New issue
Advanced search Search tips

Issue 726671 link

Starred by 2 users

Issue metadata

Status: Verified
Owner:
Closed: Nov 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Integer-overflow in position_cluster

Project Member Reported by ClusterFuzz, May 26 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=6079723930386432

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  position_cluster
  hb_ot_position
  hb_ot_shape_internal
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=434178:434216

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6079723930386432


Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: drott@chromium.org
Owner: behdad@chromium.org
Assigning to behdad@ for triage. Note that it's possible this has already been fixed upstream and Chromium's copy may need to be updated. It's also possible that this is benign. If so we should mark it with the right fuzz labels for that.
Components: Blink>Fonts
Labels: M-63 Test-Predator-Wrong-CLs
Status: Assigned (was: Untriaged)
Project Member

Comment 3 by ClusterFuzz, Oct 1 2017

Labels: Test-Predator-AutoComponents
Automatically applying components based on information from OWNERS files. If this seems incorrect, please apply the Test-Predator-Wrong-Components label.
Project Member

Comment 4 by ClusterFuzz, Nov 7 2017

ClusterFuzz has detected this issue as fixed in range 514348:514378.

Detailed report: https://clusterfuzz.com/testcase?key=6079723930386432

Fuzzer: inferno_twister_c
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  position_cluster
  hb_ot_position
  hb_ot_shape_internal
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=434178:434216
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=514348:514378

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6079723930386432

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 5 by ClusterFuzz, Nov 7 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 6079723930386432 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Labels: -Test-Predator-AutoComponents Test-Predator-Auto-Components

Sign in to add a comment