New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 728569 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Jul 2017
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 3
Type: Bug



Sign in to add a comment

Null-dereference WRITE in SkImageFilterCache::Get

Project Member Reported by ClusterFuzz, Jun 1 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=4957272613847040

Fuzzer: sugoi_filter_fuzzer
Job Type: linux_asan_filter_fuzz_stub_32bit
Platform Id: linux

Crash Type: Null-dereference WRITE
Crash Address: 0x00000004
Crash State:
  SkImageFilterCache::Get
  SkImageFilter::~SkImageFilter
  SkOffsetImageFilter::~SkOffsetImageFilter
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_asan_filter_fuzz_stub_32bit&range=391407:391453

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4957272613847040


Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: ranjitkan@chromium.org
Labels: M-61 Test-Predator-Correct-CLs
Owner: mtklein@chromium.org
Status: Assigned (was: Untriaged)
Assigning to the concern owner from Predator results --
The result is a list of CLs that change the crashed files. 

Author: mtklein
Project: chromium-skia
Changelist: https://chromium.googlesource.com/skia.git/+/b37c68ad42ae7880e702649a01655165c7e12acc
Time: Wed May 04 20:57:30 2016
The CL last changed line 37 of file SkOnce.h, which is stack frame 3. 

@mtklein: Assigning to you, kindly take a look into it. Please help us to find an owner if not with respect to your change.

Thanks.!

Labels: -Pri-1 Pri-3
This is probably not a problem with SkOnce.  I also don't see any interesting Skia changes in the regression range.

If you've got another candidate to assign this to, you may want to.  I'm happy to investigate this at some point, but it doesn't seem like a regression.

What's Predator?
Project Member

Comment 3 by ClusterFuzz, Jul 13 2017

ClusterFuzz has detected this issue as fixed in range 485950:486007.

Detailed report: https://clusterfuzz.com/testcase?key=4957272613847040

Fuzzer: sugoi_filter_fuzzer
Job Type: linux_asan_filter_fuzz_stub_32bit
Platform Id: linux

Crash Type: Null-dereference WRITE
Crash Address: 0x00000004
Crash State:
  SkImageFilterCache::Get
  SkImageFilter::~SkImageFilter
  SkOffsetImageFilter::~SkOffsetImageFilter
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_asan_filter_fuzz_stub_32bit&range=391407:391453
Fixed: https://clusterfuzz.com/revisions?job=linux_asan_filter_fuzz_stub_32bit&range=485950:486007

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4957272613847040


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 4 by ClusterFuzz, Jul 13 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 4957272613847040 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment