New issue
Advanced search Search tips

Issue 666631 link

Starred by 0 users

Issue metadata

Status: Verified
Owner:
Closed: Mar 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug

Blocking:
issue 673919



Sign in to add a comment

Undefined-shift in get_ur_golomb_jpegls

Project Member Reported by ClusterFuzz, Nov 18 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5786072283086848

Fuzzer: libfuzzer_media_pipeline_integration_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Undefined-shift
Crash Address: 
Crash State:
  get_ur_golomb_jpegls
  get_sr_golomb_flac
  decode_residuals
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=413192:413325

Minimized Testcase (2.05 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94loWV5nVea5hDHcAvWj81_X-MofU71D-REaxd8buQj9blULpC9ylJdfHtoh0Y5IguhDyWcYfDIbba_TL5c2gecEIcM7qMwkAVWfMVDE84U6ZJ-PVgQ2qas02bnIRZm6Zlaz_OpW_Ihz45eBc4pR0Fp_zbneg?testcase_id=5786072283086848

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 

Comment 1 by ajha@chromium.org, Nov 18 2016

Components: Internals>Media>FFmpeg
Labels: M-55
Cc: wolenetz@chromium.org
Project Member

Comment 3 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Cc: -wolenetz@chromium.org
Owner: wolenetz@chromium.org
Status: Assigned (was: Untriaged)
Matt, can you take a look and re-assign appropriately if needed. 
Cc: wolenetz@chromium.org
Labels: -M-55 M-56
Owner: hubbe@chromium.org
=> hubbe@ for looking at fixing this in M-57 roll ( bug 673919 ). Depending on severity, might need to be merged to M56 eventually.
Blocking: 673919
Owner: liber...@chromium.org
=> liberato@'s doing the M-57 roll instead.
Project Member

Comment 8 by ClusterFuzz, Mar 22 2017

ClusterFuzz has detected this issue as fixed in range 458516:458571.

Detailed report: https://clusterfuzz.com/testcase?key=5786072283086848

Fuzzer: libfuzzer_media_pipeline_integration_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Undefined-shift
Crash Address: 
Crash State:
  get_ur_golomb_jpegls
  get_sr_golomb_flac
  decode_residuals
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=413192:413325
Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=458516:458571

Reproducer Testcase: https://clusterfuzz.com/download/AMIfv95mRq5KXBiv0BuSenE0anGvlx-2UhG6_ctVFao6-52enUXCI1nlNFIurlbVXgg3J83bS1xC4AWN2nvZ1szqZY78HteS5g6u9z-7DsfO-X8Np6LdFKH1vb3MhzuUglZ1ODPkEqq-nWPKudLQBZk-eBBEKeId6HWiCQgNX3o_LcGMiKpEPEA8Taqhw9O-vDsTU8LhyEBa-gU_5AVvgtRtYMpNih213DgjeLw4XxJivD7bRxvkvVljcFI-seZag1pJ8rtKMiQn8M2AejZcocShisNLjpW1ACtYvpHlPtmXcdhHBLd_6897Gnz0RUmsM47ICIxGFGCCOgYfki4QvhMNRdP0TfPF1GvQPdNZQyxKuGB0l6DAwNo?testcase_id=5786072283086848


See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 9 by ClusterFuzz, Mar 22 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 5786072283086848 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment