New issue
Advanced search Search tips

Issue 636054 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Dec 2016
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Integer-overflow in walk_convex_edges

Project Member Reported by ClusterFuzz, Aug 9 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5564031635292160

Fuzzer: inferno_webbot
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  walk_convex_edges
  sk_fill_path
  SkScan::FillPath
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=370165:370712

Minimized Testcase (0.09 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv97ZsY_7Y07w4wpqmYYR2o8CFBBjXFr-fWu_K48KIDFKf79QhBRKemVN3SKqX3ch_cABG8iD16EI3ob_v-BBwMdqER4C1TeXnkhs-47VyqvgbVM-MhfHXSf3L9m7XQj0-iLrkwSWJsW1y_TO8nRkPCeAbxQ-Qw?testcase_id=5564031635292160
<script>
window.open("http://rusmeteo.net");
window.location = "http://itstactical.com";</script>


Issue manually filed by: mmohammad

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Owner: senorblanco@chromium.org
Status: Assigned (was: Untriaged)
suspected 
Changelist: https://chromium.googlesource.com/skia.git/+/afc7cce5d68663934128d76963cd501f771d71de

senorblanco@ could you please look into this. thanks
Owner: reed@google.com
I think my change is simply tickling something deeper in Skia.

reed@, could you triage?
Project Member

Comment 3 by ClusterFuzz, Aug 18 2016

Labels: Stability-AFL Stability-Memory-AddressSanitizer
Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4508213640953856

Fuzzer: afl_skia_path_fuzzer
Job Type: afl_chrome_asan
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000010
Crash State:
  sk_fill_path
  SkScan::FillPath
  SkScan::FillPath
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=402185:402404

Minimized Testcase (0.12 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96CFcv_KQu4asKdwqOoU1v0af3A40zy5MvavGk9LLUIj7taJd-VWAxQN31yQShCJLsrgMRslqGDw7ZIasKTBJZP0cCvD5Q0s3Tzvc1rttYy_gUWLSwlCxsEDBeXJbgCUsY8Ctgr-F053Z9-0av9BN2JlSipIw?testcase_id=4508213640953856

Issue manually filed by: mummareddy

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
Project Member

Comment 4 by ClusterFuzz, Aug 25 2016

ClusterFuzz has detected this issue as fixed in range 414068:414117.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4508213640953856

Fuzzer: afl_skia_path_fuzzer
Job Type: afl_chrome_asan
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000010
Crash State:
  sk_fill_path
  SkScan::FillPath
  SkScan::FillPath
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=402185:402404
Fixed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=414068:414117

Minimized Testcase (0.12 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96CFcv_KQu4asKdwqOoU1v0af3A40zy5MvavGk9LLUIj7taJd-VWAxQN31yQShCJLsrgMRslqGDw7ZIasKTBJZP0cCvD5Q0s3Tzvc1rttYy_gUWLSwlCxsEDBeXJbgCUsY8Ctgr-F053Z9-0av9BN2JlSipIw?testcase_id=4508213640953856

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 5 by ClusterFuzz, Aug 25 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4562951405305856

Fuzzer: afl_skia_path_fuzzer
Job Type: afl_chrome_asan
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000010
Crash State:
  sk_fill_path
  SkScan::FillPath
  SkScan::FillPath
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=414365:414421

Minimized Testcase (0.07 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96IIZ-GQZbV5f5rxtuBDFPvx5wiXHGZvTtGRw4bzh5R3V1oo5UDcPEW10MjRUl7-Mr63pVeiz9j9iwEM--NdarGGm9rqBMw0Eyu5zcUmz01DrbmZMvpsZ2jc62xS4ABMIqaME0egdxXt_MmgUF2Lgu3AcPboA?testcase_id=4562951405305856

Issue manually filed by: mmohammad

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
Project Member

Comment 6 by ClusterFuzz, Aug 26 2016

ClusterFuzz has detected this issue as fixed in range 414421:414515.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4562951405305856

Fuzzer: afl_skia_path_fuzzer
Job Type: afl_chrome_asan
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000010
Crash State:
  sk_fill_path
  SkScan::FillPath
  SkScan::FillPath
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=414365:414421
Fixed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=414421:414515

Minimized Testcase (0.07 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96IIZ-GQZbV5f5rxtuBDFPvx5wiXHGZvTtGRw4bzh5R3V1oo5UDcPEW10MjRUl7-Mr63pVeiz9j9iwEM--NdarGGm9rqBMw0Eyu5zcUmz01DrbmZMvpsZ2jc62xS4ABMIqaME0egdxXt_MmgUF2Lgu3AcPboA?testcase_id=4562951405305856

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 7 by ClusterFuzz, Aug 26 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6199075743727616

Fuzzer: afl_skia_path_fuzzer
Job Type: afl_chrome_asan
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000010
Crash State:
  sk_fill_path
  SkScan::FillPath
  SkScan::FillPath
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=414624:414653

Minimized Testcase (0.07 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94x9Iy_pIIxkzl_Zxi8NX8DLG0DMcTgsyN5zHMdRsXGEbySqgcwunU88XXxAub4x-gnOz6BbT2djXPftWEJFGCXkaJJ1m1JJn4pO-Zo7VxMwsoUD0QC7OXfOHTvkloakMvUduYXmcAo4vajvxqCTbJomDg0ZA?testcase_id=6199075743727616

Issue manually filed by: mmohammad

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
Project Member

Comment 8 by ClusterFuzz, Aug 27 2016

ClusterFuzz has detected this issue as fixed in range 414747:414803.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6199075743727616

Fuzzer: afl_skia_path_fuzzer
Job Type: afl_chrome_asan
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000010
Crash State:
  sk_fill_path
  SkScan::FillPath
  SkScan::FillPath
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=414624:414653
Fixed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=414747:414803

Minimized Testcase (0.07 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94x9Iy_pIIxkzl_Zxi8NX8DLG0DMcTgsyN5zHMdRsXGEbySqgcwunU88XXxAub4x-gnOz6BbT2djXPftWEJFGCXkaJJ1m1JJn4pO-Zo7VxMwsoUD0QC7OXfOHTvkloakMvUduYXmcAo4vajvxqCTbJomDg0ZA?testcase_id=6199075743727616

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 10 by ClusterFuzz, Aug 30 2016

ClusterFuzz has detected this issue as fixed in range 415035:415039.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6473463688855552

Fuzzer: afl_skia_path_fuzzer
Job Type: afl_chrome_asan
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000010
Crash State:
  sk_fill_path
  SkScan::FillPath
  SkScan::FillPath
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=414983:414996
Fixed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=415035:415039

Minimized Testcase (0.08 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94gn_ZkQZycjkkDDcc2L_Mv8XtOog3iR7PXMa5Ds21e4_ip0S81LOKKmzQ7UCAbIoqU0ZFv_zrXVW1s3UkdYGalxcOA15W3LIK66W_17thlR8gYBL-jGwn2JqlLjF2V-oCpvDPzu2ZN2A_DqTYdSJOxJXXb5Q?testcase_id=6473463688855552

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Labels: Pri-2
Project Member

Comment 13 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 14 by ClusterFuzz, Dec 1 2016

ClusterFuzz has detected this issue as fixed in range 435159:435196.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5564031635292160

Fuzzer: inferno_webbot
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  walk_convex_edges
  sk_fill_path
  SkScan::FillPath
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=370165:370712
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=435159:435196

Minimized Testcase (0.09 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv97ZsY_7Y07w4wpqmYYR2o8CFBBjXFr-fWu_K48KIDFKf79QhBRKemVN3SKqX3ch_cABG8iD16EI3ob_v-BBwMdqER4C1TeXnkhs-47VyqvgbVM-MhfHXSf3L9m7XQj0-iLrkwSWJsW1y_TO8nRkPCeAbxQ-Qw?testcase_id=5564031635292160
<script>
window.open("http://rusmeteo.net");
window.location = "http://itstactical.com";</script>


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 15 by ClusterFuzz, Dec 31 2016

Status: WontFix (was: Assigned)
ClusterFuzz testcase 5806323600195584 is flaky and no longer reproduces, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment