Wireshark-bugs: [Wireshark-bugs] [Bug 11570] New: Buildbot crash output: fuzz-2015-10-06-30742.p
Date: Wed, 07 Oct 2015 03:00:02 +0000
Bug ID 11570
Summary Buildbot crash output: fuzz-2015-10-06-30742.pcap
Product Wireshark
Version unspecified
Hardware x86-64
URL https://www.wireshark.org/download/automated/captures/fuzz-2015-10-06-30742.pcap
OS Ubuntu
Status CONFIRMED
Severity Major
Priority High
Component Dissection engine (libwireshark)
Assignee bugzilla-admin@wireshark.org
Reporter buildbot-do-not-reply@wireshark.org

Problems have been found with the following capture file:

https://www.wireshark.org/download/automated/captures/fuzz-2015-10-06-30742.pcap

stderr:
Input file:
/home/wireshark/menagerie/menagerie/12699-unknownextensionheader.pcap

Build host information:
Linux wsbb04 3.13.0-65-generic #105-Ubuntu SMP Mon Sep 21 18:50:58 UTC 2015
x86_64 x86_64 x86_64 GNU/Linux
Distributor ID:    Ubuntu
Description:    Ubuntu 14.04.3 LTS
Release:    14.04
Codename:    trusty

Buildbot information:
BUILDBOT_REPOSITORY=ssh://wireshark-buildbot@code.wireshark.org:29418/wireshark
BUILDBOT_BUILDNUMBER=3332
BUILDBOT_URL=http://buildbot.wireshark.org/wireshark-master/
BUILDBOT_BUILDERNAME=Clang Code Analysis
BUILDBOT_SLAVENAME=clang-code-analysis
BUILDBOT_GOT_REVISION=63b9bc110dd2423baac539a3d8762cc92be0b223

Return value:  0

Dissector bug:  0

Valgrind error count:  50



Git commit
commit 63b9bc110dd2423baac539a3d8762cc92be0b223
Author: Roland Knall <roland.knall@br-automation.com>
Date:   Tue Oct 6 10:00:54 2015 +0200

    openSAFETY: Add Producer ID to info field

     Cosmetic change, to better distinguish if multiple
     SPDO packages have been detected.

     This should also be back-ported to 1.12 and 2.0

    Change-Id: I3d0b26ecb6e0cc60b3cdc9861920c5ccaeb70cbd
    Reviewed-on: https://code.wireshark.org/review/10829
    Reviewed-by: Roland Knall <rknall@gmail.com>
    Petri-Dish: Alexis La Goutte <alexis.lagoutte@gmail.com>
    Tested-by: Petri Dish Buildbot <buildbot-no-reply@wireshark.org>
    Reviewed-by: Alexis La Goutte <alexis.lagoutte@gmail.com>


Command and args: ./tools/valgrind-wireshark.sh -T

==26839== Memcheck, a memory error detector
==26839== Copyright (C) 2002-2013, and GNU GPL'd, by Julian Seward et al.
==26839== Using Valgrind-3.10.0.SVN and LibVEX; rerun with -h for copyright
info
==26839== Command:
/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/bin/tshark
-Vx -nr
/fuzz/buildbot/clangcodeanalysis/valgrind-fuzz/fuzz-2015-10-06-30742.pcap
==26839== 
==26839== Conditional jump or move depends on uninitialised value(s)
==26839==    at 0x67E832B: ip6_to_str_buf_len (address_types.c:275)
==26839==    by 0x67E862C: ipv6_to_str (address_types.c:364)
==26839==    by 0x67E8DF3: address_to_str (address_types.c:929)
==26839==    by 0x681CD1A: proto_item_fill_label (proto.c:6726)
==26839==    by 0x680DCB2: proto_tree_print_node (print.c:163)
==26839==    by 0x6811439: proto_tree_children_foreach (proto.c:656)
==26839==    by 0x680DDDB: proto_tree_print_node (print.c:218)
==26839==    by 0x6811439: proto_tree_children_foreach (proto.c:656)
==26839==    by 0x680DDDB: proto_tree_print_node (print.c:218)
==26839==    by 0x6811439: proto_tree_children_foreach (proto.c:656)
==26839==    by 0x680DC4D: proto_tree_print (print.c:132)
==26839==    by 0x4143C9: print_packet (tshark.c:4129)
==26839== 
==26839== Conditional jump or move depends on uninitialised value(s)
==26839==    at 0x682F4E6: word_to_hex_npad (to_str.c:89)
==26839==    by 0x67E842B: ip6_to_str_buf_len (address_types.c:350)
==26839==    by 0x67E862C: ipv6_to_str (address_types.c:364)
==26839==    by 0x67E8DF3: address_to_str (address_types.c:929)
==26839==    by 0x681CD1A: proto_item_fill_label (proto.c:6726)
==26839==    by 0x680DCB2: proto_tree_print_node (print.c:163)
==26839==    by 0x6811439: proto_tree_children_foreach (proto.c:656)
==26839==    by 0x680DDDB: proto_tree_print_node (print.c:218)
==26839==    by 0x6811439: proto_tree_children_foreach (proto.c:656)
==26839==    by 0x680DDDB: proto_tree_print_node (print.c:218)
==26839==    by 0x6811439: proto_tree_children_foreach (proto.c:656)
==26839==    by 0x680DC4D: proto_tree_print (print.c:132)
==26839== 
==26839== Conditional jump or move depends on uninitialised value(s)
==26839==    at 0x682F509: word_to_hex_npad (to_str.c:91)
==26839==    by 0x67E842B: ip6_to_str_buf_len (address_types.c:350)
==26839==    by 0x67E862C: ipv6_to_str (address_types.c:364)
==26839==    by 0x67E8DF3: address_to_str (address_types.c:929)
==26839==    by 0x681CD1A: proto_item_fill_label (proto.c:6726)
==26839==    by 0x680DCB2: proto_tree_print_node (print.c:163)
==26839==    by 0x6811439: proto_tree_children_foreach (proto.c:656)
==26839==    by 0x680DDDB: proto_tree_print_node (print.c:218)
==26839==    by 0x6811439: proto_tree_children_foreach (proto.c:656)
==26839==    by 0x680DDDB: proto_tree_print_node (print.c:218)
==26839==    by 0x6811439: proto_tree_children_foreach (proto.c:656)
==26839==    by 0x680DC4D: proto_tree_print (print.c:132)
==26839== 
==26839== Conditional jump or move depends on uninitialised value(s)
==26839==    at 0x682F526: word_to_hex_npad (to_str.c:93)
==26839==    by 0x67E842B: ip6_to_str_buf_len (address_types.c:350)
==26839==    by 0x67E862C: ipv6_to_str (address_types.c:364)
==26839==    by 0x67E8DF3: address_to_str (address_types.c:929)
==26839==    by 0x681CD1A: proto_item_fill_label (proto.c:6726)
==26839==    by 0x680DCB2: proto_tree_print_node (print.c:163)
==26839==    by 0x6811439: proto_tree_children_foreach (proto.c:656)
==26839==    by 0x680DDDB: proto_tree_print_node (print.c:218)
==26839==    by 0x6811439: proto_tree_children_foreach (proto.c:656)
==26839==    by 0x680DDDB: proto_tree_print_node (print.c:218)
==26839==    by 0x6811439: proto_tree_children_foreach (proto.c:656)
==26839==    by 0x680DC4D: proto_tree_print (print.c:132)
==26839== 
==26839== Use of uninitialised value of size 8
==26839==    at 0x682F549: word_to_hex_npad (to_str.c:58)
==26839==    by 0x67E842B: ip6_to_str_buf_len (address_types.c:350)
==26839==    by 0x67E862C: ipv6_to_str (address_types.c:364)
==26839==    by 0x67E8DF3: address_to_str (address_types.c:929)
==26839==    by 0x681CD1A: proto_item_fill_label (proto.c:6726)
==26839==    by 0x680DCB2: proto_tree_print_node (print.c:163)
==26839==    by 0x6811439: proto_tree_children_foreach (proto.c:656)
==26839==    by 0x680DDDB: proto_tree_print_node (print.c:218)
==26839==    by 0x6811439: proto_tree_children_foreach (proto.c:656)
==26839==    by 0x680DDDB: proto_tree_print_node (print.c:218)
==26839==    by 0x6811439: proto_tree_children_foreach (proto.c:656)
==26839==    by 0x680DC4D: proto_tree_print (print.c:132)
==26839== 
==26839== 
==26839== HEAP SUMMARY:
==26839==     in use at exit: 1,037,002 bytes in 28,216 blocks
==26839==   total heap usage: 236,918 allocs, 208,702 frees, 31,005,323 bytes
allocated
==26839== 
==26839== LEAK SUMMARY:
==26839==    definitely lost: 2,932 bytes in 126 blocks
==26839==    indirectly lost: 36,456 bytes in 49 blocks
==26839==      possibly lost: 0 bytes in 0 blocks
==26839==    still reachable: 997,614 bytes in 28,041 blocks
==26839==         suppressed: 0 bytes in 0 blocks
==26839== Rerun with --leak-check=full to see details of leaked memory
==26839== 
==26839== For counts of detected and suppressed errors, rerun with: -v
==26839== Use --track-origins=yes to see where uninitialised values come from
==26839== ERROR SUMMARY: 50 errors from 5 contexts (suppressed: 0 from 0)

[ no debug trace ]


You are receiving this mail because:
  • You are watching all bug changes.