New issue
Advanced search Search tips

Issue 651293 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner: ----
Closed: Sep 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Use-of-uninitialized-value in _start

Project Member Reported by ClusterFuzz, Sep 29 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5819203523444736

Fuzzer: libfuzzer_icu_unicode_string_codepage_create_fuzzer
Job Type: libfuzzer_chrome_msan
Platform Id: linux

Crash Type: Use-of-uninitialized-value
Crash Address: 
Crash State:
  _start
  
Recommended Security Severity: Medium

Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_msan&range=421508:421597

Minimized Testcase (0.00 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96G_7N3C8IMhO0YbAVMCo2S_0tB8_lhapagF2fE8xLbbybM3av34KGrKfllnmDCwM2vny3sDV5T6K_58elZqtBKK1_YQ9vdeH6z95KN6nMdzEA4E4wyukyysqzzUAZzpo5u82DHZlRVRqdCWUENJWikjAY5DQ?testcase_id=5819203523444736

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 
Project Member

Comment 1 by sheriffbot@chromium.org, Sep 29 2016

Labels: M-55
Project Member

Comment 2 by sheriffbot@chromium.org, Sep 29 2016

Labels: ReleaseBlock-Beta
This issue is a security regression. If you are not able to fix this quickly, please revert the change that introduced it.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 3 by sheriffbot@chromium.org, Sep 29 2016

Labels: Pri-1

Comment 4 by kenrb@chromium.org, Sep 29 2016

Cc: mmoroz@chromium.org infe...@chromium.org
Owner: kcc@chromium.org
Status: Assigned (was: Untriaged)
kcc@: There are multiple use-of-uninitialized-value reports that I don't think correspond to Chromium bugs, so I am suspecting they might be libfuzzer issues. The regression range for all of these includes a libfuzzer roll. https://chromium.googlesource.com/chromium/src/+/b8a5efc4d6c7100e6b889fb567c71a0c29fbf35b

Are you able to look into this?

Comment 5 by kenrb@chromium.org, Sep 29 2016

 Issue 651313  has been merged into this issue.

Comment 6 by kenrb@chromium.org, Sep 29 2016

 Issue 651294  has been merged into this issue.

Comment 7 by kenrb@chromium.org, Sep 29 2016

 Issue 651286  has been merged into this issue.

Comment 8 by kcc@chromium.org, Sep 29 2016

This should have been fixed already by new libFuzzer roll. Max? 

Comment 9 by gov...@chromium.org, Sep 29 2016

This bug is reported as M55 Beta blocker.Please try to resolve this before M55 branch on Oct 6th,2016 so it has enough baking time in Dev.


Comment 10 by aarya@google.com, Sep 29 2016

Should be fixed by https://codereview.chromium.org/2381073002/. Will let CF autoclose this tonight.

Comment 11 by kenrb@chromium.org, Sep 30 2016

Cc: kenrb@chromium.org
Status: ExternalDependency (was: Assigned)
CF doesn't think that roll fixes the problem.

I am going to keep duping uninitialized value reports into this one until it gets resolved. If any of those reports still remain open after this is closed then I can dedupe.

Comment 12 by kenrb@chromium.org, Sep 30 2016

 Issue 651632  has been merged into this issue.

Comment 13 by kenrb@chromium.org, Sep 30 2016

 Issue 651849  has been merged into this issue.

Comment 14 by aarya@google.com, Sep 30 2016

This is fixed, see CF is trying to find progression range.

[2016-09-30 07:19:45] clusterfuzz-linux-0002: Progression task started: r422084.
[2016-09-30 08:10:59] clusterfuzz-linux-0002: Progression task in-progress: Testing r421597:r422084.
Project Member

Comment 15 by ClusterFuzz, Sep 30 2016

ClusterFuzz has detected this issue as fixed in range 421846:421912.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5819203523444736

Fuzzer: libfuzzer_icu_unicode_string_codepage_create_fuzzer
Job Type: libfuzzer_chrome_msan
Platform Id: linux

Crash Type: Use-of-uninitialized-value
Crash Address: 
Crash State:
  _start
  
Recommended Security Severity: Medium

Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_msan&range=421508:421597
Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_msan&range=421846:421912

Minimized Testcase (0.00 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96G_7N3C8IMhO0YbAVMCo2S_0tB8_lhapagF2fE8xLbbybM3av34KGrKfllnmDCwM2vny3sDV5T6K_58elZqtBKK1_YQ9vdeH6z95KN6nMdzEA4E4wyukyysqzzUAZzpo5u82DHZlRVRqdCWUENJWikjAY5DQ?testcase_id=5819203523444736

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Comment 16 by kenrb@chromium.org, Sep 30 2016

Labels: -Type-Bug-Security -ReleaseBlock-Beta -M-55 -Restrict-View-SecurityTeam -Security_Severity-Medium -Security_Impact-Head Type-Bug
Owner: ----
Status: Fixed (was: ExternalDependency)

Sign in to add a comment