Integer-overflow in shadeSpan_linear_repeat |
|||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5896889313787904 Fuzzer: ifratric-browserfuzzer-v3 Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: shadeSpan_linear_repeat SkLinearGradient::LinearGradientContext::shadeSpan SkARGB32_Shader_Blitter::blitMask Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=451439:451445 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv96Zkr26bbyDSw1D9W4olhB3re2vzPbu4FmKTLqK5Nl2A3L4ay66Fip_f-6mIxBT1Ad80wQtip5FbS6pan7NC79RcePejAIkBWu085hpp8j-fP7u3yGawb3xC5-II7AgCbkm0dU48jH2KmrLcTGNMVuxFeaAJpEtX_ZAQviPI7x79n4jhA_YD4yyfBTydsMwRwvkknaw1qTAgk9qerkZsBWY7sYQ7rmusTpL5PWrSAlMbvJKjfEyYgTaupRaH3AXfld1CUv3SYkhk50TjrKNmydOeBuX-cQ1bzXfH0SqCPuOIeIe2KTqQL1-nmuAAbaRHyj-27feyFuMYkbSq-UV_LoduT_PGB3_3XQvS1zuvwIqe2IlujpJZkxqueR7eN4Rk0nVvpIov90Kj9OShLpWrPuiq1zEqg?testcase_id=5896889313787904 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Mar 28 2017
,
Aug 31 2017
ClusterFuzz has detected this issue as fixed in range 498602:498620. Detailed report: https://clusterfuzz.com/testcase?key=5896889313787904 Fuzzer: ifratric-browserfuzzer-v3 Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: shadeSpan_linear_repeat SkLinearGradient::LinearGradientContext::shadeSpan SkARGB32_Shader_Blitter::blitMask Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=451439:451445 Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=498602:498620 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5896889313787904 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Aug 31 2017
ClusterFuzz testcase 5896889313787904 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
|||
►
Sign in to add a comment |
|||
Comment 1 by msrchandra@chromium.org
, Mar 20 2017Labels: Test-Predator-Wrong-CLs M-59