Undefined-shift in sfntly::ReadableFontData::ReadByte |
||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6451442972098560 Fuzzer: libfuzzer_sfntly_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Undefined-shift Crash Address: Crash State: sfntly::ReadableFontData::ReadByte sfntly::ReadableFontData::ReadLong sfntly::Font::Builder::ReadHeader Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=414214:414310 Minimized Testcase (0.03 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97riY6sz1YHFwIqLQMitN4j-1dCYomn4hzd8X3HYAWZflh9kaQiswX5fUNNvcDEh1F7w6oaNlUuMQlJj_q7G9unpcHdGoy-g6D2_9zVcBMLQcpEa0wXgrkMu8aondPGMa19PYlnuGwFGClFAmYQlAAnAjeDmg?testcase_id=6451442972098560 Issue manually filed by: mmoroz See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Aug 27 2016
,
Sep 1 2016
,
Sep 8 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/8fe11cb88b21b7e1c3a8830249ab30c72d556bd7 commit 8fe11cb88b21b7e1c3a8830249ab30c72d556bd7 Author: thestig <thestig@chromium.org> Date: Thu Sep 08 09:11:00 2016 Roll DEPS for sfntly b18b09b..1ef790a https://chromium.googlesource.com/external/github.com/googlei18n/sfntly/+log/b18b09b..1ef790a 1ef790a Add missing header from commit c9025ecc. 6917286 Merge pull request #58 from leizleiz/leizleiz-lotsofchecks 4f1aa49 Add ReadableFontData::kInvalidUnsigned. c9025ec Add more bounds checks in WritableFontData. dd23046 Return error values in ReadableFontData::Read*(). 813efeb Add a size limit for font tables. 08652be Add a nullptr check to GlyphTable::Glyph(). BUG= 641330 , 641446 , 641460 , 642300 TBR=behdad@chromium.org Review-Url: https://codereview.chromium.org/2316303003 Cr-Commit-Position: refs/heads/master@{#417229} [modify] https://crrev.com/8fe11cb88b21b7e1c3a8830249ab30c72d556bd7/DEPS
,
Sep 8 2016
,
Sep 8 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/8fe11cb88b21b7e1c3a8830249ab30c72d556bd7 commit 8fe11cb88b21b7e1c3a8830249ab30c72d556bd7 Author: thestig <thestig@chromium.org> Date: Thu Sep 08 09:11:00 2016 Roll DEPS for sfntly b18b09b..1ef790a https://chromium.googlesource.com/external/github.com/googlei18n/sfntly/+log/b18b09b..1ef790a 1ef790a Add missing header from commit c9025ecc. 6917286 Merge pull request #58 from leizleiz/leizleiz-lotsofchecks 4f1aa49 Add ReadableFontData::kInvalidUnsigned. c9025ec Add more bounds checks in WritableFontData. dd23046 Return error values in ReadableFontData::Read*(). 813efeb Add a size limit for font tables. 08652be Add a nullptr check to GlyphTable::Glyph(). BUG= 641330 , 641446 , 641460 , 642300 TBR=behdad@chromium.org Review-Url: https://codereview.chromium.org/2316303003 Cr-Commit-Position: refs/heads/master@{#417229} [modify] https://crrev.com/8fe11cb88b21b7e1c3a8830249ab30c72d556bd7/DEPS
,
Sep 8 2016
ClusterFuzz has detected this issue as fixed in range 417039:417261. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6451442972098560 Fuzzer: libfuzzer_sfntly_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Undefined-shift Crash Address: Crash State: sfntly::ReadableFontData::ReadByte sfntly::ReadableFontData::ReadLong sfntly::Font::Builder::ReadHeader Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=414214:414310 Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=417039:417261 Minimized Testcase (0.03 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97riY6sz1YHFwIqLQMitN4j-1dCYomn4hzd8X3HYAWZflh9kaQiswX5fUNNvcDEh1F7w6oaNlUuMQlJj_q7G9unpcHdGoy-g6D2_9zVcBMLQcpEa0wXgrkMu8aondPGMa19PYlnuGwFGClFAmYQlAAnAjeDmg?testcase_id=6451442972098560 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
||||||
►
Sign in to add a comment |
||||||
Comment 1 by mmoroz@chromium.org
, Aug 26 2016Components: Internals>Skia>PDF
Labels: -Pri-1 Pri-2
Owner: thestig@chromium.org