Null-dereference READ in device::U2fMessage::AddContinuationPacket |
|||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=6365159533838336 Fuzzer: afl_u2f_message_fuzzer Job Type: afl_chrome_asan Platform Id: linux Crash Type: Null-dereference READ Crash Address: 0x000000000018 Crash State: device::U2fMessage::AddContinuationPacket Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=afl_chrome_asan&range=513103:513107 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6365159533838336 Additional requirements: Requires Gestures Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.
,
Nov 2 2017
See https://chromium-review.googlesource.com/c/chromium/src/+/751102
,
Nov 2 2017
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/43b90283ba527dc5ac9707c67bae608aba61006f commit 43b90283ba527dc5ac9707c67bae608aba61006f Author: Ke He <ke.he@intel.com> Date: Thu Nov 02 16:22:20 2017 Fix null-dereference in u2f_message_fuzzer.cc After r513104, the 'packet_size' in u2f_message_fuzzer.cc should be 64, not 65. BUG= 780499 Change-Id: I983c76599d599be53950b4a5d77bb5b5ec4bc0bd Reviewed-on: https://chromium-review.googlesource.com/751102 Commit-Queue: Ke He <ke.he@intel.com> Reviewed-by: Reilly Grant <reillyg@chromium.org> Cr-Commit-Position: refs/heads/master@{#513508} [modify] https://crrev.com/43b90283ba527dc5ac9707c67bae608aba61006f/device/u2f/u2f_message_fuzzer.cc
,
Nov 3 2017
,
Nov 3 2017
ClusterFuzz has detected this issue as fixed in range 513502:513538. Detailed report: https://clusterfuzz.com/testcase?key=6365159533838336 Fuzzer: afl_u2f_message_fuzzer Job Type: afl_chrome_asan Platform Id: linux Crash Type: Null-dereference READ Crash Address: 0x000000000018 Crash State: device::U2fMessage::AddContinuationPacket Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=afl_chrome_asan&range=513103:513107 Fixed: https://clusterfuzz.com/revisions?job=afl_chrome_asan&range=513502:513538 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6365159533838336 Additional requirements: Requires Gestures See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Nov 3 2017
ClusterFuzz testcase 6365159533838336 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Nov 7 2017
|
|||||
►
Sign in to add a comment |
|||||
Comment 1 by ClusterFuzz
, Nov 1 2017Owner: donna...@intel.com
Status: Assigned (was: Untriaged)