Integer-overflow in media::H264Parser::ParseSPS |
|||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6178217318940672 Fuzzer: libfuzzer_media_h264_parser_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: media::H264Parser::ParseSPS _start Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=397693:397764 Minimized Testcase (0.12 Kb): https://cluster-fuzz.appspot.com/download/AMIfv972qNA8fIZz3EEFhW6PqdWad1EVqmTM0iUUvgpgEqtW5teH--FTkb6DpWgTIJERsX7TwVljqpyg9Sp7l5K-FTKPMAp1WMJ4jZdnzYnowUmVqyOHyHn_A1zb3aREs3Prc3cg2xEeP_mARLY4WS3D6ZlllBRXMw?testcase_id=6178217318940672 Issue manually filed by: ajha See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Aug 16 2016
ajha@, the changes above are the improvements to the fuzzer that have probably caused this bug to get discovered. Or maybe the fuzzing simple had more time to discover bugs. The bug is in media::H264Parser::ParseSPS, please assign accordingly.
,
Aug 17 2016
Thanks kcc@ for the update. jrummell@: Could this be related to https://codereview.chromium.org/1865203002. Please help in finding an appropriate owner if the change is unrelated.
,
Sep 3 2016
ClusterFuzz has detected this issue as fixed in range 416303:416379. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6178217318940672 Fuzzer: libfuzzer_media_h264_parser_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: media::H264Parser::ParseSPS _start Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=397693:397764 Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=416303:416379 Minimized Testcase (0.12 Kb): https://cluster-fuzz.appspot.com/download/AMIfv972qNA8fIZz3EEFhW6PqdWad1EVqmTM0iUUvgpgEqtW5teH--FTkb6DpWgTIJERsX7TwVljqpyg9Sp7l5K-FTKPMAp1WMJ4jZdnzYnowUmVqyOHyHn_A1zb3aREs3Prc3cg2xEeP_mARLY4WS3D6ZlllBRXMw?testcase_id=6178217318940672 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Sep 3 2016
ClusterFuzz testcase is verified as fixed, closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||
►
Sign in to add a comment |
|||||
Comment 1 by ajha@chromium.org
, Aug 16 2016Labels: Findit-for-crash Te-Logged M-53
Owner: kcc@chromium.org
Status: Assigned (was: Untriaged)