Null-dereference READ in puffin::BsdiffStream::GetSize |
|||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5334575916777472 Fuzzer: libFuzzer_puffin_fuzzer Job Type: libfuzzer_asan_chromeos Platform Id: linux Crash Type: Null-dereference READ Crash Address: 0x000000000000 Crash State: puffin::BsdiffStream::GetSize libbspatch.so puffin::PuffPatch Sanitizer: address (ASAN) Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5334575916777472 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.
,
Apr 11 2018
,
Apr 11 2018
Added this for fix: https://android-review.googlesource.com/c/platform/external/puffin/+/663041
,
Apr 12 2018
,
Apr 13 2018
Issue 832118 has been merged into this issue.
,
Apr 17 2018
The following revision refers to this bug: https://chromium.googlesource.com/chromiumos/overlays/chromiumos-overlay/+/4696703e32f60731a311eaf1344dd69d8dd48fe1 commit 4696703e32f60731a311eaf1344dd69d8dd48fe1 Author: Amin Hassani <ahassani@google.com> Date: Tue Apr 17 22:47:22 2018 Marking 9999 ebuild for dev-util/puffin as stable. It is picking up: https://android-review.googlesource.com/c/platform/external/puffin/+/663990 https://android-review.googlesource.com/c/platform/external/puffin/+/663042 https://android-review.googlesource.com/c/platform/external/puffin/+/663041 BUG= chromium:830201 BUG= chromium:831772 BUG= chromium:831868 BUG= chromium:832118 TEST=unittests TEST=passed failed fuzzer test cases Change-Id: If92dd2960b0fa601d671417eb4ddcb295bfa83b3 Reviewed-on: https://chromium-review.googlesource.com/1011082 Commit-Ready: Amin Hassani <ahassani@chromium.org> Tested-by: Amin Hassani <ahassani@chromium.org> Reviewed-by: Chirantan Ekbote <chirantan@chromium.org> [rename] https://crrev.com/4696703e32f60731a311eaf1344dd69d8dd48fe1/dev-util/puffin/puffin-1.0.0-r420.ebuild
,
Apr 18 2018
ClusterFuzz testcase 5573159202586624 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Apr 18 2018
ClusterFuzz has detected this issue as fixed in range 2487713:2487966. Detailed report: https://clusterfuzz.com/testcase?key=5334575916777472 Fuzzer: libFuzzer_puffin_fuzzer Job Type: libfuzzer_asan_chromeos Platform Id: linux Crash Type: Null-dereference READ Crash Address: 0x000000000000 Crash State: puffin::BsdiffStream::GetSize bsdiff::bspatch puffin::PuffPatch Sanitizer: address (ASAN) Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_asan_chromeos&range=2487713:2487966 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5334575916777472 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page. |
|||
►
Sign in to add a comment |
|||
Comment 1 by ClusterFuzz
, Apr 11 2018Labels: ClusterFuzz-Auto-CC