New issue
Advanced search Search tips

Issue 670669 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Dec 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Security



Sign in to add a comment

Crash in SkBitmap::copyPixelsTo

Project Member Reported by ClusterFuzz, Dec 2 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6040526102200320

Fuzzer: inferno_sampler
Job Type: linux_asan_chrome_media
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 0x7fb157239ff0
Crash State:
  SkBitmap::copyPixelsTo
  blink::ImageFrameGenerator::decodeAndScale
  blink::DecodingImageGenerator::onGetPixels
  
Recommended Security Severity: Medium


Minimized Testcase (0.03 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95LsZvl2GyRlgKjoR_Vla7oeUS6SB5QNYxPFW11L6Pq-Ks0UiUGftLyZqs4jWxH2bKYM-4hkRnybZmoWD1upiEP6DG3lrcFJG9Blpxu0-Ov7i4XD7EBtxVQCbkAjAVnDjqrob0qaDdxjI3n94s4N5lnvO1spg?testcase_id=6040526102200320

Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Project Member

Comment 1 by sheriffbot@chromium.org, Dec 2 2016

Labels: M-55
Project Member

Comment 2 by sheriffbot@chromium.org, Dec 2 2016

Labels: Pri-1
Cc: kcc@chromium.org infe...@chromium.org
Status: WontFix (was: Untriaged)
Verified that this is another SIGBUS (OOM) (same as  bug 633475  and  bug 598724  and others), but the report says SEGV.

Received signal 7 BUS_ADRERR 7f90181a3ff0

kcc, if we can't change the report output to give us a way to distinguish between SIGBUS and SIGSEGV, would something behind an ASAN_OPTIONS flag be possible?
Project Member

Comment 4 by sheriffbot@chromium.org, Mar 11 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment