New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 858842 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Aug 17
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Pointer-overflow in mt_decode_mb_rows

Project Member Reported by ClusterFuzz, Jun 28 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=4549363767181312

Fuzzer: libFuzzer_media_vpx_video_decoder_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Pointer-overflow
Crash Address: 
Crash State:
  mt_decode_mb_rows
  vp8mt_decode_mb_rows
  vp8_decode_frame
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=551565:551569

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4549363767181312

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.
 
Project Member

Comment 1 by ClusterFuzz, Jun 28 2018

Cc: aizatsky@chromium.org
Labels: ClusterFuzz-Auto-CC
Automatically adding ccs based on OWNERS file / target commit history.

If this is incorrect, please add ClusterFuzz-Wrong label.
Cc: kkaluri@chromium.org
Labels: M-68 Test-Predator-Wrong CF-NeedsTriage
Unable to find actual suspect through code search and also observing no CL's under regression range, hence adding appropriate label and requesting someone from Android team to look in to this issue.

Thanks!

Project Member

Comment 3 by ClusterFuzz, Jul 28

Labels: -Reproducible Unreproducible
ClusterFuzz testcase 4549363767181312 appears to be flaky, updating reproducibility label.
Project Member

Comment 4 by ClusterFuzz, Aug 17

Status: WontFix (was: Untriaged)
ClusterFuzz testcase 4549363767181312 is flaky and no longer crashes, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment