New issue
Advanced search Search tips

Issue 878544 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Aug 29
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Security



Sign in to add a comment

Crash in void fuzzer::TracePC::IterateInline8bitCounters<fuzzer::TracePC::InitializeUnsta

Project Member Reported by ClusterFuzz, Aug 28

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5732275128631296

Fuzzer: libFuzzer_css_parser_fast_paths_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x3a00011f8067
Crash State:
  void fuzzer::TracePC::IterateInline8bitCounters<fuzzer::TracePC::InitializeUnsta
  
Sanitizer: address (ASAN)

Recommended Security Severity: Medium

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5732275128631296

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.

Note: This crash might not be reproducible with the provided testcase. That said, for the past 14 days we've been seeing this crash frequently. If you are unable to reproduce this, please try a speculative fix based on the crash stacktrace in the report. The fix can be verified by looking at the crash statistics in the report, a day after the fix is deployed. We will auto-close the bug if the crash is not seen for 14 days.
 
Project Member

Comment 1 by sheriffbot@chromium.org, Aug 29

Labels: Pri-1
Components: Tools>Stability>libFuzzer
Status: WontFix (was: Untriaged)
Not much to go on in the report, and possibly an issue with the fuzz driver itself or the effects of wild corruption while fuzzing.
Project Member

Comment 3 by sheriffbot@chromium.org, Dec 6

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Thanks, Tom! Yeah, that issue was reporter due to buggy -handle_unstable=1 mode. Sorry for the noise.

Sign in to add a comment