wonder, how could I beat CF with 4 cores:)

Sign in to add a comment