New issue
Advanced search Search tips

Issue 768235 link

Starred by 1 user

Issue metadata

Status: Verified
Owner: ----
Closed: Oct 2017
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Out-of-memory in pdf_codec_gif_fuzzer

Project Member Reported by ClusterFuzz, Sep 24 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=6003022680555520

Fuzzer: libFuzzer_pdf_codec_gif_fuzzer
Job Type: libfuzzer_chrome_msan
Platform Id: linux

Crash Type: Out-of-memory (exceeds 2048 MB)
Crash Address: 
Crash State:
  pdf_codec_gif_fuzzer
  
Sanitizer: memory (MSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_msan&range=400803:400900

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6003022680555520

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 
Status: WontFix (was: Untriaged)
Marking this issue as Wont Fix as it is an Out of Memory issue and there is no enough stack trace available.

Thank You.

Comment 2 by mmoroz@chromium.org, Sep 30 2017

Status: Unconfirmed (was: WontFix)
Re-opening the issue, as it has been incorrectly closed as WontFix. Out of Memory issues are valid bugs in most of the cases.

WontFix status might be assigned only by the owner of the target code, if there is no way or no reason to prevent fuzzer from causing OOM crash.

Sometimes we mark OOMs found with MSan as WontFix because MSan has big memory overhead. However, that should not be done without a proper understanding of the target as well as without looking at the crash stats.
Project Member

Comment 3 by ClusterFuzz, Oct 2 2017

ClusterFuzz has detected this issue as fixed in range 505511:505519.

Detailed report: https://clusterfuzz.com/testcase?key=6003022680555520

Fuzzer: libFuzzer_pdf_codec_gif_fuzzer
Job Type: libfuzzer_chrome_msan
Platform Id: linux

Crash Type: Out-of-memory (exceeds 2048 MB)
Crash Address: 
Crash State:
  pdf_codec_gif_fuzzer
  
Sanitizer: memory (MSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_msan&range=400803:400900
Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_msan&range=505511:505519

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6003022680555520

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 4 by ClusterFuzz, Oct 2 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Unconfirmed)
ClusterFuzz testcase 6003022680555520 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment