Open mrragava opened 3 years ago
onefuzz --endpoint https://oefuzzingtest2instance.azurewebsites.net repro create_and_connect oft-unique-reports-032590c6e8ea524cb32942a29c898a62 ee0527905b59de49a158438a3f89704a384540e9c2b50634e5e9f203fcd9d5df.json
#1 0x42e9f7 in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) (/onefuzz/blob-containers/fuzz3rpz7enxyexcq/fuzz+0x42e9f7) #2 0x41ee8a in fuzzer::RunOneTest(fuzzer::Fuzzer*, char const*, unsigned long) (/onefuzz/blob-containers/fuzz3rpz7enxyexcq/fuzz+0x41ee8a) #3 0x429e50 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) (/onefuzz/blob-containers/fuzz3rpz7enxyexcq/fuzz+0x429e50) #4 0x41cb52 in main (/onefuzz/blob-containers/fuzz3rpz7enxyexcq/fuzz+0x41cb52) #5 0x7ffff6a99bf6 in __libc_start_main /build/glibc-S9d2JN/glibc-2.27/csu/../csu/libc-start.c:310 #6 0x41cbc9 in _start (/onefuzz/blob-containers/fuzz3rpz7enxyexcq/fuzz+0x41cbc9)
INFO: Loaded 1 modules (21 inline 8-bit counters): 21 [0x788fb0, 0x788fc5), INFO: Loaded 1 PC tables (21 PCs): 21 [0x5664c8,0x566618), setup/fuzz: Running 1 inputs 1 time(s) each. Running: /tmp/.tmpAEZFNm/crash-6eb4c82559605b899dab9a2e976c623ee7aaa161 ================================================================= ==7548==ERROR: AddressSanitizer: stack-buffer-underflow on address 0x7fffffffd000 at pc 0x00000054ad24 bp 0x7fffffffcff0 sp 0x7fffffffcfe8 WRITE of size 4 at 0x7fffffffd000 thread T0 #0 0x54ad23 in LLVMFuzzerTestOneInput /__w/onefuzz-notification/onefuzz-notification/simple-libfuzzer/simple.c:28:69 #1 0x42e9f7 in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) (/onefuzz/blob-containers/fuzz3rpz7enxyexcq/fuzz+0x42e9f7) #2 0x41ee8a in fuzzer::RunOneTest(fuzzer::Fuzzer*, char const*, unsigned long) (/onefuzz/blob-containers/fuzz3rpz7enxyexcq/fuzz+0x41ee8a) #3 0x429e50 in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) (/onefuzz/blob-containers/fuzz3rpz7enxyexcq/fuzz+0x429e50) #4 0x41cb52 in main (/onefuzz/blob-containers/fuzz3rpz7enxyexcq/fuzz+0x41cb52) #5 0x7ffff6a99bf6 in __libc_start_main /build/glibc-S9d2JN/glibc-2.27/csu/../csu/libc-start.c:310 #6 0x41cbc9 in _start (/onefuzz/blob-containers/fuzz3rpz7enxyexcq/fuzz+0x41cbc9) Address 0x7fffffffd000 is located in stack of thread T0 at offset 0 in frame #0 0x54a5ff in LLVMFuzzerTestOneInput /__w/onefuzz-notification/onefuzz-notification/simple-libfuzzer/simple.c:8 This frame has 1 object(s): [32, 36) 'cnt' (line 9) HINT: this may be a false positive if your program uses some custom stack unwind mechanism or swapcontext (longjmp and C++ exceptions *are* supported) SUMMARY: AddressSanitizer: stack-buffer-underflow /__w/onefuzz-notification/onefuzz-notification/simple-libfuzzer/simple.c:28:69 in LLVMFuzzerTestOneInput Shadow bytes around the buggy address: 0x10007fff79b0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x10007fff79c0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x10007fff79d0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x10007fff79e0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x10007fff79f0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 =>0x10007fff7a00:[f1]f1 f1 f1 04 f3 f3 f3 00 00 00 00 00 00 00 00 0x10007fff7a10: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x10007fff7a20: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x10007fff7a30: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x10007fff7a40: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x10007fff7a50: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 Shadow byte legend (one shadow byte represents 8 application bytes): Addressable: 00 Partially addressable: 01 02 03 04 05 06 07 Heap left redzone: fa Freed heap region: fd Stack left redzone: f1 Stack mid redzone: f2 Stack right redzone: f3 Stack after return: f5 Stack use after scope: f8 Global redzone: f9 Global init order: f6 Poisoned by user: f7 Container overflow: fc Array cookie: ac Intra object redzone: bb ASan internal: fe Left alloca redzone: ca Right alloca redzone: cb ==7548==ABORTING
Duplicate found.
Files
Repro
onefuzz --endpoint https://oefuzzingtest2instance.azurewebsites.net repro create_and_connect oft-unique-reports-032590c6e8ea524cb32942a29c898a62 ee0527905b59de49a158438a3f89704a384540e9c2b50634e5e9f203fcd9d5df.json
Call Stack
ASAN Log