Null-dereference READ in CPDF_CrossRefTable::GetSize |
||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=6239397763350528 Fuzzer: tokenfuzz_pdf_curated Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Null-dereference READ Crash Address: 0x000000000018 Crash State: CPDF_CrossRefTable::GetSize CPDF_Parser::GetLastObjNum IsValidObjectNumber Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=580184:580193 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6239397763350528 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Aug 2
Automatically adding ccs based on suspected regression changelists: Rework of CPDF_Parser::GetLastObjNum. by art-snake@yandex-team.ru - https://pdfium.googlesource.com/pdfium/+/b07deb3fc1f54bd700a66df573bfcbc4bcc1d787 If this is incorrect, please let us know why and apply the Test-Predator-Wrong-CLs label.
,
Aug 3
Issue 870547 has been merged into this issue.
,
Aug 7
art-snake@ Could you please look into this issue.
,
Aug 8
Predator has provided with one possible suspect, hence assigning to concern owner for further triage Suspect CL: https://pdfium.googlesource.com/pdfium/+/b07deb3fc1f54bd700a66df573bfcbc4bcc1d787 Since owner is not a chromium member, assigning to its reviewer thestig@ Could you please look into this issue.
,
Aug 9
Not obvious how to fix this, so I'm going to revert.
,
Aug 9
,
Aug 10
ClusterFuzz testcase 4559938672918528 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Aug 10
ClusterFuzz has detected this issue as fixed in range 581861:581862. Detailed report: https://clusterfuzz.com/testcase?key=6239397763350528 Fuzzer: tokenfuzz_pdf_curated Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Null-dereference READ Crash Address: 0x000000000018 Crash State: CPDF_CrossRefTable::GetSize CPDF_Parser::GetLastObjNum IsValidObjectNumber Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=580184:580193 Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=581861:581862 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6239397763350528 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page. |
||||
►
Sign in to add a comment |
||||
Comment 1 by ClusterFuzz
, Aug 2Labels: Test-Predator-Auto-Components