Issue metadata
Sign in to add a comment
|
Heap-buffer-overflow in void SkMatrixConvolutionImageFilter::filterPixels<RepeatPixelFetcher, true> |
||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5662052706942976 Fuzzer: sugoi_filter_fuzzer Job Type: linux_asan_filter_fuzz_stub Platform Id: linux Crash Type: Heap-buffer-overflow WRITE 4 Crash Address: 0x6160000008c0 Crash State: void SkMatrixConvolutionImageFilter::filterPixels<RepeatPixelFetcher, true> SkMatrixConvolutionImageFilter::onFilterImage SkImageFilter::filterImage Sanitizer: address (ASAN) Recommended Security Severity: High Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5662052706942976 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
May 18 2018
,
May 18 2018
,
May 18 2018
Should be fixed by https://skia-review.googlesource.com/c/skia/+/129165
,
May 18 2018
This does not repro in the skia branch chrome/m66 or m67, so there does not appear to need a cherry-pick
,
May 18 2018
Lets wait on ClusterFuzz to auto-verify and close this in a day.
,
May 19 2018
ClusterFuzz has detected this issue as fixed in range 559937:559944. Detailed report: https://clusterfuzz.com/testcase?key=5662052706942976 Fuzzer: sugoi_filter_fuzzer Job Type: linux_asan_filter_fuzz_stub Platform Id: linux Crash Type: Heap-buffer-overflow WRITE 4 Crash Address: 0x6160000008c0 Crash State: void SkMatrixConvolutionImageFilter::filterPixels<RepeatPixelFetcher, true> SkMatrixConvolutionImageFilter::onFilterImage SkImageFilter::filterImage Sanitizer: address (ASAN) Recommended Security Severity: High Fixed: https://clusterfuzz.com/revisions?job=linux_asan_filter_fuzz_stub&range=559937:559944 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5662052706942976 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
May 19 2018
ClusterFuzz testcase 5662052706942976 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
May 19 2018
,
May 29 2018
,
Jun 8 2018
,
Jun 8 2018
This bug requires manual review: M68 has already been promoted to the beta branch, so this requires manual review Please contact the milestone owner if you have questions. Owners: cmasso@(Android), kariahda@(iOS), bhthompson@(ChromeOS), abdulsyed@(Desktop) For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jun 8 2018
I don't see anything to merge here.
,
Jun 12 2018
Correct, Skia branched for M68 on 5/24 while the fix (https://skia-review.googlesource.com/c/skia/+/129165) landed on 5/18.
,
Jul 23
,
Aug 25
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by metzman@chromium.org
, May 18 2018