Integer-overflow in XRect_roundOut |
||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=6703684391272448 Fuzzer: ifratric-browserfuzzer-v3 Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: XRect_roundOut SkScan::AntiFillXRect aa_square_proc Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=456626:457730 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv97-cuLnyHFg4FUO94gmqDhapxAFgk3Uj5mlZDtdQat2lH1ZpN8pQCuXuEIXLhiZvaXQUjPjrfj6e0Q4MCTDKiEfvFkv1obq1GGSkE77HB7Ia7eeePJDa09wUPQx84nUJCKhIsPyp3xLLTJm8E1GXt79ZlkFvUge4VJLoQn4TDyUXUz1e_uR_m4yJFJCJZXL54CsfVlTdPYfHkW1NaB5XzvhLlqWT7eZ7_8g4OVxb-d03PkOLgcuGinuluD_KdiwU0r2XRcN5uHdGL3r5_O__0SDRA-Cdpgxej5-TszN_OIw4HzKi_XrDIsGYqpF5uS1YriJx2ao9L_72KabHLR3HFKoJnB81ODcdOEyRF9ptC9vTFPZNSwjuS1KEl6BV3-m60KGdy4oRNQfOY54QU6Sh2VMLpJ_ng?testcase_id=6703684391272448 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Apr 3 2017
Through code search on file SkScan_Antihair.cpp, suspected CL is https://skia.googlesource.com/skia.git/+/20fbada09bbcc31d128959a8e4d4cac499741505 jbroman@, could you please take a look? Thank you.
,
Apr 4 2017
I don't see how that CL could be the cause. Assigning to caryclark@ (current Skia sheriff AFAICT) for triage.
,
Apr 4 2017
There's no process at the moment to isolate this within Skia. Taking myself off as the owner as I am not able to help out at this time.
,
Apr 7 2017
Lowering severity on non-security int overflows as we need to prioritize other issues at this time.
,
May 25 2017
ClusterFuzz has detected this issue as fixed in range 474169:474185. Detailed report: https://clusterfuzz.com/testcase?key=6703684391272448 Fuzzer: ifratric-browserfuzzer-v3 Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: XRect_roundOut SkScan::AntiFillXRect aa_square_proc Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=456626:457730 Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=474169:474185 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6703684391272448 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
May 25 2017
ClusterFuzz testcase 6703684391272448 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
||||||
►
Sign in to add a comment |
||||||
Comment 1 by msrchandra@chromium.org
, Apr 3 2017