New issue
Advanced search Search tips

Issue 660395 link

Starred by 1 user

Issue metadata

Status: Verified
Owner: ----
Closed: Jan 2017
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Out-of-memory in libxml_xml_read_memory_fuzzer

Project Member Reported by ClusterFuzz, Oct 28 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4672570252328960

Fuzzer: libfuzzer_libxml_xml_read_memory_fuzzer
Job Type: libfuzzer_chrome_msan
Platform Id: linux

Crash Type: Out-of-memory
Crash Address: 
Crash State:
  libxml_xml_read_memory_fuzzer
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_msan&range=395689:395794

Minimized Testcase (0.19 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv970LL8JXjitKd_RAlba1GcAJEE03WPgZclPoVOUp8t1ZS_DP8BoNQtkmSGKlM9DRhZkHTlFPQ9oXeE9zQVrLpBJbqH_B-1C5mCvn1L9wTkvBSK4tUmFkVhSKOKTDrI8h3wQEJO0x4-lbnXMmH-YCYr0weIJCg?testcase_id=4672570252328960
<!DOCTYPE test [
<!ENTITY % xx '         &#37;zz;
<![INCLUDE[
&#37;&#37;zz;<!EL7;z37;z
;'>
<!ENTITY % zz '      &#37;zz;
<![INCLUDE&#60;!ENTITY<?xDOCwYPEm~?>' >
%x;%xx;%xx;%xx;%xr;%xxx;wx;%xx;%xfo


Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 
Project Member

Comment 1 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 2 by ClusterFuzz, Jan 17 2017

ClusterFuzz has detected this issue as fixed in range 443824:443836.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4672570252328960

Fuzzer: libfuzzer_libxml_xml_read_memory_fuzzer
Job Type: libfuzzer_chrome_msan
Platform Id: linux

Crash Type: Out-of-memory (exceeds 1024 MB)
Crash Address: 
Crash State:
  libxml_xml_read_memory_fuzzer
  
Sanitizer: memory (MSAN)

Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_msan&range=395689:395794
Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_msan&range=443824:443836

Minimized Testcase (0.19 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv970LL8JXjitKd_RAlba1GcAJEE03WPgZclPoVOUp8t1ZS_DP8BoNQtkmSGKlM9DRhZkHTlFPQ9oXeE9zQVrLpBJbqH_B-1C5mCvn1L9wTkvBSK4tUmFkVhSKOKTDrI8h3wQEJO0x4-lbnXMmH-YCYr0weIJCg?testcase_id=4672570252328960
<!DOCTYPE test [
<!ENTITY % xx '         &#37;zz;
<![INCLUDE[
&#37;&#37;zz;<!EL7;z37;z
;'>
<!ENTITY % zz '      &#37;zz;
<![INCLUDE&#60;!ENTITY<?xDOCwYPEm~?>' >
%x;%xx;%xx;%xx;%xr;%xxx;wx;%xx;%xfo


See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 3 by ClusterFuzz, Jan 17 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Untriaged)
ClusterFuzz testcase 4672570252328960 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment