Integer-overflow in position_mark |
||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4567209162833920 Fuzzer: libfuzzer_harfbuzz_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: position_mark position_around_base position_cluster Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=395640:395746 Minimized Testcase (10.18 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96rI7PWThfDmijLzi2MVOlV1auVRqqbv-r81Uq5eiNokLdVQ2YvrakFhbXTVhU_maDvrgas3z-PuLkMXTfhXQEGu6aaNQ9u1k4oTKRHVgc9sZZQy76D5q0Pt_y3Es-1MCwgBaHIRXMw4292oKfUuW6g2MWnMw?testcase_id=4567209162833920 Additional requirements: Requires Gestures Filer: mummareddy See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Aug 2 2016
behdad@, can you triage this?
,
Aug 2 2016
Should be harmless. Also tracked here: https://github.com/behdad/harfbuzz/issues/189
,
Aug 2 2016
,
Aug 5 2016
Moving this nonessential bug to the next milestone. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 11 2016
ClusterFuzz has detected this issue as fixed in range 424217:424275. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4567209162833920 Fuzzer: libfuzzer_harfbuzz_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: position_mark position_around_base position_cluster Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=395640:395746 Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=424217:424275 Minimized Testcase (10.18 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96rI7PWThfDmijLzi2MVOlV1auVRqqbv-r81Uq5eiNokLdVQ2YvrakFhbXTVhU_maDvrgas3z-PuLkMXTfhXQEGu6aaNQ9u1k4oTKRHVgc9sZZQy76D5q0Pt_y3Es-1MCwgBaHIRXMw4292oKfUuW6g2MWnMw?testcase_id=4567209162833920 Additional requirements: Requires Gestures See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Oct 11 2016
ClusterFuzz testcase is verified as fixed, closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Oct 18 2016
,
Oct 18 2016
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
May 2 2017
Bulk-WontFixing these bugs. This was a bug on ClusterFuzz side, see bug 717534. We will start seeing new testcases auto-filed in a day or two. We can't leave these open as ClusterFuzz won't autoverify them after ClusterFuzz-Wrong label.
,
Sep 18 2017
We have made a bunch of changes on ClusterFuzz side, so resetting ClusterFuzz-Wrong label. |
||||||||||
►
Sign in to add a comment |
||||||||||
Comment 1 by mummare...@chromium.org
, Aug 1 2016Components: Blink>Fonts
Labels: Te-Logged M-53
Status: Available (was: Untriaged)