Integer-overflow in sw::RectT<int>::width |
||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5617188212572160 Fuzzer: inferno_twister Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: sw::RectT<int>::width es2::Device::ClipSrcRect es2::Context::blitFramebuffer Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=529742:529750 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5617188212572160 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Feb 5 2018
Since it is related to SwiftShader component, assigning it to the capn@ for further triage
,
Feb 5 2018
Looks very similar to Issue 804072. Alexis, can you have a look?
,
May 30 2018
ClusterFuzz has detected this issue as fixed in range 562746:562750. Detailed report: https://clusterfuzz.com/testcase?key=5617188212572160 Fuzzer: inferno_twister Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: sw::RectT<int>::width es2::Device::ClipSrcRect es2::Context::blitFramebuffer Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=529742:529750 Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=562746:562750 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5617188212572160 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
May 30 2018
ClusterFuzz testcase 5617188212572160 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
May 30 2018
Must be https://chromium-review.googlesource.com/1061053. Alexis, please check if this still needs mitigation on SwiftShader's side. I'm inclined to label this as garbage-in-garbage-out, unless this is reasonably expected to work in OpenGL ES, or affects security. |
||||
►
Sign in to add a comment |
||||
Comment 1 by ClusterFuzz
, Feb 2 2018Labels: Test-Predator-Auto-Components