Crash in media::VpxVideoDecoder::DecodeBuffer |
||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5069470420959232 Fuzzer: libfuzzer_media_vpx_video_decoder_fuzzer Job Type: libfuzzer_chrome_asan_debug Platform Id: linux Crash Type: UNKNOWN Crash Address: 0x03e900005bdb Crash State: media::VpxVideoDecoder::DecodeBuffer media::VpxVideoDecoder::Decode Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=395717:395804 Minimized Testcase (0.01 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv97jCw7PTTMGSxxyDBLFvtDUcIZGkbThyM-2_LdzKjmQHeZduLQjrGkukceH5kvfpVwnLhyl6xKnrQvj5JN3_4yHFC2HQb2ONvjIYzkpYYXAdkswuNdcOqUtrppxfkHh4TAV7amEKUZ5eaZt1yYEIbn-3PSWeg?testcase_id=5069470420959232 0123456789 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Oct 21 2016
nyerramilli@, libFuzzer is a bug finding tool and it has found a bug in media::VpxVideoDecoder::DecodeBuffer. Please find the appropriate owner there. [0831/231618:FATAL:vpx_video_decoder.cc(381)] Check failed: state_ != kUninitialized (0 vs. 0)Called Decode() before successful Initialize()
,
Oct 27 2016
dalecurtis@, could you please help us to find an owner?
,
Oct 27 2016
,
Oct 27 2016
Issue is that the fuzzer never verifies initialize succeeded. It just assumes it does.
,
Oct 31 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/417f6041baad6fa9607a0e96aeab950c7be3f5f5 commit 417f6041baad6fa9607a0e96aeab950c7be3f5f5 Author: dalecurtis <dalecurtis@chromium.org> Date: Mon Oct 31 19:03:03 2016 Fix VpxVideoDecoder fuzzer: check initialize and wait for decode. Decode() can't be called if initialize fails and just because the RunLoop is idle it does not mean the decode has finished. BUG= 657446 TEST=fuzzer test Review-Url: https://codereview.chromium.org/2453013005 Cr-Commit-Position: refs/heads/master@{#428763} [modify] https://crrev.com/417f6041baad6fa9607a0e96aeab950c7be3f5f5/media/filters/vpx_video_decoder_fuzzertest.cc
,
Nov 3 2016
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
||||||
►
Sign in to add a comment |
||||||
Comment 1 by nyerramilli@chromium.org
, Oct 21 2016Labels: M-56
Owner: kcc@chromium.org
Status: Assigned (was: Untriaged)