Wireshark-bugs: [Wireshark-bugs] [Bug 10570] New: Buildbot crash output: fuzz-2014-10-10-4420.pc

Date: Tue, 14 Oct 2014 20:40:11 +0000
Bug ID 10570
Summary Buildbot crash output: fuzz-2014-10-10-4420.pcap
Product Wireshark
Version unspecified
Hardware x86-64
URL https://www.wireshark.org/download/automated/captures/fuzz-2014-10-10-4420.pcap
OS Ubuntu
Status CONFIRMED
Severity Major
Priority High
Component Dissection engine (libwireshark)
Assignee [email protected]
Reporter [email protected]

Problems have been found with the following capture file:

https://www.wireshark.org/download/automated/captures/fuzz-2014-10-10-4420.pcap

stderr:
Input file:
/home/wireshark/menagerie/menagerie/8969-smb3_encryption-ntlmssp-A1b2C3d4.pcap.gz

Build host information:
Linux wsbb04 3.13.0-37-generic #64-Ubuntu SMP Mon Sep 22 21:28:38 UTC 2014
x86_64 x86_64 x86_64 GNU/Linux
Distributor ID:    Ubuntu
Description:    Ubuntu 14.04.1 LTS
Release:    14.04
Codename:    trusty

Buildbot information:
BUILDBOT_REPOSITORY=ssh://[email protected]:29418/wireshark
BUILDBOT_BUILDNUMBER=3001
BUILDBOT_URL=http://buildbot.wireshark.org/trunk/
BUILDBOT_BUILDERNAME=Clang Code Analysis
BUILDBOT_SLAVENAME=clang-code-analysis
BUILDBOT_GOT_REVISION=bdbc8e3a79ae7ca7b4d5f100b985f0f1699a33fd

Return value:  0

Dissector bug:  0

Valgrind error count:  128



Git commit
commit bdbc8e3a79ae7ca7b4d5f100b985f0f1699a33fd
Author: AndersBroman <[email protected]>
Date:   Fri Oct 10 15:41:53 2014 +0200

    GTPv2: Presence-Reporting-Area-Elements-List do full dissection of ECGI
    and TAI.

    Change-Id: I95d9ebf1d6f4eabe30b557fdc937d56006f8b123
    Reviewed-on: https://code.wireshark.org/review/4593
    Reviewed-by: Anders Broman <[email protected]>


Command and args: ./tools/valgrind-wireshark.sh 

==24477== Memcheck, a memory error detector
==24477== Copyright (C) 2002-2013, and GNU GPL'd, by Julian Seward et al.
==24477== Using Valgrind-3.10.0.SVN and LibVEX; rerun with -h for copyright
info
==24477== Command:
/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/bin/tshark
-nr /fuzz/buildbot/clangcodeanalysis/valgrind-fuzz/fuzz-2014-10-10-4420.pcap
==24477== 
==24477== Use of uninitialised value of size 8
==24477==    at 0x4C30C09: __memcmp_sse4_1 (in
/usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==24477==    by 0x6D38642: dissect_smb2 (packet-smb2.c:6719)
==24477==    by 0x6D38D06: dissect_smb2_heur (packet-smb2.c:7223)
==24477==    by 0x6685D49: dissector_try_heuristic (packet.c:2028)
==24477==    by 0x6B8358D: dissect_netbios_payload (packet-netbios.c:1076)
==24477==    by 0x6B4DC47: dissect_nbss_packet (packet-nbns.c:1484)
==24477==    by 0x6B4DE1D: dissect_nbss (packet-nbns.c:1804)
==24477==    by 0x6683F3E: call_dissector_through_handle (packet.c:622)
==24477==    by 0x6684824: call_dissector_work (packet.c:713)
==24477==    by 0x6684EDB: dissector_try_uint_new (packet.c:1145)
==24477==    by 0x6D7F88B: decode_tcp_ports (packet-tcp.c:4035)
==24477==    by 0x6D7FBFE: process_tcp_payload (packet-tcp.c:4107)
==24477== 
==24477== Conditional jump or move depends on uninitialised value(s)
==24477==    at 0x4C30C11: __memcmp_sse4_1 (in
/usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==24477==    by 0x6D38642: dissect_smb2 (packet-smb2.c:6719)
==24477==    by 0x6D38D06: dissect_smb2_heur (packet-smb2.c:7223)
==24477==    by 0x6685D49: dissector_try_heuristic (packet.c:2028)
==24477==    by 0x6B8358D: dissect_netbios_payload (packet-netbios.c:1076)
==24477==    by 0x6B4DC47: dissect_nbss_packet (packet-nbns.c:1484)
==24477==    by 0x6B4DE1D: dissect_nbss (packet-nbns.c:1804)
==24477==    by 0x6683F3E: call_dissector_through_handle (packet.c:622)
==24477==    by 0x6684824: call_dissector_work (packet.c:713)
==24477==    by 0x6684EDB: dissector_try_uint_new (packet.c:1145)
==24477==    by 0x6D7F88B: decode_tcp_ports (packet-tcp.c:4035)
==24477==    by 0x6D7FBFE: process_tcp_payload (packet-tcp.c:4107)
==24477== 
==24477== Use of uninitialised value of size 8
==24477==    at 0x4C30C20: __memcmp_sse4_1 (in
/usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==24477==    by 0x6D38642: dissect_smb2 (packet-smb2.c:6719)
==24477==    by 0x6D38D06: dissect_smb2_heur (packet-smb2.c:7223)
==24477==    by 0x6685D49: dissector_try_heuristic (packet.c:2028)
==24477==    by 0x6B8358D: dissect_netbios_payload (packet-netbios.c:1076)
==24477==    by 0x6B4DC47: dissect_nbss_packet (packet-nbns.c:1484)
==24477==    by 0x6B4DE1D: dissect_nbss (packet-nbns.c:1804)
==24477==    by 0x6683F3E: call_dissector_through_handle (packet.c:622)
==24477==    by 0x6684824: call_dissector_work (packet.c:713)
==24477==    by 0x6684EDB: dissector_try_uint_new (packet.c:1145)
==24477==    by 0x6D7F88B: decode_tcp_ports (packet-tcp.c:4035)
==24477==    by 0x6D7FBFE: process_tcp_payload (packet-tcp.c:4107)
==24477== 
==24477== Conditional jump or move depends on uninitialised value(s)
==24477==    at 0x4C30C32: __memcmp_sse4_1 (in
/usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==24477==    by 0x6D38642: dissect_smb2 (packet-smb2.c:6719)
==24477==    by 0x6D38D06: dissect_smb2_heur (packet-smb2.c:7223)
==24477==    by 0x6685D49: dissector_try_heuristic (packet.c:2028)
==24477==    by 0x6B8358D: dissect_netbios_payload (packet-netbios.c:1076)
==24477==    by 0x6B4DC47: dissect_nbss_packet (packet-nbns.c:1484)
==24477==    by 0x6B4DE1D: dissect_nbss (packet-nbns.c:1804)
==24477==    by 0x6683F3E: call_dissector_through_handle (packet.c:622)
==24477==    by 0x6684824: call_dissector_work (packet.c:713)
==24477==    by 0x6684EDB: dissector_try_uint_new (packet.c:1145)
==24477==    by 0x6D7F88B: decode_tcp_ports (packet-tcp.c:4035)
==24477==    by 0x6D7FBFE: process_tcp_payload (packet-tcp.c:4107)
==24477== 
==24477== 
==24477== HEAP SUMMARY:
==24477==     in use at exit: 1,216,602 bytes in 29,625 blocks
==24477==   total heap usage: 226,997 allocs, 197,372 frees, 28,743,890 bytes
allocated
==24477== 
==24477== LEAK SUMMARY:
==24477==    definitely lost: 5,568 bytes in 167 blocks
==24477==    indirectly lost: 36,840 bytes in 53 blocks
==24477==      possibly lost: 0 bytes in 0 blocks
==24477==    still reachable: 1,174,194 bytes in 29,405 blocks
==24477==         suppressed: 0 bytes in 0 blocks
==24477== Rerun with --leak-check=full to see details of leaked memory
==24477== 
==24477== For counts of detected and suppressed errors, rerun with: -v
==24477== Use --track-origins=yes to see where uninitialised values come from
==24477== ERROR SUMMARY: 128 errors from 4 contexts (suppressed: 0 from 0)

[ no debug trace ]


You are receiving this mail because:
  • You are watching all bug changes.