New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 738425 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Jul 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug

Blocking:
issue 62400



Sign in to add a comment

Out-of-memory in pdfium_xfa_fuzzer

Project Member Reported by ClusterFuzz, Jun 30 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=4715643785183232

Fuzzer: libFuzzer_pdfium_xfa_fuzzer
Job Type: libfuzzer_chrome_msan
Platform Id: linux

Crash Type: Out-of-memory (exceeds 2048 MB)
Crash Address: 
Crash State:
  pdfium_xfa_fuzzer
  
Sanitizer: memory (MSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_msan&range=459141:459202

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4715643785183232


Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 
Cc: msrchandra@chromium.org
Labels: M-60 Test-Predator-Wrong
Owner: dsinclair@chromium.org
Status: Assigned (was: Untriaged)
Predator did not provide any possible suspects.
Assigning to concern from CL --
https://chromium.googlesource.com/chromium/src/+log/e1b5abb6552410cef4b2de74624b24a32a3081a2..c05f3475ecaae3f033bb4ee8cfe139b8c4d0b897?pretty=fuller

Suspecting Commit#
https://chromium.googlesource.com/chromium/src/+/034ca9381180401b9b25eac088babf7fdae847d8

@dsinclair -- Could you please look into the issue, kindly re-assign if this is not related to your changes.
Thank You.
Components: Internals>Plugins>PDF
Blocking: 62400
Cc: dsinclair@chromium.org
Owner: rharrison@chromium.org
Status: Started (was: Assigned)
Status: WontFix (was: Started)
One of pages has /MediaBox[0 0 224 792792] in it. This is a massive rect, so is causing us to go over the allocation limit when we try to render it. This is expected behaviour.
Labels: ClusterFuzz-Ignore
Labels: -M-60

Sign in to add a comment