New issue
Advanced search Search tips

Issue 920143 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 917029
Owner:
Closed: Jan 9
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Abrt in fuzz_webp_enc_dec.cc

Project Member Reported by ClusterFuzz, Jan 9

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5000830985699328

Fuzzer: libFuzzer_libwebp_enc_dec_api_fuzzer
Fuzz target binary: libwebp_enc_dec_api_fuzzer
Job Type: x86_libfuzzer_chrome_asan_debug
Platform Id: linux

Crash Type: Abrt
Crash Address: 0x002f70ca
Crash State:
  fuzz_webp_enc_dec.cc
  
Sanitizer: address (ASAN)

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5000830985699328

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for instructions to reproduce this bug locally.
 
Project Member

Comment 1 by ClusterFuzz, Jan 9

Cc: mbarow...@chromium.org
Labels: ClusterFuzz-Auto-CC
Automatically adding ccs based on OWNERS file / target commit history.

If this is incorrect, please add ClusterFuzz-Wrong label.
Project Member

Comment 2 by bugdroid1@chromium.org, Jan 9

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/b49e2f53b1a4459513c18e603ef35ba5952dbf79

commit b49e2f53b1a4459513c18e603ef35ba5952dbf79
Author: Thiemo Nagel <tnagel@chromium.org>
Date: Wed Jan 09 10:57:31 2019

Mark RTCDtlsTransport-state.html flake

BUG= 920143 
TBR=hta

Change-Id: I48fd762e5edd90e956ce24bd3e821c666c18036a
Reviewed-on: https://chromium-review.googlesource.com/c/1402567
Commit-Queue: Thiemo Nagel <tnagel@chromium.org>
Reviewed-by: Thiemo Nagel <tnagel@chromium.org>
Cr-Commit-Position: refs/heads/master@{#621109}
[modify] https://crrev.com/b49e2f53b1a4459513c18e603ef35ba5952dbf79/third_party/blink/web_tests/TestExpectations

Whoops, sorry. That CL was meant for  issue 920144 .
Owner: yguyon@google.com
Assigning to yguyon@. It doesn't look like this is even a bug with the library because it looks like it's aborting on an invalidly formatted header--maybe the fuzzer needs to be modified to not generate such test cases? Not sure.
Mergedinto: 917029
Status: Duplicate (was: Untriaged)
The patch of the Issue 917029 seems to fix this bug too.
Waiting for the next sync of the public repository of libwebp
to chromium/third_party/libwebp.
Cc: jzern@chromium.org

Sign in to add a comment