New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 629962 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Last visit > 30 days ago
Closed: Jul 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: All
Pri: 1
Type: Bug-Security



Sign in to add a comment

Use-of-uninitialized-value in segment

Project Member Reported by ClusterFuzz, Jul 20 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5154511169781760

Fuzzer: libfuzzer_skia_pathop_fuzzer
Job Type: libfuzzer_chrome_msan
Platform Id: linux

Crash Type: Use-of-uninitialized-value
Crash Address: 
Crash State:
  segment
  containsCoincidence
  SkOpSpan::insertCoincidence
  
Recommended Security Severity: Medium


Minimized Testcase (0.43 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97BGafjVRRRvBnVQQOlVapUakT2LZj5euTDSMMw21fRGYnALfR25mmxQNyX7aPQw2mJkZ6EoZyICzD_1O84fBPGtg2Ss5zIjGBtm75fAaq1nltLmE_URlm-x4zL1U5vqjtz5wWdk3syyBGHyzDirgPJKjb8zA?testcase_id=5154511169781760

Filer: inferno

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 
Cc: reed@chromium.org
Components: Internals>Skia
Labels: -OS-Linux OS-All Pri-1
Owner: caryclark@chromium.org
Status: Assigned (was: Untriaged)
Cc: caryclark@chromium.org
Owner: caryclark@google.com
Project Member

Comment 3 by bugdroid1@chromium.org, Jul 21 2016

Project Member

Comment 4 by bugdroid1@chromium.org, Jul 21 2016

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/80c8275a0224e98155648f61463f77e967537add

commit 80c8275a0224e98155648f61463f77e967537add
Author: skia-deps-roller <skia-deps-roller@chromium.org>
Date: Thu Jul 21 14:47:31 2016

Roll src/third_party/skia/ ec336deff..9b43094bf (2 commits).

https://chromium.googlesource.com/skia.git/+log/ec336deffbf5..9b43094bf207

$ git log ec336deff..9b43094bf --date=short --no-merges --format='%ad %ae %s'
2016-07-21 mtklein Roll buildtools for latest GN binary.
2016-07-21 caryclark fix fuzzer bug

BUG= 629962 

CQ_INCLUDE_TRYBOTS=master.tryserver.blink:linux_blink_rel
TBR=jcgregorio@google.com

Review-Url: https://codereview.chromium.org/2165273002
Cr-Commit-Position: refs/heads/master@{#406850}

[modify] https://crrev.com/80c8275a0224e98155648f61463f77e967537add/DEPS

Status: Fixed (was: Assigned)
Project Member

Comment 6 by ClusterFuzz, Jul 22 2016

ClusterFuzz has detected this issue as fixed in range 406824:406932.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5154511169781760

Fuzzer: libfuzzer_skia_pathop_fuzzer
Job Type: libfuzzer_chrome_msan
Platform Id: linux

Crash Type: Use-of-uninitialized-value
Crash Address: 
Crash State:
  segment
  containsCoincidence
  SkOpSpan::insertCoincidence
  
Recommended Security Severity: Medium

Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_msan&range=406010:406169
Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_msan&range=406824:406932

Minimized Testcase (0.43 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97BGafjVRRRvBnVQQOlVapUakT2LZj5euTDSMMw21fRGYnALfR25mmxQNyX7aPQw2mJkZ6EoZyICzD_1O84fBPGtg2Ss5zIjGBtm75fAaq1nltLmE_URlm-x4zL1U5vqjtz5wWdk3syyBGHyzDirgPJKjb8zA?testcase_id=5154511169781760

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 7 by sheriffbot@chromium.org, Jul 22 2016

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Labels: Security_Impact-Head M-54
Project Member

Comment 9 by sheriffbot@chromium.org, Oct 28 2016

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment