Wireshark-bugs: [Wireshark-bugs] [Bug 11879] New: Buildbot crash output: fuzz-2015-12-13-11973.p
Date: Mon, 14 Dec 2015 04:50:02 +0000
Bug ID | 11879 |
---|---|
Summary | Buildbot crash output: fuzz-2015-12-13-11973.pcap |
Product | Wireshark |
Version | unspecified |
Hardware | x86-64 |
URL | https://www.wireshark.org/download/automated/captures/fuzz-2015-12-13-11973.pcap |
OS | Ubuntu |
Status | CONFIRMED |
Severity | Major |
Priority | High |
Component | Dissection engine (libwireshark) |
Assignee | [email protected] |
Reporter | [email protected] |
Problems have been found with the following capture file: https://www.wireshark.org/download/automated/captures/fuzz-2015-12-13-11973.pcap stderr: Input file: /home/wireshark/menagerie/menagerie/13693-wifi_packets.pcapng Build host information: Linux wsbb04 3.13.0-71-generic #114-Ubuntu SMP Tue Dec 1 02:34:22 UTC 2015 x86_64 x86_64 x86_64 GNU/Linux Distributor ID: Ubuntu Description: Ubuntu 14.04.3 LTS Release: 14.04 Codename: trusty Buildbot information: BUILDBOT_REPOSITORY=ssh://[email protected]:29418/wireshark BUILDBOT_BUILDNUMBER=3441 BUILDBOT_URL=http://buildbot.wireshark.org/wireshark-master/ BUILDBOT_BUILDERNAME=Clang Code Analysis BUILDBOT_SLAVENAME=clang-code-analysis BUILDBOT_GOT_REVISION=2ebfa30ffd8c5ef76d06f1705cb7e7797bda954a Return value: 0 Dissector bug: 0 Valgrind error count: 8 Git commit commit 2ebfa30ffd8c5ef76d06f1705cb7e7797bda954a Author: João Valverde <[email protected]> Date: Fri Dec 11 13:36:49 2015 +0000 IPv6: Dest/Hop extension header register_info fixup Fixes 90d971014574da1e5615eff1e588d3fb2f9070d2. Change-Id: I334c8b1816e08163fc68970b19586734b8194087 Reviewed-on: https://code.wireshark.org/review/12532 Reviewed-by: Michael Mann <[email protected]> Petri-Dish: Michael Mann <[email protected]> Tested-by: Petri Dish Buildbot <[email protected]> Reviewed-by: Anders Broman <[email protected]> Command and args: ./tools/valgrind-wireshark.sh -T ==29810== Memcheck, a memory error detector ==29810== Copyright (C) 2002-2013, and GNU GPL'd, by Julian Seward et al. ==29810== Using Valgrind-3.10.1 and LibVEX; rerun with -h for copyright info ==29810== Command: /home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/bin/tshark -Vx -nr /fuzz/buildbot/clangcodeanalysis/valgrind-fuzz/fuzz-2015-12-13-11973.pcap ==29810== ==29810== Conditional jump or move depends on uninitialised value(s) ==29810== at 0x6BF9A98: dissect_wlan_radio (packet-ieee80211-radio.c:740) ==29810== by 0x6830624: call_dissector_through_handle (packet.c:616) ==29810== by 0x6830624: call_dissector_work (packet.c:691) ==29810== by 0x682FB5C: call_dissector_only (packet.c:2662) ==29810== by 0x682FB5C: call_dissector_with_data (packet.c:2675) ==29810== by 0x6E22112: dissect_ppi (packet-ppi.c:1133) ==29810== by 0x6830624: call_dissector_through_handle (packet.c:616) ==29810== by 0x6830624: call_dissector_work (packet.c:691) ==29810== by 0x68304CE: dissector_try_uint_new (packet.c:1148) ==29810== by 0x6B26B6F: dissect_frame (packet-frame.c:500) ==29810== by 0x6830624: call_dissector_through_handle (packet.c:616) ==29810== by 0x6830624: call_dissector_work (packet.c:691) ==29810== by 0x682FB5C: call_dissector_only (packet.c:2662) ==29810== by 0x682FB5C: call_dissector_with_data (packet.c:2675) ==29810== by 0x682FA35: dissect_record (packet.c:501) ==29810== by 0x6823ECE: epan_dissect_run_with_taps (epan.c:373) ==29810== by 0x413BC4: process_packet (tshark.c:3728) ==29810== ==29810== Conditional jump or move depends on uninitialised value(s) ==29810== at 0x6BF9ABB: dissect_wlan_radio (packet-ieee80211-radio.c:745) ==29810== by 0x6830624: call_dissector_through_handle (packet.c:616) ==29810== by 0x6830624: call_dissector_work (packet.c:691) ==29810== by 0x682FB5C: call_dissector_only (packet.c:2662) ==29810== by 0x682FB5C: call_dissector_with_data (packet.c:2675) ==29810== by 0x6E22112: dissect_ppi (packet-ppi.c:1133) ==29810== by 0x6830624: call_dissector_through_handle (packet.c:616) ==29810== by 0x6830624: call_dissector_work (packet.c:691) ==29810== by 0x68304CE: dissector_try_uint_new (packet.c:1148) ==29810== by 0x6B26B6F: dissect_frame (packet-frame.c:500) ==29810== by 0x6830624: call_dissector_through_handle (packet.c:616) ==29810== by 0x6830624: call_dissector_work (packet.c:691) ==29810== by 0x682FB5C: call_dissector_only (packet.c:2662) ==29810== by 0x682FB5C: call_dissector_with_data (packet.c:2675) ==29810== by 0x682FA35: dissect_record (packet.c:501) ==29810== by 0x6823ECE: epan_dissect_run_with_taps (epan.c:373) ==29810== by 0x413BC4: process_packet (tshark.c:3728) ==29810== ==29810== Conditional jump or move depends on uninitialised value(s) ==29810== at 0x6BF9ADD: dissect_wlan_radio (packet-ieee80211-radio.c:750) ==29810== by 0x6830624: call_dissector_through_handle (packet.c:616) ==29810== by 0x6830624: call_dissector_work (packet.c:691) ==29810== by 0x682FB5C: call_dissector_only (packet.c:2662) ==29810== by 0x682FB5C: call_dissector_with_data (packet.c:2675) ==29810== by 0x6E22112: dissect_ppi (packet-ppi.c:1133) ==29810== by 0x6830624: call_dissector_through_handle (packet.c:616) ==29810== by 0x6830624: call_dissector_work (packet.c:691) ==29810== by 0x68304CE: dissector_try_uint_new (packet.c:1148) ==29810== by 0x6B26B6F: dissect_frame (packet-frame.c:500) ==29810== by 0x6830624: call_dissector_through_handle (packet.c:616) ==29810== by 0x6830624: call_dissector_work (packet.c:691) ==29810== by 0x682FB5C: call_dissector_only (packet.c:2662) ==29810== by 0x682FB5C: call_dissector_with_data (packet.c:2675) ==29810== by 0x682FA35: dissect_record (packet.c:501) ==29810== by 0x6823ECE: epan_dissect_run_with_taps (epan.c:373) ==29810== by 0x413BC4: process_packet (tshark.c:3728) ==29810== ==29810== Conditional jump or move depends on uninitialised value(s) ==29810== at 0x6BF9B04: dissect_wlan_radio (packet-ieee80211-radio.c:755) ==29810== by 0x6830624: call_dissector_through_handle (packet.c:616) ==29810== by 0x6830624: call_dissector_work (packet.c:691) ==29810== by 0x682FB5C: call_dissector_only (packet.c:2662) ==29810== by 0x682FB5C: call_dissector_with_data (packet.c:2675) ==29810== by 0x6E22112: dissect_ppi (packet-ppi.c:1133) ==29810== by 0x6830624: call_dissector_through_handle (packet.c:616) ==29810== by 0x6830624: call_dissector_work (packet.c:691) ==29810== by 0x68304CE: dissector_try_uint_new (packet.c:1148) ==29810== by 0x6B26B6F: dissect_frame (packet-frame.c:500) ==29810== by 0x6830624: call_dissector_through_handle (packet.c:616) ==29810== by 0x6830624: call_dissector_work (packet.c:691) ==29810== by 0x682FB5C: call_dissector_only (packet.c:2662) ==29810== by 0x682FB5C: call_dissector_with_data (packet.c:2675) ==29810== by 0x682FA35: dissect_record (packet.c:501) ==29810== by 0x6823ECE: epan_dissect_run_with_taps (epan.c:373) ==29810== by 0x413BC4: process_packet (tshark.c:3728) ==29810== ==29810== Conditional jump or move depends on uninitialised value(s) ==29810== at 0x6BF9B2E: dissect_wlan_radio (packet-ieee80211-radio.c:760) ==29810== by 0x6830624: call_dissector_through_handle (packet.c:616) ==29810== by 0x6830624: call_dissector_work (packet.c:691) ==29810== by 0x682FB5C: call_dissector_only (packet.c:2662) ==29810== by 0x682FB5C: call_dissector_with_data (packet.c:2675) ==29810== by 0x6E22112: dissect_ppi (packet-ppi.c:1133) ==29810== by 0x6830624: call_dissector_through_handle (packet.c:616) ==29810== by 0x6830624: call_dissector_work (packet.c:691) ==29810== by 0x68304CE: dissector_try_uint_new (packet.c:1148) ==29810== by 0x6B26B6F: dissect_frame (packet-frame.c:500) ==29810== by 0x6830624: call_dissector_through_handle (packet.c:616) ==29810== by 0x6830624: call_dissector_work (packet.c:691) ==29810== by 0x682FB5C: call_dissector_only (packet.c:2662) ==29810== by 0x682FB5C: call_dissector_with_data (packet.c:2675) ==29810== by 0x682FA35: dissect_record (packet.c:501) ==29810== by 0x6823ECE: epan_dissect_run_with_taps (epan.c:373) ==29810== by 0x413BC4: process_packet (tshark.c:3728) ==29810== ==29810== Conditional jump or move depends on uninitialised value(s) ==29810== at 0x6BF9B59: dissect_wlan_radio (packet-ieee80211-radio.c:765) ==29810== by 0x6830624: call_dissector_through_handle (packet.c:616) ==29810== by 0x6830624: call_dissector_work (packet.c:691) ==29810== by 0x682FB5C: call_dissector_only (packet.c:2662) ==29810== by 0x682FB5C: call_dissector_with_data (packet.c:2675) ==29810== by 0x6E22112: dissect_ppi (packet-ppi.c:1133) ==29810== by 0x6830624: call_dissector_through_handle (packet.c:616) ==29810== by 0x6830624: call_dissector_work (packet.c:691) ==29810== by 0x68304CE: dissector_try_uint_new (packet.c:1148) ==29810== by 0x6B26B6F: dissect_frame (packet-frame.c:500) ==29810== by 0x6830624: call_dissector_through_handle (packet.c:616) ==29810== by 0x6830624: call_dissector_work (packet.c:691) ==29810== by 0x682FB5C: call_dissector_only (packet.c:2662) ==29810== by 0x682FB5C: call_dissector_with_data (packet.c:2675) ==29810== by 0x682FA35: dissect_record (packet.c:501) ==29810== by 0x6823ECE: epan_dissect_run_with_taps (epan.c:373) ==29810== by 0x413BC4: process_packet (tshark.c:3728) ==29810== ==29810== Conditional jump or move depends on uninitialised value(s) ==29810== at 0x6BF9B84: dissect_wlan_radio (packet-ieee80211-radio.c:770) ==29810== by 0x6830624: call_dissector_through_handle (packet.c:616) ==29810== by 0x6830624: call_dissector_work (packet.c:691) ==29810== by 0x682FB5C: call_dissector_only (packet.c:2662) ==29810== by 0x682FB5C: call_dissector_with_data (packet.c:2675) ==29810== by 0x6E22112: dissect_ppi (packet-ppi.c:1133) ==29810== by 0x6830624: call_dissector_through_handle (packet.c:616) ==29810== by 0x6830624: call_dissector_work (packet.c:691) ==29810== by 0x68304CE: dissector_try_uint_new (packet.c:1148) ==29810== by 0x6B26B6F: dissect_frame (packet-frame.c:500) ==29810== by 0x6830624: call_dissector_through_handle (packet.c:616) ==29810== by 0x6830624: call_dissector_work (packet.c:691) ==29810== by 0x682FB5C: call_dissector_only (packet.c:2662) ==29810== by 0x682FB5C: call_dissector_with_data (packet.c:2675) ==29810== by 0x682FA35: dissect_record (packet.c:501) ==29810== by 0x6823ECE: epan_dissect_run_with_taps (epan.c:373) ==29810== by 0x413BC4: process_packet (tshark.c:3728) ==29810== ==29810== Conditional jump or move depends on uninitialised value(s) ==29810== at 0x6BF9BAA: dissect_wlan_radio (packet-ieee80211-radio.c:784) ==29810== by 0x6830624: call_dissector_through_handle (packet.c:616) ==29810== by 0x6830624: call_dissector_work (packet.c:691) ==29810== by 0x682FB5C: call_dissector_only (packet.c:2662) ==29810== by 0x682FB5C: call_dissector_with_data (packet.c:2675) ==29810== by 0x6E22112: dissect_ppi (packet-ppi.c:1133) ==29810== by 0x6830624: call_dissector_through_handle (packet.c:616) ==29810== by 0x6830624: call_dissector_work (packet.c:691) ==29810== by 0x68304CE: dissector_try_uint_new (packet.c:1148) ==29810== by 0x6B26B6F: dissect_frame (packet-frame.c:500) ==29810== by 0x6830624: call_dissector_through_handle (packet.c:616) ==29810== by 0x6830624: call_dissector_work (packet.c:691) ==29810== by 0x682FB5C: call_dissector_only (packet.c:2662) ==29810== by 0x682FB5C: call_dissector_with_data (packet.c:2675) ==29810== by 0x682FA35: dissect_record (packet.c:501) ==29810== by 0x6823ECE: epan_dissect_run_with_taps (epan.c:373) ==29810== by 0x413BC4: process_packet (tshark.c:3728) ==29810== ==29810== ==29810== HEAP SUMMARY: ==29810== in use at exit: 1,039,891 bytes in 28,310 blocks ==29810== total heap usage: 400,599 allocs, 372,289 frees, 43,502,159 bytes allocated ==29810== ==29810== LEAK SUMMARY: ==29810== definitely lost: 2,908 bytes in 125 blocks ==29810== indirectly lost: 36,448 bytes in 48 blocks ==29810== possibly lost: 0 bytes in 0 blocks ==29810== still reachable: 1,000,535 bytes in 28,137 blocks ==29810== suppressed: 0 bytes in 0 blocks ==29810== Rerun with --leak-check=full to see details of leaked memory ==29810== ==29810== For counts of detected and suppressed errors, rerun with: -v ==29810== Use --track-origins=yes to see where uninitialised values come from ==29810== ERROR SUMMARY: 8 errors from 8 contexts (suppressed: 0 from 0) [ no debug trace ]
You are receiving this mail because:
- You are watching all bug changes.
- Follow-Ups:
- [Wireshark-bugs] [Bug 11879] Buildbot crash output: fuzz-2015-12-13-11973.pcap
- From: bugzilla-daemon
- [Wireshark-bugs] [Bug 11879] Buildbot crash output: fuzz-2015-12-13-11973.pcap
- From: bugzilla-daemon
- [Wireshark-bugs] [Bug 11879] Buildbot crash output: fuzz-2015-12-13-11973.pcap
- Prev by Date: [Wireshark-bugs] [Bug 11039] ULP: raw ASN.1 values are not interpreted
- Next by Date: [Wireshark-bugs] [Bug 11876] Buildbot crash output: fuzz-2015-12-10-18690.pcap
- Previous by thread: [Wireshark-bugs] [Bug 11039] ULP: raw ASN.1 values are not interpreted
- Next by thread: [Wireshark-bugs] [Bug 11879] Buildbot crash output: fuzz-2015-12-13-11973.pcap
- Index(es):