Wireshark-bugs: [Wireshark-bugs] [Bug 12359] New: Buildbot crash output: fuzz-2016-04-19-5629.pc
Date: Wed, 20 Apr 2016 10:10:04 +0000
Bug ID | 12359 |
---|---|
Summary | Buildbot crash output: fuzz-2016-04-19-5629.pcap |
Product | Wireshark |
Version | unspecified |
Hardware | x86-64 |
URL | https://www.wireshark.org/download/automated/captures/fuzz-2016-04-19-5629.pcap |
OS | Ubuntu |
Status | CONFIRMED |
Severity | Major |
Priority | High |
Component | Dissection engine (libwireshark) |
Assignee | [email protected] |
Reporter | [email protected] |
Problems have been found with the following capture file: https://www.wireshark.org/download/automated/captures/fuzz-2016-04-19-5629.pcap stderr: Input file: /home/wireshark/menagerie/menagerie/2867-ldss_filtered.pcap Build host information: Linux wsbb04 3.13.0-85-generic #129-Ubuntu SMP Thu Mar 17 20:50:15 UTC 2016 x86_64 x86_64 x86_64 GNU/Linux Distributor ID: Ubuntu Description: Ubuntu 14.04.4 LTS Release: 14.04 Codename: trusty Buildbot information: BUILDBOT_REPOSITORY=ssh://[email protected]:29418/wireshark BUILDBOT_BUILDNUMBER=3570 BUILDBOT_URL=http://buildbot.wireshark.org/wireshark-master/ BUILDBOT_BUILDERNAME=Clang Code Analysis BUILDBOT_SLAVENAME=clang-code-analysis BUILDBOT_GOT_REVISION=0b824d41c206fecd77603b95f1f905efe183d524 Return value: 1 Dissector bug: 0 Valgrind error count: 0 Git commit commit 0b824d41c206fecd77603b95f1f905efe183d524 Author: Petr Sumbera <[email protected]> Date: Fri Apr 8 06:34:19 2016 -0700 Support for Oracle Solaris ECP/VDP dissection based on IEEE 802.1Qbg Draft 2.1. Bug: 12272 Change-Id: I9e58187695ceef089b452657d2fe60400114f522 Reviewed-on: https://code.wireshark.org/review/14866 Petri-Dish: Michael Mann <[email protected]> Tested-by: Petri Dish Buildbot <[email protected]> Reviewed-by: Alexis La Goutte <[email protected]> ** (process:22491): WARNING **: Dissector bug, protocol TCP, in packet 163: packet-tcp.c:5053: failed assertion "save_desegment_offset == pinfo->desegment_offset && save_desegment_len == pinfo->desegment_len" ** (process:22491): WARNING **: Dissector bug, protocol TCP, in packet 166: packet-tcp.c:5053: failed assertion "save_desegment_offset == pinfo->desegment_offset && save_desegment_len == pinfo->desegment_len" ** (process:22491): WARNING **: Dissector bug, protocol TCP, in packet 169: packet-tcp.c:5053: failed assertion "save_desegment_offset == pinfo->desegment_offset && save_desegment_len == pinfo->desegment_len" ** (process:22491): WARNING **: Dissector bug, protocol TCP, in packet 330: packet-tcp.c:5053: failed assertion "save_desegment_offset == pinfo->desegment_offset && save_desegment_len == pinfo->desegment_len" ** (process:22491): WARNING **: Dissector bug, protocol TCP, in packet 334: packet-tcp.c:5053: failed assertion "save_desegment_offset == pinfo->desegment_offset && save_desegment_len == pinfo->desegment_len" ** (process:22491): WARNING **: Dissector bug, protocol TCP, in packet 336: packet-tcp.c:5053: failed assertion "save_desegment_offset == pinfo->desegment_offset && save_desegment_len == pinfo->desegment_len" ** (process:22491): WARNING **: Dissector bug, protocol TCP, in packet 337: packet-tcp.c:5053: failed assertion "save_desegment_offset == pinfo->desegment_offset && save_desegment_len == pinfo->desegment_len" ** (process:22491): WARNING **: Dissector bug, protocol TCP, in packet 396: packet-tcp.c:5053: failed assertion "save_desegment_offset == pinfo->desegment_offset && save_desegment_len == pinfo->desegment_len" ================================================================= ==22491==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x6020003ddeff at pc 0x0000004b5d3a bp 0x7ffd63dcbd30 sp 0x7ffd63dcb4e0 READ of size 3 at 0x6020003ddeff thread T0 #0 0x4b5d39 (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/bin/tshark+0x4b5d39) #1 0x7f6717c4846a (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/lib/libwireshark.so.0+0x7c6746a) #2 0x7f6717421d11 (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/lib/libwireshark.so.0+0x7440d11) #3 0x7f67173f6533 (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/lib/libwireshark.so.0+0x7415533) #4 0x7f6718126c82 (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/lib/libwireshark.so.0+0x8145c82) #5 0x7f6718129d3b (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/lib/libwireshark.so.0+0x8148d3b) #6 0x7f6718127bdb (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/lib/libwireshark.so.0+0x8146bdb) #7 0x7f67181315c1 (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/lib/libwireshark.so.0+0x81505c1) #8 0x7f6717421d11 (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/lib/libwireshark.so.0+0x7440d11) #9 0x7f67174219aa (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/lib/libwireshark.so.0+0x74409aa) #10 0x7f6717b4d6c3 (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/lib/libwireshark.so.0+0x7b6c6c3) #11 0x7f6717b5077b (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/lib/libwireshark.so.0+0x7b6f77b) #12 0x7f6717421d11 (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/lib/libwireshark.so.0+0x7440d11) #13 0x7f6717421fb8 (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/lib/libwireshark.so.0+0x7440fb8) #14 0x7f6717965951 (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/lib/libwireshark.so.0+0x7984951) #15 0x7f6717421d11 (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/lib/libwireshark.so.0+0x7440d11) #16 0x7f671741fd8c (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/lib/libwireshark.so.0+0x743ed8c) #17 0x7f67179640f6 (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/lib/libwireshark.so.0+0x79830f6) #18 0x7f6717962d40 (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/lib/libwireshark.so.0+0x7981d40) #19 0x7f6717421d11 (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/lib/libwireshark.so.0+0x7440d11) #20 0x7f67174219aa (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/lib/libwireshark.so.0+0x74409aa) #21 0x7f67179af742 (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/lib/libwireshark.so.0+0x79ce742) #22 0x7f6717421d11 (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/lib/libwireshark.so.0+0x7440d11) #23 0x7f671741fd8c (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/lib/libwireshark.so.0+0x743ed8c) #24 0x7f671741f582 (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/lib/libwireshark.so.0+0x743e582) #25 0x7f67173ffb5e (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/lib/libwireshark.so.0+0x741eb5e) #26 0x500fc9 (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/bin/tshark+0x500fc9) #27 0x4fbc82 (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/bin/tshark+0x4fbc82) #28 0x7f670d289ec4 (/lib/x86_64-linux-gnu/libc.so.6+0x21ec4) #29 0x4402c6 (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/bin/tshark+0x4402c6) 0x6020003ddeff is located 0 bytes to the right of 15-byte region [0x6020003ddef0,0x6020003ddeff) allocated by thread T0 here: #0 0x4c7282 (/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/bin/tshark+0x4c7282) #1 0x7f670f6c0610 (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0x4e610) Shadow bytes around the buggy address: 0x0c0480073b80: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa 0x0c0480073b90: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa 0x0c0480073ba0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa 0x0c0480073bb0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa 0x0c0480073bc0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa =>0x0c0480073bd0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa 00[07] 0x0c0480073be0: fa fa 00 01 fa fa 00 03 fa fa fd fd fa fa 00 05 0x0c0480073bf0: fa fa 00 05 fa fa 00 05 fa fa 00 05 fa fa 00 00 0x0c0480073c00: fa fa 00 00 fa fa 00 00 fa fa 00 00 fa fa 01 fa 0x0c0480073c10: fa fa fd fa fa fa 06 fa fa fa fd fd fa fa fd fd 0x0c0480073c20: fa fa fd fd fa fa fd fd fa fa 00 07 fa fa fd fd Shadow byte legend (one shadow byte represents 8 application bytes): Addressable: 00 Partially addressable: 01 02 03 04 05 06 07 Heap left redzone: fa Heap right redzone: fb Freed heap region: fd Stack left redzone: f1 Stack mid redzone: f2 Stack right redzone: f3 Stack partial redzone: f4 Stack after return: f5 Stack use after scope: f8 Global redzone: f9 Global init order: f6 Poisoned by user: f7 Container overflow: fc Array cookie: ac Intra object redzone: bb ASan internal: fe Left alloca redzone: ca Right alloca redzone: cb ==22491==ABORTING [ no debug trace ]
You are receiving this mail because:
- You are watching all bug changes.
- Follow-Ups:
- [Wireshark-bugs] [Bug 12359] Buildbot crash output: fuzz-2016-04-19-5629.pcap
- From: bugzilla-daemon
- [Wireshark-bugs] [Bug 12359] Buildbot crash output: fuzz-2016-04-19-5629.pcap
- Prev by Date: [Wireshark-bugs] [Bug 12344] Buildbot crash output: fuzz-2016-04-16-19092.pcap
- Next by Date: [Wireshark-bugs] [Bug 11759] Add new EDNS0 Option
- Previous by thread: [Wireshark-bugs] [Bug 12242] Wireshark heap-based out-of-bounds read in dissect_pktc_rekey
- Next by thread: [Wireshark-bugs] [Bug 12359] Buildbot crash output: fuzz-2016-04-19-5629.pcap
- Index(es):