Ill in ctap_response_fuzzer |
||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5012371538706432 Fuzzer: libFuzzer_ctap_response_fuzzer Job Type: libfuzzer_chrome_msan Platform Id: linux Crash Type: Ill Crash Address: 0x000001260cc0 Crash State: ctap_response_fuzzer long base::internal::checked_cast<long, base::internal::CheckOnFailure, unsigned cbor::CBORReader::ReadArrayContent Sanitizer: memory (MSAN) Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_msan&range=537720:537724 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5012371538706432 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.
,
Feb 22 2018
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/1e3136289954860e760caa4214124249c9549c59 commit 1e3136289954860e760caa4214124249c9549c59 Author: Kouhei Ueno <kouhei@chromium.org> Date: Thu Feb 22 07:37:27 2018 CBORReader: CBOR array/map length should be treated as uint64_t Bug: 813738 , 813735 Change-Id: I126e260f6ffb938264a40f92a286cf8488852f56 Reviewed-on: https://chromium-review.googlesource.com/927926 Reviewed-by: Balazs Engedy <engedy@chromium.org> Reviewed-by: Jochen Eisinger <jochen@chromium.org> Commit-Queue: Kouhei Ueno <kouhei@chromium.org> Cr-Commit-Position: refs/heads/master@{#538378} [modify] https://crrev.com/1e3136289954860e760caa4214124249c9549c59/components/cbor/cbor_reader.cc [modify] https://crrev.com/1e3136289954860e760caa4214124249c9549c59/components/cbor/cbor_reader_unittest.cc
,
Feb 23 2018
ClusterFuzz has detected this issue as fixed in range 538377:538379. Detailed report: https://clusterfuzz.com/testcase?key=5012371538706432 Fuzzer: libFuzzer_ctap_response_fuzzer Job Type: libfuzzer_chrome_msan Platform Id: linux Crash Type: Ill Crash Address: 0x000001260cc0 Crash State: ctap_response_fuzzer long base::internal::checked_cast<long, base::internal::CheckOnFailure, unsigned cbor::CBORReader::ReadArrayContent Sanitizer: memory (MSAN) Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_msan&range=537720:537724 Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_msan&range=538377:538379 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5012371538706432 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Feb 23 2018
ClusterFuzz testcase 5012371538706432 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
||
►
Sign in to add a comment |
||
Comment 1 by ClusterFuzz
, Feb 20 2018Owner: kouhei@chromium.org
Status: Assigned (was: Untriaged)