New issue
Advanced search Search tips

Issue 868200 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Aug 6
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Security



Sign in to add a comment

Use-of-uninitialized-value in sse41::blit_row_s32a_opaque

Project Member Reported by ClusterFuzz, Jul 27

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=4584254269554688

Fuzzer: inferno_twister_c
Job Type: linux_msan_chrome
Platform Id: linux

Crash Type: Use-of-uninitialized-value
Crash Address: 
Crash State:
  sse41::blit_row_s32a_opaque
  SkAAClipBlitter::blitRect
  antifilldot8
  
Sanitizer: memory (MSAN)

Recommended Security Severity: Medium

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4584254269554688

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by sheriffbot@chromium.org, Jul 27

Labels: M-68 Target-68
Project Member

Comment 2 by sheriffbot@chromium.org, Jul 27

Labels: Pri-1
Components: Internals>Skia
Owner: hcm@chromium.org
Status: Assigned (was: Untriaged)
hcm: Any idea who the right owner for this would be?
Components: -Internals>Skia
Owner: ----
Status: WontFix (was: Assigned)
This is another tricky one where Skia is not the culprit and a precondition for calling us (passing us initialized data) has not been met.  Being nearly impossible to find from our view of the world, we often end up "won't fix"ing these and they resolve in time.  The other option is maybe having cc team take a look, but they are often in the same boat.
Project Member

Comment 6 by ClusterFuzz, Aug 13

Labels: Needs-Feedback
ClusterFuzz testcase 4584254269554688 is still reproducing on tip-of-tree build (trunk).

If this testcase was not reproducible locally or unworkable, ignore this notification and we will file another bug soon with hopefully a better and workable testcase.

Otherwise, if this is not intended to be fixed (e.g. this is an intentional crash), please add ClusterFuzz-Ignore label to prevent future bug filing with similar crash stacktrace.
Project Member

Comment 7 by sheriffbot@chromium.org, Nov 13

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment