New issue
Advanced search Search tips

Issue 640909 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 637985
Owner:
Closed: Sep 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Integer-overflow in gfx::Rect::bottom

Project Member Reported by ClusterFuzz, Aug 25 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5522560597098496

Fuzzer: inferno_twister
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  gfx::Rect::bottom
  cc::Occlusion::GetUnoccludedContentRect
  cc::RenderSurfaceImpl::AppendQuads
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=407167:409418

Minimized Testcase (14.35 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95gW-oQSPRKQQ0dHukpwrz2_Dgx_GjDIG9ygXNEDJfgRsXP2ASF4cKoVmqqepBPcxrK7W6cxmD5CD7nH2O-cQX8Tgg5m9fpLD2337r_ajctDoONMpjZHlvIakuyWsXBGUOtfj3YndEtIrxSHrI7ZK6aax0l_A?testcase_id=5522560597098496

Issue manually filed by: durga.behera

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Components: Internals>Compositing Tools>Test>FindIt>CorrectResult
Labels: M-54 Te-Logged
Owner: ajuma@chromium.org
Status: Assigned (was: Untriaged)
Suspected CLs
=============
The result is a list of CLs that change the crashed files.

Author: ajuma
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/ad024d0d13a53ae225963d26ed23bd8d80e0d64c
Time: Thu Jul 28 17:42:35 2016
Lines 399-400 of file render_surface_impl.cc which potentially caused crash are changed in this cl (frame #6, "cc::RenderSurfaceImpl::AppendQuads").
Minimum distance from crash line to modified line: 0. (file: render_surface_impl.cc, crashed on: 399, modified: 399).

Author: ajuma
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/4c14b256d8b2b7b3196f246437a9a67f641b980b
Time: Tue Jul 26 20:10:59 2016
Lines 373-377 of file render_surface_impl.cc which potentially caused crash are changed in this cl (frame #6, "cc::RenderSurfaceImpl::AppendQuads").
Minimum distance from crash line to modified line: 0. (file: render_surface_impl.cc, crashed on: 373, modified: 373).

========================
Suspected Project: chromium
Suspected Component: Internals>Compositing

Suspect from above CL list : https://chromium.googlesource.com/chromium/src/+/ad024d0d13a53ae225963d26ed23bd8d80e0d64c
ajuma@ : Could you please take a look into this if its related to your change.

Comment 2 by ajuma@chromium.org, Aug 25 2016

Cc: ajuma@chromium.org
Owner: sunxd@chromium.org
Reassigning to sunxd@ who has a CL in progress (https://codereview.chromium.org/2268423003/) to prevent overflow in gfx::Rect::bottom.

Comment 3 by sunxd@chromium.org, Sep 2 2016

Mergedinto: 637985
Status: Duplicate (was: Assigned)
Project Member

Comment 4 by ClusterFuzz, Sep 3 2016

ClusterFuzz has detected this issue as fixed in range 415934:416233.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5522560597098496

Fuzzer: inferno_twister
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  gfx::Rect::bottom
  cc::Occlusion::GetUnoccludedContentRect
  cc::RenderSurfaceImpl::AppendQuads
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=407167:409418
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=415934:416233

Minimized Testcase (14.35 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95gW-oQSPRKQQ0dHukpwrz2_Dgx_GjDIG9ygXNEDJfgRsXP2ASF4cKoVmqqepBPcxrK7W6cxmD5CD7nH2O-cQX8Tgg5m9fpLD2337r_ajctDoONMpjZHlvIakuyWsXBGUOtfj3YndEtIrxSHrI7ZK6aax0l_A?testcase_id=5522560597098496

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 5 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment