New issue
Advanced search Search tips

Issue 833114 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 843044
Owner:
Closed: May 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 1
Type: Bug-Security

Blocked on:
issue 768565



Sign in to add a comment

Heap-buffer-overflow in cc::VideoResourceUpdater::AllocateResource

Project Member Reported by ClusterFuzz, Apr 15 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=4796939091312640

Fuzzer: inferno_webbot
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: Heap-buffer-overflow READ 8
Crash Address: 0x6150000bea80
Crash State:
  cc::VideoResourceUpdater::AllocateResource
  cc::VideoResourceUpdater::CreateForSoftwarePlanes
  cc::VideoResourceUpdater::CreateExternalResourcesFromVideoFrame
  
Sanitizer: address (ASAN)

Recommended Security Severity: Medium

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4796939091312640

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, Apr 15 2018

Labels: M-68 Fuzz-Blocker ReleaseBlock-Beta
This crash occurs very frequently on mac platform and is likely preventing the fuzzer inferno_webbot from making much progress. Fixing this will allow more bugs to be found.

Marking this bug as a blocker for next Beta release.

If this is incorrect, please add ClusterFuzz-Wrong label and remove the ReleaseBlock-Beta label.
Project Member

Comment 2 by sheriffbot@chromium.org, Apr 15 2018

Labels: Pri-1
Components: Internals>GPU>Internals
Owner: lethalantidote@chromium.org
Status: Assigned (was: Untriaged)
lethalantidote: This looks related to  crbug.com/829280 , can you take a look?
Cc: mlamouri@chromium.org
Interesting. Not sure why the fuzzer is still hitting this. @mlamouri, the finch experiment is still disabled right?
Yes. However, I suspect the fuzzer to use the configs which is a different thing than the finch experiment. IOW, the fuzzer must turn on the feature. It adds a bit of noise but will be helpful for us to catch any issue faster going forward.
Project Member

Comment 7 by sheriffbot@chromium.org, May 1 2018

lethalantidote: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers?

If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one?

If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Blockedon: 768565
Mergedinto: 843044
Status: Duplicate (was: Assigned)
Project Member

Comment 10 by ClusterFuzz, May 18 2018

ClusterFuzz has detected this issue as fixed in range 559525:559539.

Detailed report: https://clusterfuzz.com/testcase?key=4796939091312640

Fuzzer: inferno_webbot
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: Heap-buffer-overflow READ 8
Crash Address: 0x6150000bea80
Crash State:
  cc::VideoResourceUpdater::AllocateResource
  cc::VideoResourceUpdater::CreateForSoftwarePlanes
  cc::VideoResourceUpdater::CreateExternalResourcesFromVideoFrame
  
Sanitizer: address (ASAN)

Recommended Security Severity: Medium

Fixed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=559525:559539

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4796939091312640

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 11 by sheriffbot@chromium.org, Aug 22

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment