New issue
Advanced search Search tips

Issue 660196 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner:
Closed: Jan 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Integer-overflow in OT::propagate_attachment_offsets

Project Member Reported by ClusterFuzz, Oct 27 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5812273412308992

Fuzzer: inferno_twister
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  OT::propagate_attachment_offsets
  OT::GPOS::position_finish_offsets
  hb_ot_position_complex
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=377242:377255

Minimized Testcase (3.01 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96M9xu50kZXH54OmulwNYpAcodhiKJOZgUphQGl1OO4OHcw3fqX9GK5siWEAbmrSAhAYne-7tDu8-tnz_fq1no5q8BgfpTjVNZGAmlqZyVtNkmBvSRHvUopneOJMBC14MFRqM2flaXILqdnQiyZ8QiPpw9JZw?testcase_id=5812273412308992

Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Owner: drott@chromium.org
Status: Assigned (was: Untriaged)
drott @ could you please look into this.please feel free to re-assigned back if needed. thanks in advance !

Comment 2 by drott@chromium.org, Oct 27 2016

Owner: behdad@chromium.org
Project Member

Comment 3 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 4 by ClusterFuzz, Oct 1 2017

Components: Blink>Fonts
Labels: Test-Predator-AutoComponents
Automatically applying components based on information from OWNERS files. If this seems incorrect, please apply the Test-Predator-Wrong-Components label.
Labels: -Test-Predator-AutoComponents Test-Predator-Auto-Components

Comment 6 by e...@chromium.org, Jan 29 2018

Status: WontFix (was: Assigned)
Project Member

Comment 7 by ClusterFuzz, Feb 5 2018

Labels: Needs-Feedback
ClusterFuzz testcase 5812273412308992 is still reproducing on tip-of-tree build (trunk).

If this testcase was not reproducible locally or unworkable, ignore this notification and we will file another bug soon with hopefully a better and workable testcase.

Otherwise, if this is not intended to be fixed (e.g. this is an intentional crash), please add ClusterFuzz-Ignore label to prevent future bug filing with similar crash stacktrace.
Cc: ebra...@gnu.org

Sign in to add a comment