Undefined-shift in CFX_BitStream::GetBits |
||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5533298917113856 Fuzzer: libfuzzer_pdf_hint_table_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Undefined-shift Crash Address: Crash State: CFX_BitStream::GetBits CPDF_HintTables::ReadSharedObjHintTable HintTableForFuzzing::Fuzz Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=413192:413325 Minimized Testcase (0.14 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94gcElPZxwD7Bhc8yTYwlyA0hX9zc1Ow13r3QKjAG3DsI4SgLTlBHKv1Ne9ysOqVnVN3Ntti6Wuug8R3PQ2C6m0NGWlWNXu4it_qogyP6RvwRhkzz75YgcOPCUMTQ6NEk3aGxhAf62lHeNSNHB4-MYeZb_YCA?testcase_id=5533298917113856 Issue manually filed by: msrchandra See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Sep 2 2016
msrchandra: pdfium-deps-roller is a machine.
,
Oct 18 2016
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Mar 27 2017
ClusterFuzz has detected this issue as fixed in range 459701:459705. Detailed report: https://clusterfuzz.com/testcase?key=5533298917113856 Fuzzer: libfuzzer_pdf_hint_table_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Undefined-shift Crash Address: Crash State: CFX_BitStream::GetBits CPDF_HintTables::ReadSharedObjHintTable HintTableForFuzzing::Fuzz Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=413192:413325 Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=459701:459705 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv94AmRUm8-EalBMsWSnEQCHKQJQ0OitZb92koyRqJYAfs2eaxP9Jx06mNnz73fdVXCGkWifQ4XFmGIwcQN8C7kp_-w7IGdak5awzGNbCEeyoaferA5Qs05AKqLNTAstkQEZzoq9gEDZ7ZJmIo0KtUQMlvI2Q7FYplHmJ3ahW3bAa8jKf0ZuYIcMv9o8g4ydxJlOuOH0gxRXTw29JpgKBRD-JiZd0tze0ciG-f3hfxfXbbCBeCvx1HYpEdJRD_3JCLPZOUC464a1vmvpFi79g2JDrZmCU9wK5Gt05fLcuezqTp4Cx_9mQZDch2NmPoWsEfd5SWY1x9IZTdc-Dt2BoLAKJ1JCvxQgbS0kG6__OyJ2qMxtbpxM?testcase_id=5533298917113856 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Mar 27 2017
ClusterFuzz testcase 5533298917113856 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Mar 27 2017
I don't think this is fixed. Seems to be crashing now.
,
May 2 2017
Bulk-WontFixing these bugs. This was a bug on ClusterFuzz side, see bug 717534. We will start seeing new testcases auto-filed in a day or two. We can't leave these open as ClusterFuzz won't autoverify them after ClusterFuzz-Wrong label.
,
Sep 18 2017
We have made a bunch of changes on ClusterFuzz side, so resetting ClusterFuzz-Wrong label. |
||||||||
►
Sign in to add a comment |
||||||||
Comment 1 by msrchandra@chromium.org
, Sep 2 2016Components: Tools>Test>FindIt>NoResult Internals>Plugins>PDF
Labels: -Type-Bug findit-wrong Te-Logged Type-Bug-Regression
Owner: dsinclair@chromium.org
Status: Assigned (was: Untriaged)