New issue
Advanced search Search tips

Issue 657466 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner:
Closed: Jan 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Integer-overflow in _hb_ot_shape_fallback_spaces

Project Member Reported by ClusterFuzz, Oct 19 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5696563500548096

Fuzzer: inferno_twister
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  _hb_ot_shape_fallback_spaces
  hb_ot_position_default
  hb_ot_position
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=370022:370027

Minimized Testcase (0.04 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv94xu9RhkOf5Ij7rR2M8RmpJkn3OuCrJ9LAUozOWfUDvSgj1jW-vCZBkPfsvfe0aQ5SDzbOQVTX1QzzwKefmMC5MeYcnPfbVMMqFxW_GEqiKoVCvvduJYX8fQ-8pd8mTwkxPbaG3X7_PTM1xMh40W3e-wyFjyA?testcase_id=5696563500548096
<h6 style='font: 11143in/53 Ahem; '>J&#x205f;


Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Owner: drott@chromium.org
Status: Assigned (was: Untriaged)
drott@ could you please look into this.please feel free to re-assigned back if needed. thanks in advance !

Comment 2 by drott@chromium.org, Oct 20 2016

Cc: behdad@chromium.org
Components: Blink>Fonts
Project Member

Comment 3 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Cc: -behdad@chromium.org drott@chromium.org
Owner: behdad@chromium.org
Project Member

Comment 5 by ClusterFuzz, Oct 1 2017

Labels: Test-Predator-AutoComponents
Automatically applying components based on information from OWNERS files. If this seems incorrect, please apply the Test-Predator-Wrong-Components label.
Labels: -Test-Predator-AutoComponents Test-Predator-Auto-Components

Comment 7 by e...@chromium.org, Jan 30 2018

Status: WontFix (was: Assigned)
Project Member

Comment 8 by ClusterFuzz, Feb 6 2018

Labels: Needs-Feedback
ClusterFuzz testcase 5696563500548096 is still reproducing on tip-of-tree build (trunk).

If this testcase was not reproducible locally or unworkable, ignore this notification and we will file another bug soon with hopefully a better and workable testcase.

Otherwise, if this is not intended to be fixed (e.g. this is an intentional crash), please add ClusterFuzz-Ignore label to prevent future bug filing with similar crash stacktrace.
Cc: ebra...@gnu.org

Sign in to add a comment