New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 754432 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Oct 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Mac
Pri: 2
Type: Bug

Blocking:
issue 62400



Sign in to add a comment

Timeout in pdf_codec_jpeg_fuzzer

Project Member Reported by ClusterFuzz, Aug 10 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=6031152220733440

Fuzzer: libFuzzer_pdf_codec_jpeg_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: Timeout (exceeds 25 secs)
Crash Address: 
Crash State:
  pdf_codec_jpeg_fuzzer
  
Sanitizer: address (ASAN)

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6031152220733440

Note: This crash might not be reproducible with the provided testcase. That said, for the past 14 days we've been seeing this crash frequently. If you are unable to reproduce this, please try a speculative fix based on the crash stacktrace in the report. The fix can be verified by looking at the crash statistics in the report, a day after the fix is deployed. If the fix resolved the issue, please close the bug by marking as Fixed.

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 
Labels: Pri-2
Stack-overflow, Out of memory and Timeout issues are 'P2'.
Project Member

Comment 2 by ClusterFuzz, Sep 2 2017

Labels: OS-Mac
Cc: msrchandra@chromium.org
Components: Internals>Plugins>PDF
Labels: Test-Predator-Correct-CLs
Owner: tsepez@chromium.org
Status: Assigned (was: Untriaged)
Assigning to concern owner from Predator results --
Regression information is not available. The result is the blame information. 

Author: hbono@chromium.org
Project: chromium-libjpeg_turbo
Changelist: https://chromium.googlesource.com/chromium/deps/libjpeg_turbo.git/+/f0c4f33a4aa0760ba0e12a254b69d996442c9c5a
Time: Mon Nov 01 05:14:55 2010
The CL last changed line 77 of file jdsample.c, which is stack frame 3. 

Author: hbono@chromium.org
Project: chromium-libjpeg_turbo
Changelist: https://chromium.googlesource.com/chromium/deps/libjpeg_turbo.git/+/c6beb74efd1b43982a5b6c957c57426442359c17
Time: Tue Nov 29 05:16:26 2011
The CL last changed line 311 of file jdmainct.c, which is stack frame 4. 

Author: hbono@chromium.org
Project: chromium-libjpeg_turbo
Changelist: https://chromium.googlesource.com/chromium/deps/libjpeg_turbo.git/+/f0c4f33a4aa0760ba0e12a254b69d996442c9c5a
Time: Mon Nov 01 05:14:55 2010
The CL last changed line 282 of file jdapistd.c, which is stack frame 5. 

Author: dsinclair
Project: chromium-pdfium
Changelist: https://pdfium.googlesource.com/pdfium.git/+/d55e11eeb8ebf1e226a1166f395ba77248ce84c3
Time: Tue Apr 12 11:21:22 2016 -0700
The CL last changed line 492 of file fx_codec_jpeg.cpp, which is stack frame 6. 

Author: Tom Sepez
Project: chromium-pdfium
Changelist: https://pdfium.googlesource.com/pdfium.git/+/5171a27eaa7489939310bd2864864867cc78ce21
Time: Thu Jun 01 12:29:09 2017 -0700
The CL last changed line 2040 of file fx_codec_progress.cpp, which is stack frame 7. 

Author: dsinclair
Project: chromium-pdfium
Changelist: https://pdfium.googlesource.com/pdfium.git/+/5a5f251ce8646ec421aa9e35d8bbca71a984770a
Time: Mon Jun 06 11:52:30 2016 -0700
The CL last changed line 47 of file xfa_codec_fuzzer.h, which is stack frame 8.

Suspecting Commit#
https://pdfium.googlesource.com/pdfium.git/+/5171a27eaa7489939310bd2864864867cc78ce21

@tsepez -- Could you please look into the issue, kindly re-assign if this is not related to your changes.
Thank You.

Comment 4 by tsepez@chromium.org, Sep 11 2017

Owner: dsinclair@chromium.org
There's no stack overflow here. It's just that decoding an image with a large dimension takes time.
Blocking: 62400
Owner: rharrison@chromium.org
JPEG fuzzer is XFA only. Blocking XFA on this bug.

Comment 7 by mmoroz@chromium.org, Oct 24 2017

For more information, please see https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md.

The link referenced in the description is no longer valid.

(bulk edit)
Status: WontFix (was: Assigned)
This appears to be attempting to decode a very large jpeg, 4097x47364, so it is taking a lot of time like thestig commented above. Other image viewers attempt to decode the image, so I am pretty sure it is valid, but they end up spending huge amounts of time on it also.

Sign in to add a comment