Issue metadata
Sign in to add a comment
|
Crash in getAddress |
||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=6014962334695424 Fuzzer: libFuzzer_swiftshader_vertex_routine_fuzzer Job Type: libfuzzer_chrome_asan Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x62d00005e418 Crash State: getAddress sw::Array<sw::Float4, 1>::operator Sanitizer: address (ASAN) Recommended Security Severity: Medium Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan&range=521502:521564 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6014962334695424 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.
,
Jun 27 2018
,
Jun 27 2018
,
Jun 27 2018
,
Jun 27 2018
The shader contains an array of 32769 elements, which is a lot more than our limit of 4096 temporary registers, which we check for since April: https://swiftshader-review.googlesource.com/18388. The regression range is from December last year, and last tested version from March. So this might not reproduce. Either way it doesn't appear that this can be used for targeted memory access, so lowering the priority.
,
Jun 29 2018
ClusterFuzz appears to be stuck and hasn't tested any recent revisions.
,
Jun 29 2018
Sorry about this, this is a recent issue with ClusterFuzz and should go away with https://bugs.chromium.org/p/chromium/issues/detail?id=856906. Also, this bug should get autoclosed soon.
,
Jul 1
ClusterFuzz has detected this issue as fixed in range 552045:552055. Detailed report: https://clusterfuzz.com/testcase?key=6014962334695424 Fuzzer: libFuzzer_swiftshader_vertex_routine_fuzzer Job Type: libfuzzer_chrome_asan Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x62d00005e418 Crash State: getAddress sw::Array<sw::Float4, 1>::operator Sanitizer: address (ASAN) Recommended Security Severity: Medium Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan&range=521502:521564 Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan&range=552045:552055 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6014962334695424 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jul 14
capn: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jul 25
ClusterFuzz has detected this issue as fixed in range 552045:552055. Detailed report: https://clusterfuzz.com/testcase?key=6014962334695424 Fuzzer: libFuzzer_swiftshader_vertex_routine_fuzzer Job Type: libfuzzer_chrome_asan Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x62d00005e418 Crash State: getAddress sw::Array<sw::Float4, 1>::operator Sanitizer: address (ASAN) Recommended Security Severity: Medium Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan&range=521502:521564 Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan&range=552045:552055 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6014962334695424 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jul 29
capn: Uh oh! This issue still open and hasn't been updated in the last 29 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jul 30
@inferno, it looks like this hasn't autoclosed yet as mentioned in #7. Anyway, no big deal. I think this was the actual fix: https://swiftshader.googlesource.com/SwiftShader/+/329747ca1c0fc80010ac55f2fa41c22d3c56c1a0
,
Jul 31
,
Nov 6
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by ClusterFuzz
, Jun 27 2018Labels: Test-Predator-Auto-Components