Wireshark-bugs: [Wireshark-bugs] [Bug 11879] New: Buildbot crash output: fuzz-2015-12-13-11973.p

Date: Mon, 14 Dec 2015 04:50:02 +0000
Bug ID 11879
Summary Buildbot crash output: fuzz-2015-12-13-11973.pcap
Product Wireshark
Version unspecified
Hardware x86-64
URL https://www.wireshark.org/download/automated/captures/fuzz-2015-12-13-11973.pcap
OS Ubuntu
Status CONFIRMED
Severity Major
Priority High
Component Dissection engine (libwireshark)
Assignee [email protected]
Reporter [email protected]

Problems have been found with the following capture file:

https://www.wireshark.org/download/automated/captures/fuzz-2015-12-13-11973.pcap

stderr:
Input file: /home/wireshark/menagerie/menagerie/13693-wifi_packets.pcapng

Build host information:
Linux wsbb04 3.13.0-71-generic #114-Ubuntu SMP Tue Dec 1 02:34:22 UTC 2015
x86_64 x86_64 x86_64 GNU/Linux
Distributor ID:    Ubuntu
Description:    Ubuntu 14.04.3 LTS
Release:    14.04
Codename:    trusty

Buildbot information:
BUILDBOT_REPOSITORY=ssh://[email protected]:29418/wireshark
BUILDBOT_BUILDNUMBER=3441
BUILDBOT_URL=http://buildbot.wireshark.org/wireshark-master/
BUILDBOT_BUILDERNAME=Clang Code Analysis
BUILDBOT_SLAVENAME=clang-code-analysis
BUILDBOT_GOT_REVISION=2ebfa30ffd8c5ef76d06f1705cb7e7797bda954a

Return value:  0

Dissector bug:  0

Valgrind error count:  8



Git commit
commit 2ebfa30ffd8c5ef76d06f1705cb7e7797bda954a
Author: João Valverde <[email protected]>
Date:   Fri Dec 11 13:36:49 2015 +0000

    IPv6: Dest/Hop extension header register_info fixup

    Fixes 90d971014574da1e5615eff1e588d3fb2f9070d2.

    Change-Id: I334c8b1816e08163fc68970b19586734b8194087
    Reviewed-on: https://code.wireshark.org/review/12532
    Reviewed-by: Michael Mann <[email protected]>
    Petri-Dish: Michael Mann <[email protected]>
    Tested-by: Petri Dish Buildbot <[email protected]>
    Reviewed-by: Anders Broman <[email protected]>


Command and args: ./tools/valgrind-wireshark.sh -T

==29810== Memcheck, a memory error detector
==29810== Copyright (C) 2002-2013, and GNU GPL'd, by Julian Seward et al.
==29810== Using Valgrind-3.10.1 and LibVEX; rerun with -h for copyright info
==29810== Command:
/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/bin/tshark
-Vx -nr
/fuzz/buildbot/clangcodeanalysis/valgrind-fuzz/fuzz-2015-12-13-11973.pcap
==29810== 
==29810== Conditional jump or move depends on uninitialised value(s)
==29810==    at 0x6BF9A98: dissect_wlan_radio (packet-ieee80211-radio.c:740)
==29810==    by 0x6830624: call_dissector_through_handle (packet.c:616)
==29810==    by 0x6830624: call_dissector_work (packet.c:691)
==29810==    by 0x682FB5C: call_dissector_only (packet.c:2662)
==29810==    by 0x682FB5C: call_dissector_with_data (packet.c:2675)
==29810==    by 0x6E22112: dissect_ppi (packet-ppi.c:1133)
==29810==    by 0x6830624: call_dissector_through_handle (packet.c:616)
==29810==    by 0x6830624: call_dissector_work (packet.c:691)
==29810==    by 0x68304CE: dissector_try_uint_new (packet.c:1148)
==29810==    by 0x6B26B6F: dissect_frame (packet-frame.c:500)
==29810==    by 0x6830624: call_dissector_through_handle (packet.c:616)
==29810==    by 0x6830624: call_dissector_work (packet.c:691)
==29810==    by 0x682FB5C: call_dissector_only (packet.c:2662)
==29810==    by 0x682FB5C: call_dissector_with_data (packet.c:2675)
==29810==    by 0x682FA35: dissect_record (packet.c:501)
==29810==    by 0x6823ECE: epan_dissect_run_with_taps (epan.c:373)
==29810==    by 0x413BC4: process_packet (tshark.c:3728)
==29810== 
==29810== Conditional jump or move depends on uninitialised value(s)
==29810==    at 0x6BF9ABB: dissect_wlan_radio (packet-ieee80211-radio.c:745)
==29810==    by 0x6830624: call_dissector_through_handle (packet.c:616)
==29810==    by 0x6830624: call_dissector_work (packet.c:691)
==29810==    by 0x682FB5C: call_dissector_only (packet.c:2662)
==29810==    by 0x682FB5C: call_dissector_with_data (packet.c:2675)
==29810==    by 0x6E22112: dissect_ppi (packet-ppi.c:1133)
==29810==    by 0x6830624: call_dissector_through_handle (packet.c:616)
==29810==    by 0x6830624: call_dissector_work (packet.c:691)
==29810==    by 0x68304CE: dissector_try_uint_new (packet.c:1148)
==29810==    by 0x6B26B6F: dissect_frame (packet-frame.c:500)
==29810==    by 0x6830624: call_dissector_through_handle (packet.c:616)
==29810==    by 0x6830624: call_dissector_work (packet.c:691)
==29810==    by 0x682FB5C: call_dissector_only (packet.c:2662)
==29810==    by 0x682FB5C: call_dissector_with_data (packet.c:2675)
==29810==    by 0x682FA35: dissect_record (packet.c:501)
==29810==    by 0x6823ECE: epan_dissect_run_with_taps (epan.c:373)
==29810==    by 0x413BC4: process_packet (tshark.c:3728)
==29810== 
==29810== Conditional jump or move depends on uninitialised value(s)
==29810==    at 0x6BF9ADD: dissect_wlan_radio (packet-ieee80211-radio.c:750)
==29810==    by 0x6830624: call_dissector_through_handle (packet.c:616)
==29810==    by 0x6830624: call_dissector_work (packet.c:691)
==29810==    by 0x682FB5C: call_dissector_only (packet.c:2662)
==29810==    by 0x682FB5C: call_dissector_with_data (packet.c:2675)
==29810==    by 0x6E22112: dissect_ppi (packet-ppi.c:1133)
==29810==    by 0x6830624: call_dissector_through_handle (packet.c:616)
==29810==    by 0x6830624: call_dissector_work (packet.c:691)
==29810==    by 0x68304CE: dissector_try_uint_new (packet.c:1148)
==29810==    by 0x6B26B6F: dissect_frame (packet-frame.c:500)
==29810==    by 0x6830624: call_dissector_through_handle (packet.c:616)
==29810==    by 0x6830624: call_dissector_work (packet.c:691)
==29810==    by 0x682FB5C: call_dissector_only (packet.c:2662)
==29810==    by 0x682FB5C: call_dissector_with_data (packet.c:2675)
==29810==    by 0x682FA35: dissect_record (packet.c:501)
==29810==    by 0x6823ECE: epan_dissect_run_with_taps (epan.c:373)
==29810==    by 0x413BC4: process_packet (tshark.c:3728)
==29810== 
==29810== Conditional jump or move depends on uninitialised value(s)
==29810==    at 0x6BF9B04: dissect_wlan_radio (packet-ieee80211-radio.c:755)
==29810==    by 0x6830624: call_dissector_through_handle (packet.c:616)
==29810==    by 0x6830624: call_dissector_work (packet.c:691)
==29810==    by 0x682FB5C: call_dissector_only (packet.c:2662)
==29810==    by 0x682FB5C: call_dissector_with_data (packet.c:2675)
==29810==    by 0x6E22112: dissect_ppi (packet-ppi.c:1133)
==29810==    by 0x6830624: call_dissector_through_handle (packet.c:616)
==29810==    by 0x6830624: call_dissector_work (packet.c:691)
==29810==    by 0x68304CE: dissector_try_uint_new (packet.c:1148)
==29810==    by 0x6B26B6F: dissect_frame (packet-frame.c:500)
==29810==    by 0x6830624: call_dissector_through_handle (packet.c:616)
==29810==    by 0x6830624: call_dissector_work (packet.c:691)
==29810==    by 0x682FB5C: call_dissector_only (packet.c:2662)
==29810==    by 0x682FB5C: call_dissector_with_data (packet.c:2675)
==29810==    by 0x682FA35: dissect_record (packet.c:501)
==29810==    by 0x6823ECE: epan_dissect_run_with_taps (epan.c:373)
==29810==    by 0x413BC4: process_packet (tshark.c:3728)
==29810== 
==29810== Conditional jump or move depends on uninitialised value(s)
==29810==    at 0x6BF9B2E: dissect_wlan_radio (packet-ieee80211-radio.c:760)
==29810==    by 0x6830624: call_dissector_through_handle (packet.c:616)
==29810==    by 0x6830624: call_dissector_work (packet.c:691)
==29810==    by 0x682FB5C: call_dissector_only (packet.c:2662)
==29810==    by 0x682FB5C: call_dissector_with_data (packet.c:2675)
==29810==    by 0x6E22112: dissect_ppi (packet-ppi.c:1133)
==29810==    by 0x6830624: call_dissector_through_handle (packet.c:616)
==29810==    by 0x6830624: call_dissector_work (packet.c:691)
==29810==    by 0x68304CE: dissector_try_uint_new (packet.c:1148)
==29810==    by 0x6B26B6F: dissect_frame (packet-frame.c:500)
==29810==    by 0x6830624: call_dissector_through_handle (packet.c:616)
==29810==    by 0x6830624: call_dissector_work (packet.c:691)
==29810==    by 0x682FB5C: call_dissector_only (packet.c:2662)
==29810==    by 0x682FB5C: call_dissector_with_data (packet.c:2675)
==29810==    by 0x682FA35: dissect_record (packet.c:501)
==29810==    by 0x6823ECE: epan_dissect_run_with_taps (epan.c:373)
==29810==    by 0x413BC4: process_packet (tshark.c:3728)
==29810== 
==29810== Conditional jump or move depends on uninitialised value(s)
==29810==    at 0x6BF9B59: dissect_wlan_radio (packet-ieee80211-radio.c:765)
==29810==    by 0x6830624: call_dissector_through_handle (packet.c:616)
==29810==    by 0x6830624: call_dissector_work (packet.c:691)
==29810==    by 0x682FB5C: call_dissector_only (packet.c:2662)
==29810==    by 0x682FB5C: call_dissector_with_data (packet.c:2675)
==29810==    by 0x6E22112: dissect_ppi (packet-ppi.c:1133)
==29810==    by 0x6830624: call_dissector_through_handle (packet.c:616)
==29810==    by 0x6830624: call_dissector_work (packet.c:691)
==29810==    by 0x68304CE: dissector_try_uint_new (packet.c:1148)
==29810==    by 0x6B26B6F: dissect_frame (packet-frame.c:500)
==29810==    by 0x6830624: call_dissector_through_handle (packet.c:616)
==29810==    by 0x6830624: call_dissector_work (packet.c:691)
==29810==    by 0x682FB5C: call_dissector_only (packet.c:2662)
==29810==    by 0x682FB5C: call_dissector_with_data (packet.c:2675)
==29810==    by 0x682FA35: dissect_record (packet.c:501)
==29810==    by 0x6823ECE: epan_dissect_run_with_taps (epan.c:373)
==29810==    by 0x413BC4: process_packet (tshark.c:3728)
==29810== 
==29810== Conditional jump or move depends on uninitialised value(s)
==29810==    at 0x6BF9B84: dissect_wlan_radio (packet-ieee80211-radio.c:770)
==29810==    by 0x6830624: call_dissector_through_handle (packet.c:616)
==29810==    by 0x6830624: call_dissector_work (packet.c:691)
==29810==    by 0x682FB5C: call_dissector_only (packet.c:2662)
==29810==    by 0x682FB5C: call_dissector_with_data (packet.c:2675)
==29810==    by 0x6E22112: dissect_ppi (packet-ppi.c:1133)
==29810==    by 0x6830624: call_dissector_through_handle (packet.c:616)
==29810==    by 0x6830624: call_dissector_work (packet.c:691)
==29810==    by 0x68304CE: dissector_try_uint_new (packet.c:1148)
==29810==    by 0x6B26B6F: dissect_frame (packet-frame.c:500)
==29810==    by 0x6830624: call_dissector_through_handle (packet.c:616)
==29810==    by 0x6830624: call_dissector_work (packet.c:691)
==29810==    by 0x682FB5C: call_dissector_only (packet.c:2662)
==29810==    by 0x682FB5C: call_dissector_with_data (packet.c:2675)
==29810==    by 0x682FA35: dissect_record (packet.c:501)
==29810==    by 0x6823ECE: epan_dissect_run_with_taps (epan.c:373)
==29810==    by 0x413BC4: process_packet (tshark.c:3728)
==29810== 
==29810== Conditional jump or move depends on uninitialised value(s)
==29810==    at 0x6BF9BAA: dissect_wlan_radio (packet-ieee80211-radio.c:784)
==29810==    by 0x6830624: call_dissector_through_handle (packet.c:616)
==29810==    by 0x6830624: call_dissector_work (packet.c:691)
==29810==    by 0x682FB5C: call_dissector_only (packet.c:2662)
==29810==    by 0x682FB5C: call_dissector_with_data (packet.c:2675)
==29810==    by 0x6E22112: dissect_ppi (packet-ppi.c:1133)
==29810==    by 0x6830624: call_dissector_through_handle (packet.c:616)
==29810==    by 0x6830624: call_dissector_work (packet.c:691)
==29810==    by 0x68304CE: dissector_try_uint_new (packet.c:1148)
==29810==    by 0x6B26B6F: dissect_frame (packet-frame.c:500)
==29810==    by 0x6830624: call_dissector_through_handle (packet.c:616)
==29810==    by 0x6830624: call_dissector_work (packet.c:691)
==29810==    by 0x682FB5C: call_dissector_only (packet.c:2662)
==29810==    by 0x682FB5C: call_dissector_with_data (packet.c:2675)
==29810==    by 0x682FA35: dissect_record (packet.c:501)
==29810==    by 0x6823ECE: epan_dissect_run_with_taps (epan.c:373)
==29810==    by 0x413BC4: process_packet (tshark.c:3728)
==29810== 
==29810== 
==29810== HEAP SUMMARY:
==29810==     in use at exit: 1,039,891 bytes in 28,310 blocks
==29810==   total heap usage: 400,599 allocs, 372,289 frees, 43,502,159 bytes
allocated
==29810== 
==29810== LEAK SUMMARY:
==29810==    definitely lost: 2,908 bytes in 125 blocks
==29810==    indirectly lost: 36,448 bytes in 48 blocks
==29810==      possibly lost: 0 bytes in 0 blocks
==29810==    still reachable: 1,000,535 bytes in 28,137 blocks
==29810==         suppressed: 0 bytes in 0 blocks
==29810== Rerun with --leak-check=full to see details of leaked memory
==29810== 
==29810== For counts of detected and suppressed errors, rerun with: -v
==29810== Use --track-origins=yes to see where uninitialised values come from
==29810== ERROR SUMMARY: 8 errors from 8 contexts (suppressed: 0 from 0)

[ no debug trace ]


You are receiving this mail because:
  • You are watching all bug changes.