Crash in v8::base::OS::Abort |
|||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6078497295695872 Fuzzer: libfuzzer_v8_wasm_fuzzer Job Type: libfuzzer_chrome_asan Platform Id: linux Crash Type: UNKNOWN Crash Address: 0x000001d391f8 Crash State: v8::base::OS::Abort V8_Fatal v8::internal::wasm::WasmDecoder::OpcodeLength Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=426478:426526 Minimized Testcase (0.07 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94Dm0B5erdIfG82RlYSxs1EzPIPsWYTCT-y48jhjG_-xHZt0R1OPk5SPhu2DjTiwF5LvlNq4n8cE4qs4_X2sS345a4K0_ze0mG_mqCBTSKBn1P9IKkbXTAKT0aRfxs5mNvxf2udJdMHPL8PTzR-U5W34iGVxw?testcase_id=6078497295695872 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Oct 25 2016
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/1f6f345db29e96f6070ab8cef58e18ae7f879fe2 commit 1f6f345db29e96f6070ab8cef58e18ae7f879fe2 Author: aseemgarg <aseemgarg@chromium.org> Date: Tue Oct 25 22:03:17 2016 [wasm] fix simd opcode read and error case for bad simd opcodes BUG= chromium:658426 R=ahaas@chromium.org,titzer@chromium.org,gdeepti@chromium.org Review-Url: https://codereview.chromium.org/2447683004 Cr-Commit-Position: refs/heads/master@{#40572} [modify] https://crrev.com/1f6f345db29e96f6070ab8cef58e18ae7f879fe2/src/wasm/ast-decoder.cc [modify] https://crrev.com/1f6f345db29e96f6070ab8cef58e18ae7f879fe2/test/unittests/wasm/ast-decoder-unittest.cc
,
Oct 26 2016
,
Oct 27 2016
ClusterFuzz has detected this issue as fixed in range 427617:427664. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6078497295695872 Fuzzer: libfuzzer_v8_wasm_fuzzer Job Type: libfuzzer_chrome_asan Platform Id: linux Crash Type: UNKNOWN Crash Address: 0x000001d391f8 Crash State: v8::internal::wasm::WasmDecoder::OpcodeLength v8::internal::wasm::WasmFullDecoder::AnalyzeLoopAssignment v8::internal::wasm::WasmFullDecoder::PrepareForLoop Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=426478:426526 Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=427617:427664 Minimized Testcase (0.07 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96NbSI-_wq6vlzRuS1FRksCLZ0bgYARWcNbm4lg1AtkpBEL_zm_aIyCj0xpChFhnHWzDiwMkIcD6CHi1E2mrlHNNE_ZrHAc4xHfqM336wOK8BcfsJy1Jnijeyd3wqe_6sP7FDgxgt-RRREqnCaA9ZOMEfLP5w?testcase_id=6078497295695872 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||
►
Sign in to add a comment |
|||
Comment 1 by mmohammad@chromium.org
, Oct 21 2016Status: Assigned (was: Untriaged)