Wireshark-bugs: [Wireshark-bugs] [Bug 11127] New: Buildbot crash output: fuzz-2015-04-17-20798.p

Date: Fri, 17 Apr 2015 22:40:03 +0000
Bug ID 11127
Summary Buildbot crash output: fuzz-2015-04-17-20798.pcap
Product Wireshark
Version unspecified
Hardware x86-64
URL https://www.wireshark.org/download/automated/captures/fuzz-2015-04-17-20798.pcap
OS Ubuntu
Status CONFIRMED
Severity Major
Priority High
Component Dissection engine (libwireshark)
Assignee [email protected]
Reporter [email protected]

Problems have been found with the following capture file:

https://www.wireshark.org/download/automated/captures/fuzz-2015-04-17-20798.pcap

stderr:
Input file:
/home/wireshark/menagerie/menagerie/12570-TESTCYCL_46145_4GLOCL18.pcap

Build host information:
Linux wsbb04 3.13.0-46-generic #79-Ubuntu SMP Tue Mar 10 20:06:50 UTC 2015
x86_64 x86_64 x86_64 GNU/Linux
Distributor ID:    Ubuntu
Description:    Ubuntu 14.04.2 LTS
Release:    14.04
Codename:    trusty

Buildbot information:
BUILDBOT_REPOSITORY=ssh://[email protected]:29418/wireshark
BUILDBOT_BUILDNUMBER=3205
BUILDBOT_URL=http://buildbot.wireshark.org/trunk/
BUILDBOT_BUILDERNAME=Clang Code Analysis
BUILDBOT_SLAVENAME=clang-code-analysis
BUILDBOT_GOT_REVISION=b845785a73e4d2224da6b2e1ca7be7a76de07352

Return value:  0

Dissector bug:  0

Valgrind error count:  4738



Git commit
commit b845785a73e4d2224da6b2e1ca7be7a76de07352
Author: Gerald Combs <[email protected]>
Date:   Wed Apr 15 16:23:56 2015 -0700

    CMake: Try not to clobber our gspawn exes.

    Try not to overwrite gspawn*.exe between signing them and packaging
    them. (Second try.)

    Change-Id: I717f5fca6dc6afbc146927d06e6f74ae6a0a87c8
    Reviewed-on: https://code.wireshark.org/review/8082
    Reviewed-by: Gerald Combs <[email protected]>


Command and args: ./tools/valgrind-wireshark.sh 

==25302== Memcheck, a memory error detector
==25302== Copyright (C) 2002-2013, and GNU GPL'd, by Julian Seward et al.
==25302== Using Valgrind-3.10.0.SVN and LibVEX; rerun with -h for copyright
info
==25302== Command:
/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/bin/tshark
-nr /fuzz/buildbot/clangcodeanalysis/valgrind-fuzz/fuzz-2015-04-17-20798.pcap
==25302== 
==25302== Use of uninitialised value of size 8
==25302==    at 0x9F5C068: ??? (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==25302==    by 0x6A26009: dissect_giop_common (packet-giop.c:4869)
==25302==    by 0x6E85AB7: tcp_dissect_pdus (packet-tcp.c:2477)
==25302==    by 0x6A249A5: dissect_giop_tcp (packet-giop.c:4984)
==25302==    by 0x6A247F0: dissect_giop_heur (packet-giop.c:5027)
==25302==    by 0x672E156: dissector_try_heuristic (packet.c:2041)
==25302==    by 0x6E85E34: decode_tcp_ports (packet-tcp.c:4141)
==25302==    by 0x6E86E19: process_tcp_payload (packet-tcp.c:4187)
==25302==    by 0x6E8636E: dissect_tcp_payload (packet-tcp.c:1997)
==25302==    by 0x6E89E70: dissect_tcp (packet-tcp.c:5075)
==25302==    by 0x672D12D: call_dissector_work (packet.c:614)
==25302==    by 0x672CFAE: dissector_try_uint_new (packet.c:1132)
==25302== 
==25302== Use of uninitialised value of size 8
==25302==    at 0x9F5BE9B: ??? (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==25302==    by 0x9F5C106: ??? (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==25302==    by 0x6A26009: dissect_giop_common (packet-giop.c:4869)
==25302==    by 0x6E85AB7: tcp_dissect_pdus (packet-tcp.c:2477)
==25302==    by 0x6A249A5: dissect_giop_tcp (packet-giop.c:4984)
==25302==    by 0x6A247F0: dissect_giop_heur (packet-giop.c:5027)
==25302==    by 0x672E156: dissector_try_heuristic (packet.c:2041)
==25302==    by 0x6E85E34: decode_tcp_ports (packet-tcp.c:4141)
==25302==    by 0x6E86E19: process_tcp_payload (packet-tcp.c:4187)
==25302==    by 0x6E8636E: dissect_tcp_payload (packet-tcp.c:1997)
==25302==    by 0x6E89E70: dissect_tcp (packet-tcp.c:5075)
==25302==    by 0x672D12D: call_dissector_work (packet.c:614)
==25302== 
==25302== Use of uninitialised value of size 8
==25302==    at 0x9F5BF38: ??? (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==25302==    by 0x9F5C106: ??? (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==25302==    by 0x6A26009: dissect_giop_common (packet-giop.c:4869)
==25302==    by 0x6E85AB7: tcp_dissect_pdus (packet-tcp.c:2477)
==25302==    by 0x6A249A5: dissect_giop_tcp (packet-giop.c:4984)
==25302==    by 0x6A247F0: dissect_giop_heur (packet-giop.c:5027)
==25302==    by 0x672E156: dissector_try_heuristic (packet.c:2041)
==25302==    by 0x6E85E34: decode_tcp_ports (packet-tcp.c:4141)
==25302==    by 0x6E86E19: process_tcp_payload (packet-tcp.c:4187)
==25302==    by 0x6E8636E: dissect_tcp_payload (packet-tcp.c:1997)
==25302==    by 0x6E89E70: dissect_tcp (packet-tcp.c:5075)
==25302==    by 0x672D12D: call_dissector_work (packet.c:614)
==25302== 
==25302== Use of uninitialised value of size 8
==25302==    at 0x9F5BF49: ??? (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==25302==    by 0x9F5C106: ??? (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==25302==    by 0x6A26009: dissect_giop_common (packet-giop.c:4869)
==25302==    by 0x6E85AB7: tcp_dissect_pdus (packet-tcp.c:2477)
==25302==    by 0x6A249A5: dissect_giop_tcp (packet-giop.c:4984)
==25302==    by 0x6A247F0: dissect_giop_heur (packet-giop.c:5027)
==25302==    by 0x672E156: dissector_try_heuristic (packet.c:2041)
==25302==    by 0x6E85E34: decode_tcp_ports (packet-tcp.c:4141)
==25302==    by 0x6E86E19: process_tcp_payload (packet-tcp.c:4187)
==25302==    by 0x6E8636E: dissect_tcp_payload (packet-tcp.c:1997)
==25302==    by 0x6E89E70: dissect_tcp (packet-tcp.c:5075)
==25302==    by 0x672D12D: call_dissector_work (packet.c:614)
==25302== 
==25302== Use of uninitialised value of size 8
==25302==    at 0x9F5BF5D: ??? (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==25302==    by 0x9F5C106: ??? (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==25302==    by 0x6A26009: dissect_giop_common (packet-giop.c:4869)
==25302==    by 0x6E85AB7: tcp_dissect_pdus (packet-tcp.c:2477)
==25302==    by 0x6A249A5: dissect_giop_tcp (packet-giop.c:4984)
==25302==    by 0x6A247F0: dissect_giop_heur (packet-giop.c:5027)
==25302==    by 0x672E156: dissector_try_heuristic (packet.c:2041)
==25302==    by 0x6E85E34: decode_tcp_ports (packet-tcp.c:4141)
==25302==    by 0x6E86E19: process_tcp_payload (packet-tcp.c:4187)
==25302==    by 0x6E8636E: dissect_tcp_payload (packet-tcp.c:1997)
==25302==    by 0x6E89E70: dissect_tcp (packet-tcp.c:5075)
==25302==    by 0x672D12D: call_dissector_work (packet.c:614)
==25302== 
==25302== Conditional jump or move depends on uninitialised value(s)
==25302==    at 0x9F5BF61: ??? (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==25302==    by 0x9F5C106: ??? (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==25302==    by 0x6A26009: dissect_giop_common (packet-giop.c:4869)
==25302==    by 0x6E85AB7: tcp_dissect_pdus (packet-tcp.c:2477)
==25302==    by 0x6A249A5: dissect_giop_tcp (packet-giop.c:4984)
==25302==    by 0x6A247F0: dissect_giop_heur (packet-giop.c:5027)
==25302==    by 0x672E156: dissector_try_heuristic (packet.c:2041)
==25302==    by 0x6E85E34: decode_tcp_ports (packet-tcp.c:4141)
==25302==    by 0x6E86E19: process_tcp_payload (packet-tcp.c:4187)
==25302==    by 0x6E8636E: dissect_tcp_payload (packet-tcp.c:1997)
==25302==    by 0x6E89E70: dissect_tcp (packet-tcp.c:5075)
==25302==    by 0x672D12D: call_dissector_work (packet.c:614)
==25302== 
==25302== Use of uninitialised value of size 8
==25302==    at 0x9F5BED9: ??? (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==25302==    by 0x9F5C106: ??? (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==25302==    by 0x6A26009: dissect_giop_common (packet-giop.c:4869)
==25302==    by 0x6E85AB7: tcp_dissect_pdus (packet-tcp.c:2477)
==25302==    by 0x6A249A5: dissect_giop_tcp (packet-giop.c:4984)
==25302==    by 0x6A247F0: dissect_giop_heur (packet-giop.c:5027)
==25302==    by 0x672E156: dissector_try_heuristic (packet.c:2041)
==25302==    by 0x6E85E34: decode_tcp_ports (packet-tcp.c:4141)
==25302==    by 0x6E86E19: process_tcp_payload (packet-tcp.c:4187)
==25302==    by 0x6E8636E: dissect_tcp_payload (packet-tcp.c:1997)
==25302==    by 0x6E89E70: dissect_tcp (packet-tcp.c:5075)
==25302==    by 0x672D12D: call_dissector_work (packet.c:614)
==25302== 
==25302== Conditional jump or move depends on uninitialised value(s)
==25302==    at 0x9F5C06D: ??? (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==25302==    by 0x6A26009: dissect_giop_common (packet-giop.c:4869)
==25302==    by 0x6E85AB7: tcp_dissect_pdus (packet-tcp.c:2477)
==25302==    by 0x6A249A5: dissect_giop_tcp (packet-giop.c:4984)
==25302==    by 0x672D10F: call_dissector_work (packet.c:612)
==25302==    by 0x671DDFE: try_conversation_dissector (conversation.c:1312)
==25302==    by 0x6E85CE6: decode_tcp_ports (packet-tcp.c:4083)
==25302==    by 0x6E86E19: process_tcp_payload (packet-tcp.c:4187)
==25302==    by 0x6E8636E: dissect_tcp_payload (packet-tcp.c:1997)
==25302==    by 0x6E89E70: dissect_tcp (packet-tcp.c:5075)
==25302==    by 0x672D12D: call_dissector_work (packet.c:614)
==25302==    by 0x672CFAE: dissector_try_uint_new (packet.c:1132)
==25302== 
==25302== Conditional jump or move depends on uninitialised value(s)
==25302==    at 0x9F5C0A4: ??? (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==25302==    by 0x6A26009: dissect_giop_common (packet-giop.c:4869)
==25302==    by 0x6E85AB7: tcp_dissect_pdus (packet-tcp.c:2477)
==25302==    by 0x6A249A5: dissect_giop_tcp (packet-giop.c:4984)
==25302==    by 0x672D10F: call_dissector_work (packet.c:612)
==25302==    by 0x671DDFE: try_conversation_dissector (conversation.c:1312)
==25302==    by 0x6E85CE6: decode_tcp_ports (packet-tcp.c:4083)
==25302==    by 0x6E86E19: process_tcp_payload (packet-tcp.c:4187)
==25302==    by 0x6E8636E: dissect_tcp_payload (packet-tcp.c:1997)
==25302==    by 0x6E89E70: dissect_tcp (packet-tcp.c:5075)
==25302==    by 0x672D12D: call_dissector_work (packet.c:614)
==25302==    by 0x672CFAE: dissector_try_uint_new (packet.c:1132)
==25302== 
==25302== Use of uninitialised value of size 8
==25302==    at 0x9F5C0AC: ??? (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==25302==    by 0x6A26009: dissect_giop_common (packet-giop.c:4869)
==25302==    by 0x6E85AB7: tcp_dissect_pdus (packet-tcp.c:2477)
==25302==    by 0x6A249A5: dissect_giop_tcp (packet-giop.c:4984)
==25302==    by 0x672D10F: call_dissector_work (packet.c:612)
==25302==    by 0x671DDFE: try_conversation_dissector (conversation.c:1312)
==25302==    by 0x6E85CE6: decode_tcp_ports (packet-tcp.c:4083)
==25302==    by 0x6E86E19: process_tcp_payload (packet-tcp.c:4187)
==25302==    by 0x6E8636E: dissect_tcp_payload (packet-tcp.c:1997)
==25302==    by 0x6E89E70: dissect_tcp (packet-tcp.c:5075)
==25302==    by 0x672D12D: call_dissector_work (packet.c:614)
==25302==    by 0x672CFAE: dissector_try_uint_new (packet.c:1132)
==25302== 
==25302== Conditional jump or move depends on uninitialised value(s)
==25302==    at 0x9F5C0C2: ??? (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==25302==    by 0x6A26009: dissect_giop_common (packet-giop.c:4869)
==25302==    by 0x6E85AB7: tcp_dissect_pdus (packet-tcp.c:2477)
==25302==    by 0x6A249A5: dissect_giop_tcp (packet-giop.c:4984)
==25302==    by 0x672D10F: call_dissector_work (packet.c:612)
==25302==    by 0x671DDFE: try_conversation_dissector (conversation.c:1312)
==25302==    by 0x6E85CE6: decode_tcp_ports (packet-tcp.c:4083)
==25302==    by 0x6E86E19: process_tcp_payload (packet-tcp.c:4187)
==25302==    by 0x6E8636E: dissect_tcp_payload (packet-tcp.c:1997)
==25302==    by 0x6E89E70: dissect_tcp (packet-tcp.c:5075)
==25302==    by 0x672D12D: call_dissector_work (packet.c:614)
==25302==    by 0x672CFAE: dissector_try_uint_new (packet.c:1132)
==25302== 
==25302== Conditional jump or move depends on uninitialised value(s)
==25302==    at 0x9F5BEAD: ??? (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==25302==    by 0x9F5C106: ??? (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==25302==    by 0x6A26009: dissect_giop_common (packet-giop.c:4869)
==25302==    by 0x6E85AB7: tcp_dissect_pdus (packet-tcp.c:2477)
==25302==    by 0x6A249A5: dissect_giop_tcp (packet-giop.c:4984)
==25302==    by 0x672D10F: call_dissector_work (packet.c:612)
==25302==    by 0x671DDFE: try_conversation_dissector (conversation.c:1312)
==25302==    by 0x6E85CE6: decode_tcp_ports (packet-tcp.c:4083)
==25302==    by 0x6E86E19: process_tcp_payload (packet-tcp.c:4187)
==25302==    by 0x6E8636E: dissect_tcp_payload (packet-tcp.c:1997)
==25302==    by 0x6E89E70: dissect_tcp (packet-tcp.c:5075)
==25302==    by 0x672D12D: call_dissector_work (packet.c:614)
==25302== 
==25302== Use of uninitialised value of size 8
==25302==    at 0x9F5BEC2: ??? (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==25302==    by 0x9F5C106: ??? (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==25302==    by 0x6A26009: dissect_giop_common (packet-giop.c:4869)
==25302==    by 0x6E85AB7: tcp_dissect_pdus (packet-tcp.c:2477)
==25302==    by 0x6A249A5: dissect_giop_tcp (packet-giop.c:4984)
==25302==    by 0x672D10F: call_dissector_work (packet.c:612)
==25302==    by 0x671DDFE: try_conversation_dissector (conversation.c:1312)
==25302==    by 0x6E85CE6: decode_tcp_ports (packet-tcp.c:4083)
==25302==    by 0x6E86E19: process_tcp_payload (packet-tcp.c:4187)
==25302==    by 0x6E8636E: dissect_tcp_payload (packet-tcp.c:1997)
==25302==    by 0x6E89E70: dissect_tcp (packet-tcp.c:5075)
==25302==    by 0x672D12D: call_dissector_work (packet.c:614)
==25302== 
==25302== Conditional jump or move depends on uninitialised value(s)
==25302==    at 0x9F5BEDD: ??? (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==25302==    by 0x9F5C106: ??? (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==25302==    by 0x6A26009: dissect_giop_common (packet-giop.c:4869)
==25302==    by 0x6E85AB7: tcp_dissect_pdus (packet-tcp.c:2477)
==25302==    by 0x6A249A5: dissect_giop_tcp (packet-giop.c:4984)
==25302==    by 0x672D10F: call_dissector_work (packet.c:612)
==25302==    by 0x671DDFE: try_conversation_dissector (conversation.c:1312)
==25302==    by 0x6E85CE6: decode_tcp_ports (packet-tcp.c:4083)
==25302==    by 0x6E86E19: process_tcp_payload (packet-tcp.c:4187)
==25302==    by 0x6E8636E: dissect_tcp_payload (packet-tcp.c:1997)
==25302==    by 0x6E89E70: dissect_tcp (packet-tcp.c:5075)
==25302==    by 0x672D12D: call_dissector_work (packet.c:614)
==25302== 
==25302== 
==25302== HEAP SUMMARY:
==25302==     in use at exit: 1,287,589 bytes in 31,321 blocks
==25302==   total heap usage: 1,338,712 allocs, 1,307,391 frees, 77,455,337
bytes allocated
==25302== 
==25302== LEAK SUMMARY:
==25302==    definitely lost: 7,920 bytes in 558 blocks
==25302==    indirectly lost: 94,096 bytes in 995 blocks
==25302==      possibly lost: 0 bytes in 0 blocks
==25302==    still reachable: 1,185,573 bytes in 29,768 blocks
==25302==         suppressed: 0 bytes in 0 blocks
==25302== Rerun with --leak-check=full to see details of leaked memory
==25302== 
==25302== For counts of detected and suppressed errors, rerun with: -v
==25302== Use --track-origins=yes to see where uninitialised values come from
==25302== ERROR SUMMARY: 4738 errors from 14 contexts (suppressed: 1 from 1)

[ no debug trace ]


You are receiving this mail because:
  • You are watching all bug changes.