New issue
Advanced search Search tips

Issue 737512 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 729673
Owner:
Closed: Jul 2017
Cc:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 1
Type: Bug



Sign in to add a comment

Out-of-memory in blink_png_decoder_fuzzer

Project Member Reported by ClusterFuzz, Jun 28 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=4876337839079424

Fuzzer: libFuzzer_blink_png_decoder_fuzzer
Job Type: mac_libfuzzer_chrome_asan
Platform Id: mac

Crash Type: Out-of-memory (exceeds 2048 MB)
Crash Address: 
Crash State:
  blink_png_decoder_fuzzer
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=mac_libfuzzer_chrome_asan&range=441566:441775

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4876337839079424


Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 
Cc: scroggo@chromium.org
Labels: Test-Predator-Wrong-CLs M-61
Owner: csharrison@chromium.org
Status: Assigned (was: Untriaged)
Predator and CL did not provide any possible suspects.
Using Code Search for the file, "blink_png_decoder_fuzzer" assigning to the concern owner.
Suspecting Commit#
https://chromium.googlesource.com/chromium/src/+/fda3f3decbf18cec68fed81b8f48add43c3c64b2

@csharrison -- Could you please look into the issue, kindly re-assign if this is not related to your changes.
Thank You.
Cc: -scroggo@chromium.org csharrison@chromium.org
Owner: scroggo@chromium.org
Moving ownership to scroggo who wrote the fuzzer and who is also in the regression range. My guess (without knowing how png really works) is that this is wontfix though.
This looks like  issue 729673 . Will double check when back in the office.
Mergedinto: 729673
Status: Duplicate (was: Assigned)
Yep, duplicate.
Project Member

Comment 5 by ClusterFuzz, Jul 8 2017

ClusterFuzz has detected this issue as fixed in range 476905:485054.

Detailed report: https://clusterfuzz.com/testcase?key=4876337839079424

Fuzzer: libFuzzer_blink_png_decoder_fuzzer
Job Type: mac_libfuzzer_chrome_asan
Platform Id: mac

Crash Type: Out-of-memory (exceeds 2048 MB)
Crash Address: 
Crash State:
  blink_png_decoder_fuzzer
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=mac_libfuzzer_chrome_asan&range=441566:441775
Fixed: https://clusterfuzz.com/revisions?job=mac_libfuzzer_chrome_asan&range=476905:485054

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4876337839079424


See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Sign in to add a comment