New issue
Advanced search Search tips

Issue 879675 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Sep 15
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Crash in void fuzzer::TracePC::IterateInline8bitCounters<fuzzer::TracePC::InitializeUnsta

Project Member Reported by ClusterFuzz, Aug 31

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=6321468657631232

Fuzzer: libFuzzer_appcache_manifest_parser_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x3a0000298107
Crash State:
  void fuzzer::TracePC::IterateInline8bitCounters<fuzzer::TracePC::InitializeUnsta
  
Sanitizer: address (ASAN)

Recommended Security Severity: Medium

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6321468657631232

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.

Note: This crash might not be reproducible with the provided testcase. That said, for the past 14 days we've been seeing this crash frequently. If you are unable to reproduce this, please try a speculative fix based on the crash stacktrace in the report. The fix can be verified by looking at the crash statistics in the report, a day after the fix is deployed. We will auto-close the bug if the crash is not seen for 14 days.
 
Cc: mmoroz@chromium.org
Owner: metzman@chromium.org
Status: Assigned (was: Untriaged)
This is a spurious crash in libFuzzer. I'll stop it from happening.
Project Member

Comment 2 by bugdroid1@chromium.org, Aug 31

The following revision refers to this bug:
  https://chrome-internal.googlesource.com/chrome/tools/clusterfuzz/+/d748d70d1ddd75fbe4ef99c1cb83658d4c6fb61a

commit d748d70d1ddd75fbe4ef99c1cb83658d4c6fb61a
Author: Jonathan Metzman <metzman@chromium.org>
Date: Fri Aug 31 21:35:09 2018

Project Member

Comment 3 by sheriffbot@chromium.org, Sep 1

Labels: Pri-1
Components: Tools>Stability>libFuzzer
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam -Security_Severity-Medium Type-Bug
Removing from the security queue.
Project Member

Comment 6 by ClusterFuzz, Sep 15

Status: WontFix (was: Assigned)
ClusterFuzz testcase 6321468657631232 is flaky and no longer crashes, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment