From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: <3zV3cYQ0bABA24347qy1-574tq55yt.w44w1uA8u7s439u39.s42@M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com> Received: from mail-il1-x145.google.com (mail-il1-x145.google.com [IPv6:2607:f8b0:4864:20::145]) by sourceware.org (Postfix) with ESMTPS id 44C0F3858400 for ; Mon, 10 Jan 2022 16:24:46 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.1 sourceware.org 44C0F3858400 Received: by mail-il1-x145.google.com with SMTP id g14-20020a056e021e0e00b002a26cb56bd4so6328000ila.14 for ; Mon, 10 Jan 2022 08:24:46 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:mime-version:date:reply-to:references:message-id :subject:from:to; bh=oEmHplyeQdd6phik8CIUDBa3HkgCA21bEgcSXtrpIi8=; b=R/EicsJCo0rpMldBvrDOTFt9j1yxkbSkoVVUKTcuGe+IJuHcs8lYReLTenVeY1FuE8 opLrg+dclzbzc3ayOLhQv+6MgEuiq7OrvRoEsbzWFimtP1NIDosEiYjm9DRCY8FSehB9 LHVT9/cjMVCrY7fVRUI5eUbk35rpVJwQO1JZok7sHFD2er5iagUk1mYTnuzPZ/NSx5bQ INBblaqLt8C84NQ4HLKCf+HRY8rbIq1FzlLW7B9Ayhntcskfknfz68jV9rUobxwLFy2f XVhrRyo5u+orfZ3r48bLnL/UCFn+qgvsy3S15aMZqUtKGWx+0BC2MicuSC26eddtRqeO bo0A== X-Gm-Message-State: AOAM533hekG55RJeC8zgipn5j1/W+ygOP/PDRKxzfDF8MrAvyr62VKzT 2YrFQKvWnhvr9n1rICo1DMrh2bKLfS34kbcWbOKZvRZRrNNq X-Google-Smtp-Source: ABdhPJzFiaZgAGv4Ok8dA1z9u9T3tPVzSKq8x+azx1Zq2yl4p3VubTL9ctrFfSSuV3DrGf7fWwq7Pnglr5lzuvGZkJa0Cx7XeOS7 MIME-Version: 1.0 X-Received: by 2002:a05:6e02:608:: with SMTP id t8mr184634ils.297.1641831885776; Mon, 10 Jan 2022 08:24:45 -0800 (PST) Date: Mon, 10 Jan 2022 08:24:45 -0800 Reply-To: oss-fuzz@monorail-prod.appspotmail.com References: <0=71cc74a7ba1af446b7ed6b9a08b414d9=2c0356afc660f9c3dfa1ade2a69ce6ad=oss-fuzz@monorail-prod.appspotmail.com> X-Google-Appengine-App-Id: s~monorail-prod X-Google-Appengine-App-Id-Alias: monorail-prod Message-ID: <000000000000552c2305d53cc601@google.com> Subject: Issue 43505 in oss-fuzz: elfutils:fuzz-dwfl-core: Use-of-uninitialized-value in handle_file_note From: ClusterFuzz-External via monorail To: elfutils-devel@sourceware.org X-Spam-Status: No, score=-0.8 required=5.0 tests=BAYES_00, DKIMWL_WL_HIGH, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, HEADER_FROM_DIFFERENT_DOMAINS, HTML_MESSAGE, RCVD_IN_DNSWL_NONE, SPF_HELO_NONE, SPF_PASS, TXREP autolearn=ham autolearn_force=no version=3.4.4 X-Spam-Checker-Version: SpamAssassin 3.4.4 (2020-01-24) on server2.sourceware.org Content-Type: text/plain; charset="UTF-8" X-Content-Filtered-By: Mailman/MimeDel 2.1.29 X-BeenThere: elfutils-devel@sourceware.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Elfutils-devel mailing list List-Unsubscribe: , List-Archive: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 10 Jan 2022 16:24:47 -0000 Status: New Owner: ---- CC: elfut...@sourceware.org, evv...@gmail.com, izzeem@google.com Labels: ClusterFuzz Reproducible Stability-Memory-MemorySanitizer Engine-libfuzzer OS-Linux Security_Severity-Medium Proj-elfutils Reported-2022-01-10 Type: Bug-Security New issue 43505 by ClusterFuzz-External: elfutils:fuzz-dwfl-core: Use-of-uninitialized-value in handle_file_note https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=43505 Detailed Report: https://oss-fuzz.com/testcase?key=5344860645752832 Project: elfutils Fuzzing Engine: libFuzzer Fuzz Target: fuzz-dwfl-core Job Type: libfuzzer_msan_elfutils Platform Id: linux Crash Type: Use-of-uninitialized-value Crash Address: Crash State: handle_file_note dwfl_segment_report_module dwfl_core_file_report Sanitizer: memory (MSAN) Recommended Security Severity: Medium Regressed: https://oss-fuzz.com/revisions?job=libfuzzer_msan_elfutils&range=202111300602:202112010612 Reproducer Testcase: https://oss-fuzz.com/download?testcase_id=5344860645752832 Issue filed automatically. See https://google.github.io/oss-fuzz/advanced-topics/reproducing for instructions to reproduce this bug locally. When you fix this bug, please * mention the fix revision(s). * state whether the bug was a short-lived regression or an old bug in any stable releases. * add any other useful information. This information can help downstream consumers. If you need to contact the OSS-Fuzz team with a question, concern, or any other feedback, please file an issue at https://github.com/google/oss-fuzz/issues. Comments on individual Monorail issues are not monitored. -- You received this message because: 1. You were specifically CC'd on the issue You may adjust your notification preferences at: https://bugs.chromium.org/hosting/settings Reply to this email to add a comment.