New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 894944 link

Starred by 3 users

Issue metadata

Status: Verified
Owner:
Last visit 18 days ago
Closed: Oct 24
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 1
Type: Bug



Sign in to add a comment

Null-dereference READ in spvtools::val::ValidationState_t::IsIntScalarType

Project Member Reported by ClusterFuzz, Oct 12

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5755148876644352

Fuzzer: libFuzzer_spvtools_val_fuzzer
Job Type: windows_libfuzzer_chrome_asan
Platform Id: windows

Crash Type: Null-dereference READ
Crash Address: 0x00000000003a
Crash State:
  spvtools::val::ValidationState_t::IsIntScalarType
  spvtools::val::CompositesPass
  spvtools::val::ValidateBinaryUsingContextAndValidationState
  
Sanitizer: address (ASAN)

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5755148876644352

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.
 
Project Member

Comment 1 by ClusterFuzz, Oct 12

Components: Internals>GPU>Internals
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
Cc: kkaluri@chromium.org alanbaker@google.com
Labels: M-70 CF-NeedsTriage Test-Predator-Wrong
Unable to find actual suspect through code search and also observing no CL's under regression range, hence adding appropriate label and requesting someone from dev team to look in to this issue.
with reference to the  Issue 875842 , CC'ing alanbaker@ for further triage.

Thanks!
Cc: -alanbaker@google.com dsinclair@chromium.org
Owner: alanbaker@google.com
Labels: -CF-NeedsTriage
Status: Assigned (was: Untriaged)
Project Member

Comment 5 by ClusterFuzz, Oct 24

ClusterFuzz has detected this issue as fixed in range 601568:601569.

Detailed report: https://clusterfuzz.com/testcase?key=5755148876644352

Fuzzer: libFuzzer_spvtools_val_fuzzer
Job Type: windows_libfuzzer_chrome_asan
Platform Id: windows

Crash Type: Null-dereference READ
Crash Address: 0x00000000003a
Crash State:
  spvtools::val::ValidationState_t::IsIntScalarType
  spvtools::val::CompositesPass
  spvtools::val::ValidateBinaryUsingContextAndValidationState
  
Sanitizer: address (ASAN)

Fixed: https://clusterfuzz.com/revisions?job=windows_libfuzzer_chrome_asan&range=601568:601569

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5755148876644352

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 6 by ClusterFuzz, Oct 24

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 5755148876644352 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment