Issue metadata
Sign in to add a comment
|
Use-of-uninitialized-value in AddValueForStrcmp |
||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5892925898883072 Fuzzer: libfuzzer_net_host_resolver_impl_fuzzer Job Type: libfuzzer_chrome_msan Platform Id: linux Crash Type: Use-of-uninitialized-value Crash Address: Crash State: AddValueForStrcmp pr_UnlockedFindLibrary pr_LoadLibraryByPathname Recommended Security Severity: Medium Minimized Testcase (0.01 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94S1xuW60jFYo-q0YCOMHb1TDo9Q6n6FQKCghTBzTBstRRXZlspU4_uJ5xtpxkD7yZi9EiRnTZdLFcLRlkrmDGxkB_bUg_QSP0MjVzCF4HYwAnUjndxdutg5Qf1ULvzT6ThDcOeP64U5lYJmIANn7F91TD0jw?testcase_id=5892925898883072 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Oct 1 2016
,
Oct 3 2016
rsleevi@ can you please have a look at this, and upstream a bug if you think it is appropriate? This is fuzzing the DNS resolver but looks like it causes a use of uninitialized memory in NSS.
,
Oct 6 2016
ClusterFuzz has detected this issue as fixed in range 423366:423427. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5892925898883072 Fuzzer: libfuzzer_net_host_resolver_impl_fuzzer Job Type: libfuzzer_chrome_msan Platform Id: linux Crash Type: Use-of-uninitialized-value Crash Address: Crash State: AddValueForStrcmp pr_UnlockedFindLibrary pr_LoadLibraryByPathname Recommended Security Severity: Medium Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_msan&range=423366:423427 Minimized Testcase (0.01 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94S1xuW60jFYo-q0YCOMHb1TDo9Q6n6FQKCghTBzTBstRRXZlspU4_uJ5xtpxkD7yZi9EiRnTZdLFcLRlkrmDGxkB_bUg_QSP0MjVzCF4HYwAnUjndxdutg5Qf1ULvzT6ThDcOeP64U5lYJmIANn7F91TD0jw?testcase_id=5892925898883072 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Oct 6 2016
ClusterFuzz testcase is verified as fixed, closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Oct 6 2016
MSAn bugs can be flaky, reopening.
,
Oct 15 2016
rsleevi: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 30 2016
rsleevi: Uh oh! This issue still open and hasn't been updated in the last 29 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Nov 28 2016
Friendly ping rsleevi. Any update on this issue?
,
Nov 28 2016
Marking it available. Not sure how it even ended up back in my queue, but I'd definitely muted this. At 'best', it's an upstream bug involving a third-part library that we don't really work on anymore post-BoringSSL (but still use, as part of the Linux Standard Base). I'm punting to aarya@ first re: MSAN bugs being flaky, but also because it looks to be a dupe of Issue 653461 (see Comment #13 for why there's no movement on this class of bugs)
,
Nov 28 2016
,
Nov 30 2016
WontFixing this since it's likely to be an instrumentation issue.
,
Mar 9 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by sheriffbot@chromium.org
, Oct 1 2016