Integer-overflow in ConstantUnion::operator* |
||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5048818797379584 Fuzzer: libFuzzer_swiftshader_vertex_routine_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: ConstantUnion::operator* TIntermConstantUnion::fold TIntermediate::addBinaryMath Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=521492:521536 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5048818797379584 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.
,
Dec 8 2017
@capn -- Could you please look into this issue. Assigning this issue to you, as per the update we received from you in the Issue 781505 . Please reassign if it is not related to your changes. Thanks.
,
Dec 8 2017
This is also undefined behavior in the language that we're parsing, so it's of no consequence. We'll look into silencing the sanitizer warning either by making it deterministic or suppressing it.
,
Dec 20 2017
ClusterFuzz has detected this issue as fixed in range 525156:525174. Detailed report: https://clusterfuzz.com/testcase?key=5048818797379584 Fuzzer: libFuzzer_swiftshader_vertex_routine_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: ConstantUnion::operator* TIntermConstantUnion::fold TIntermediate::addBinaryMath Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=521492:521536 Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=525156:525174 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5048818797379584 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Dec 20 2017
ClusterFuzz testcase 5048818797379584 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
||||
►
Sign in to add a comment |
||||
Comment 1 by ClusterFuzz
, Dec 7 2017Labels: Test-Predator-Auto-Components