Crash in sfntly::GlyphTable::Glyph::GetGlyph |
||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4863804200714240 Fuzzer: afl_sfntly_fuzzer Job Type: afl_chrome_asan Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000000 Crash State: sfntly::GlyphTable::Glyph::GetGlyph sfntly::SubsetterImpl::SubsetFont SfntlyWrapper::SubsetFont Regressed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=414211:414309 Minimized Testcase (0.81 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97Hxhz86XtWOdXUKmR55ogm8lfIihqJtbQgOzch7_z7olXjgok8FTEtFuzBm1MaRew1ToB3e7HFWo8N1K0l4pMtqUf0Ez8c1_T0NiFKuk8VZsWzeRiWiPmazH-5TXJCV9gKsC2fMW2Mu5jYwGS62dm7pld6Xw?testcase_id=4863804200714240 Issue manually filed by: durga.behera See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Aug 26 2016
Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5606562490220544 Fuzzer: libfuzzer_sfntly_fuzzer Job Type: libfuzzer_chrome_asan Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000000 Crash State: Glyph SimpleGlyph sfntly::GlyphTable::Glyph::GetGlyph Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=414164:414272 Minimized Testcase (0.77 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94jrZP4TV_U41lD2ZRUWJFgdkk2x4wVVj1wem56HCc9HYa0jOHOIHx0r6LJZEBRXKhebUY_qPu2Fwp2xJiEYqjyDW8tZLUxV5gLYYESEvS5m4T-N-tQCNMApXCmAvUMv3OtP6jJ4ZTA41_Q0WZm7LEKRa8SIw?testcase_id=5606562490220544 Issue manually filed by: durga.behera See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Aug 26 2016
Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5535874995716096 Fuzzer: libfuzzer_sfntly_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Undefined-shift Crash Address: Crash State: sfntly::ReadableFontData::ReadULong sfntly::LocaTable::GlyphLength ResolveCompositeGlyphs Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=414214:414310 Minimized Testcase (0.85 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96b1UANVA5h_psKobaoFGSwOJjLtttpo6A46P5F6VjyXgNoV1SNNrqbf2j3STCppUXp0E-v9FuSZhoQyZPtn24N0K0SEDnq5w3dnpMdDGgQTlBjh5vwMFUQFVyqMW7w72qQPbVfk6A_oF7Ta2eukmXkjEsALA?testcase_id=5535874995716096 Issue manually filed by: durga.behera See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Aug 26 2016
Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6451442972098560 Fuzzer: libfuzzer_sfntly_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Undefined-shift Crash Address: Crash State: sfntly::ReadableFontData::ReadByte sfntly::ReadableFontData::ReadLong sfntly::Font::Builder::ReadHeader Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=414214:414310 Minimized Testcase (0.03 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97riY6sz1YHFwIqLQMitN4j-1dCYomn4hzd8X3HYAWZflh9kaQiswX5fUNNvcDEh1F7w6oaNlUuMQlJj_q7G9unpcHdGoy-g6D2_9zVcBMLQcpEa0wXgrkMu8aondPGMa19PYlnuGwFGClFAmYQlAAnAjeDmg?testcase_id=6451442972098560 Issue manually filed by: durga.behera See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Aug 26 2016
,
Aug 26 2016
,
Aug 29 2016
It looks like comment 3 and comment 4 are misfiled. Shouldn't those be separate bugs?
,
Aug 29 2016
Comment 3 and comment 4 are both bug 641460 .
,
Aug 29 2016
Yes, comment 3 and 4 were incorrectly triaged reports. I've re-filed them separately because they are not related to this issue.
,
Aug 29 2016
,
Aug 31 2016
Are you going to submit this upstream?
,
Aug 31 2016
Yes. I'm going to submit all of them upstream soonish, but first a small fire to put out: bug 642953 .
,
Sep 8 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/8fe11cb88b21b7e1c3a8830249ab30c72d556bd7 commit 8fe11cb88b21b7e1c3a8830249ab30c72d556bd7 Author: thestig <thestig@chromium.org> Date: Thu Sep 08 09:11:00 2016 Roll DEPS for sfntly b18b09b..1ef790a https://chromium.googlesource.com/external/github.com/googlei18n/sfntly/+log/b18b09b..1ef790a 1ef790a Add missing header from commit c9025ecc. 6917286 Merge pull request #58 from leizleiz/leizleiz-lotsofchecks 4f1aa49 Add ReadableFontData::kInvalidUnsigned. c9025ec Add more bounds checks in WritableFontData. dd23046 Return error values in ReadableFontData::Read*(). 813efeb Add a size limit for font tables. 08652be Add a nullptr check to GlyphTable::Glyph(). BUG= 641330 , 641446 , 641460 , 642300 TBR=behdad@chromium.org Review-Url: https://codereview.chromium.org/2316303003 Cr-Commit-Position: refs/heads/master@{#417229} [modify] https://crrev.com/8fe11cb88b21b7e1c3a8830249ab30c72d556bd7/DEPS
,
Sep 8 2016
,
Sep 8 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/8fe11cb88b21b7e1c3a8830249ab30c72d556bd7 commit 8fe11cb88b21b7e1c3a8830249ab30c72d556bd7 Author: thestig <thestig@chromium.org> Date: Thu Sep 08 09:11:00 2016 Roll DEPS for sfntly b18b09b..1ef790a https://chromium.googlesource.com/external/github.com/googlei18n/sfntly/+log/b18b09b..1ef790a 1ef790a Add missing header from commit c9025ecc. 6917286 Merge pull request #58 from leizleiz/leizleiz-lotsofchecks 4f1aa49 Add ReadableFontData::kInvalidUnsigned. c9025ec Add more bounds checks in WritableFontData. dd23046 Return error values in ReadableFontData::Read*(). 813efeb Add a size limit for font tables. 08652be Add a nullptr check to GlyphTable::Glyph(). BUG= 641330 , 641446 , 641460 , 642300 TBR=behdad@chromium.org Review-Url: https://codereview.chromium.org/2316303003 Cr-Commit-Position: refs/heads/master@{#417229} [modify] https://crrev.com/8fe11cb88b21b7e1c3a8830249ab30c72d556bd7/DEPS
,
Sep 8 2016
,
Sep 9 2016
ClusterFuzz has detected this issue as fixed in range 417009:417261. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4863804200714240 Fuzzer: afl_sfntly_fuzzer Job Type: afl_chrome_asan Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000000 Crash State: sfntly::GlyphTable::Glyph::GetGlyph sfntly::SubsetterImpl::SubsetFont SfntlyWrapper::SubsetFont Regressed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=414211:414309 Fixed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=417009:417261 Minimized Testcase (0.81 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97Hxhz86XtWOdXUKmR55ogm8lfIihqJtbQgOzch7_z7olXjgok8FTEtFuzBm1MaRew1ToB3e7HFWo8N1K0l4pMtqUf0Ez8c1_T0NiFKuk8VZsWzeRiWiPmazH-5TXJCV9gKsC2fMW2Mu5jYwGS62dm7pld6Xw?testcase_id=4863804200714240 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Sep 9 2016
ClusterFuzz has detected this issue as fixed in range 417024:417277. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5606562490220544 Fuzzer: libfuzzer_sfntly_fuzzer Job Type: libfuzzer_chrome_asan Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000000 Crash State: Glyph SimpleGlyph sfntly::GlyphTable::Glyph::GetGlyph Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=414164:414272 Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=417024:417277 Minimized Testcase (0.77 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94jrZP4TV_U41lD2ZRUWJFgdkk2x4wVVj1wem56HCc9HYa0jOHOIHx0r6LJZEBRXKhebUY_qPu2Fwp2xJiEYqjyDW8tZLUxV5gLYYESEvS5m4T-N-tQCNMApXCmAvUMv3OtP6jJ4ZTA41_Q0WZm7LEKRa8SIw?testcase_id=5606562490220544 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Oct 18 2016
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Sep 5
|
||||||||||||
►
Sign in to add a comment |
||||||||||||
Comment 1 by durga.behera@chromium.org
, Aug 26 2016Labels: M-54 Te-Logged
Owner: thestig@chromium.org
Status: Assigned (was: Untriaged)