New issue
Advanced search Search tips

Issue 844254 link

Starred by 2 users

Issue metadata

Status: Verified
Owner:
Closed: May 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Security



Sign in to add a comment

Heap-buffer-overflow in void SkMatrixConvolutionImageFilter::filterPixels<RepeatPixelFetcher, true>

Project Member Reported by ClusterFuzz, May 18 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5662052706942976

Fuzzer: sugoi_filter_fuzzer
Job Type: linux_asan_filter_fuzz_stub
Platform Id: linux

Crash Type: Heap-buffer-overflow WRITE 4
Crash Address: 0x6160000008c0
Crash State:
  void SkMatrixConvolutionImageFilter::filterPixels<RepeatPixelFetcher, true>
  SkMatrixConvolutionImageFilter::onFilterImage
  SkImageFilter::filterImage
  
Sanitizer: address (ASAN)

Recommended Security Severity: High

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5662052706942976

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Cc: kjlubick@chromium.org
CCing kjlubick@ for fuzzing purposes
Project Member

Comment 2 by sheriffbot@chromium.org, May 18 2018

Labels: M-66
Project Member

Comment 3 by sheriffbot@chromium.org, May 18 2018

Labels: Pri-1
Components: Internals>Skia
This does not repro in the skia branch chrome/m66 or m67, so there does not appear to need a cherry-pick
Owner: robertphillips@chromium.org
Status: Started (was: Untriaged)
Lets wait on ClusterFuzz to auto-verify and close this in a day.
Project Member

Comment 7 by ClusterFuzz, May 19 2018

ClusterFuzz has detected this issue as fixed in range 559937:559944.

Detailed report: https://clusterfuzz.com/testcase?key=5662052706942976

Fuzzer: sugoi_filter_fuzzer
Job Type: linux_asan_filter_fuzz_stub
Platform Id: linux

Crash Type: Heap-buffer-overflow WRITE 4
Crash Address: 0x6160000008c0
Crash State:
  void SkMatrixConvolutionImageFilter::filterPixels<RepeatPixelFetcher, true>
  SkMatrixConvolutionImageFilter::onFilterImage
  SkImageFilter::filterImage
  
Sanitizer: address (ASAN)

Recommended Security Severity: High

Fixed: https://clusterfuzz.com/revisions?job=linux_asan_filter_fuzz_stub&range=559937:559944

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5662052706942976

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 8 by ClusterFuzz, May 19 2018

Labels: ClusterFuzz-Verified
Status: Verified (was: Started)
ClusterFuzz testcase 5662052706942976 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 9 by sheriffbot@chromium.org, May 19 2018

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Labels: -M-66 M-68
Project Member

Comment 11 by sheriffbot@chromium.org, Jun 8 2018

Labels: Merge-Request-68
Project Member

Comment 12 by sheriffbot@chromium.org, Jun 8 2018

Labels: -Merge-Request-68 Hotlist-Merge-Review Merge-Review-68
This bug requires manual review: M68 has already been promoted to the beta branch, so this requires manual review
Please contact the milestone owner if you have questions.
Owners: cmasso@(Android), kariahda@(iOS), bhthompson@(ChromeOS), abdulsyed@(Desktop)

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: -Merge-Review-68 Merge-Rejected-68
I don't see anything to merge here. 
Correct, Skia branched for M68 on 5/24 while the fix (https://skia-review.googlesource.com/c/skia/+/129165) landed on 5/18.
Labels: Release-0-M68
Project Member

Comment 16 by sheriffbot@chromium.org, Aug 25

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment