Crash in sfntly::ReadableFontData::ReadableFontData |
||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6464714001612800 Fuzzer: libfuzzer_sfntly_fuzzer Job Type: libfuzzer_chrome_asan Platform Id: linux Crash Type: UNKNOWN Crash Address: 0x03e90000691a Crash State: sfntly::ReadableFontData::ReadableFontData WritableFontData sfntly::WritableFontData::Slice Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=414164:414272 Minimized Testcase (9.49 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94VDEabtHgu0iAd8WETk935IyLVIzhqaC-NSa043WUJjygLDvVuyYp6sY09QAaET-XKfquXTUOQN6nJ458Dgy21ikiCslQXLM81G09Rvfk1IN3Jjz9LV8OvUZ-i7xoZzLyYd9-Vhsr0nCeaUXVm3TrVCR1LfQ?testcase_id=6464714001612800 Issue manually filed by: mmoroz See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Aug 30 2016
:....(
,
Sep 1 2016
,
Sep 8 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/8fe11cb88b21b7e1c3a8830249ab30c72d556bd7 commit 8fe11cb88b21b7e1c3a8830249ab30c72d556bd7 Author: thestig <thestig@chromium.org> Date: Thu Sep 08 09:11:00 2016 Roll DEPS for sfntly b18b09b..1ef790a https://chromium.googlesource.com/external/github.com/googlei18n/sfntly/+log/b18b09b..1ef790a 1ef790a Add missing header from commit c9025ecc. 6917286 Merge pull request #58 from leizleiz/leizleiz-lotsofchecks 4f1aa49 Add ReadableFontData::kInvalidUnsigned. c9025ec Add more bounds checks in WritableFontData. dd23046 Return error values in ReadableFontData::Read*(). 813efeb Add a size limit for font tables. 08652be Add a nullptr check to GlyphTable::Glyph(). BUG= 641330 , 641446 , 641460 , 642300 TBR=behdad@chromium.org Review-Url: https://codereview.chromium.org/2316303003 Cr-Commit-Position: refs/heads/master@{#417229} [modify] https://crrev.com/8fe11cb88b21b7e1c3a8830249ab30c72d556bd7/DEPS
,
Sep 8 2016
,
Sep 8 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/8fe11cb88b21b7e1c3a8830249ab30c72d556bd7 commit 8fe11cb88b21b7e1c3a8830249ab30c72d556bd7 Author: thestig <thestig@chromium.org> Date: Thu Sep 08 09:11:00 2016 Roll DEPS for sfntly b18b09b..1ef790a https://chromium.googlesource.com/external/github.com/googlei18n/sfntly/+log/b18b09b..1ef790a 1ef790a Add missing header from commit c9025ecc. 6917286 Merge pull request #58 from leizleiz/leizleiz-lotsofchecks 4f1aa49 Add ReadableFontData::kInvalidUnsigned. c9025ec Add more bounds checks in WritableFontData. dd23046 Return error values in ReadableFontData::Read*(). 813efeb Add a size limit for font tables. 08652be Add a nullptr check to GlyphTable::Glyph(). BUG= 641330 , 641446 , 641460 , 642300 TBR=behdad@chromium.org Review-Url: https://codereview.chromium.org/2316303003 Cr-Commit-Position: refs/heads/master@{#417229} [modify] https://crrev.com/8fe11cb88b21b7e1c3a8830249ab30c72d556bd7/DEPS
,
Sep 8 2016
,
Sep 9 2016
ClusterFuzz has detected this issue as fixed in range 417024:417277. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6464714001612800 Fuzzer: libfuzzer_sfntly_fuzzer Job Type: libfuzzer_chrome_asan Platform Id: linux Crash Type: UNKNOWN Crash Address: 0x03e90000691a Crash State: sfntly::ReadableFontData::ReadableFontData WritableFontData sfntly::WritableFontData::Slice Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=414164:414272 Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=417024:417277 Minimized Testcase (9.49 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94VDEabtHgu0iAd8WETk935IyLVIzhqaC-NSa043WUJjygLDvVuyYp6sY09QAaET-XKfquXTUOQN6nJ458Dgy21ikiCslQXLM81G09Rvfk1IN3Jjz9LV8OvUZ-i7xoZzLyYd9-Vhsr0nCeaUXVm3TrVCR1LfQ?testcase_id=6464714001612800 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
||||||
►
Sign in to add a comment |
||||||
Comment 1 by mmoroz@chromium.org
, Aug 30 2016Components: Internals>Skia
Owner: thestig@chromium.org