Integer-overflow in BilinearInterp16 |
|||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5877549077102592 Fuzzer: libfuzzer_pdf_codec_icc_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: BilinearInterp16 EvaluateCLUTfloatIn16 _LUTevalFloat Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=420535:420584 Minimized Testcase (0.14 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94UPAqiOvSr1O7yuvjlwJO9R0hwP87hyGdtXVqE_yEREDMxjT4gG2mCVVnzViQVKDdboCtPwjZyD8ajZGSgHhsW-cnuGpdcHfUFuaQ2S3HAK53Vn0IDp_pdJzLSuWtTZOuLc95-feRQ2gE0QjJeqqUMTkozMQ?testcase_id=5877549077102592 Issue manually filed by: mmohammad See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Sep 24 2016
lcms is doing bilinear interpolation (16 bits precision) and the result value overflowed 16bits. I don't know what I can/should do.
,
Sep 26 2016
,
Sep 29 2016
,
Oct 11 2016
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Nov 23 2016
ClusterFuzz has detected this issue as fixed in range 433990:434098. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5877549077102592 Fuzzer: libfuzzer_pdf_codec_icc_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: BilinearInterp16 EvaluateCLUTfloatIn16 _LUTevalFloat Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=420535:420584 Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=433990:434098 Minimized Testcase (0.14 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94UPAqiOvSr1O7yuvjlwJO9R0hwP87hyGdtXVqE_yEREDMxjT4gG2mCVVnzViQVKDdboCtPwjZyD8ajZGSgHhsW-cnuGpdcHfUFuaQ2S3HAK53Vn0IDp_pdJzLSuWtTZOuLc95-feRQ2gE0QjJeqqUMTkozMQ?testcase_id=5877549077102592 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Nov 23 2016
ClusterFuzz testcase is verified as fixed, closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
|||||||
►
Sign in to add a comment |
|||||||
Comment 1 by mmohammad@chromium.org
, Sep 23 2016Status: Assigned (was: Untriaged)