Wireshark-bugs: [Wireshark-bugs] [Bug 11579] New: Buildbot crash output: fuzz-2015-10-08-8774.pc
Date: Fri, 09 Oct 2015 00:10:02 +0000
Bug ID 11579
Summary Buildbot crash output: fuzz-2015-10-08-8774.pcap
Product Wireshark
Version unspecified
Hardware x86-64
URL https://www.wireshark.org/download/automated/captures/fuzz-2015-10-08-8774.pcap
OS Ubuntu
Status CONFIRMED
Severity Major
Priority High
Component Dissection engine (libwireshark)
Assignee bugzilla-admin@wireshark.org
Reporter buildbot-do-not-reply@wireshark.org

Problems have been found with the following capture file:

https://www.wireshark.org/download/automated/captures/fuzz-2015-10-08-8774.pcap

stderr:
Input file:
/home/wireshark/menagerie/menagerie/12699-unknownextensionheader.pcap

Build host information:
Linux wsbb04 3.13.0-65-generic #105-Ubuntu SMP Mon Sep 21 18:50:58 UTC 2015
x86_64 x86_64 x86_64 GNU/Linux
Distributor ID:    Ubuntu
Description:    Ubuntu 14.04.3 LTS
Release:    14.04
Codename:    trusty

Buildbot information:
BUILDBOT_REPOSITORY=ssh://wireshark-buildbot@code.wireshark.org:29418/wireshark
BUILDBOT_BUILDNUMBER=3333
BUILDBOT_URL=http://buildbot.wireshark.org/wireshark-master/
BUILDBOT_BUILDERNAME=Clang Code Analysis
BUILDBOT_SLAVENAME=clang-code-analysis
BUILDBOT_GOT_REVISION=cc1c23a980fe2519d846498f05a0fcf6437e5763

Return value:  0

Dissector bug:  0

Valgrind error count:  80



Git commit
commit cc1c23a980fe2519d846498f05a0fcf6437e5763
Author: Alexis La Goutte <alexis.lagoutte@gmail.com>
Date:   Tue Oct 6 09:28:13 2015 +0200

    BGP: Add BGP-Extended Message Capability

    From draft-ietf-idr-bgp-extended-messages
    Update BGP Capability Codes to 2015-09-30

    Change-Id: I2f3b44ad8ad7a9e5444cdfbfb22bf7d0538ffbfc
    Reviewed-on: https://code.wireshark.org/review/10826
    Reviewed-by: Michael Mann <mmann78@netscape.net>


Command and args: ./tools/valgrind-wireshark.sh -T

==1467== Memcheck, a memory error detector
==1467== Copyright (C) 2002-2013, and GNU GPL'd, by Julian Seward et al.
==1467== Using Valgrind-3.10.0.SVN and LibVEX; rerun with -h for copyright info
==1467== Command:
/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/bin/tshark
-Vx -nr
/fuzz/buildbot/clangcodeanalysis/valgrind-fuzz/fuzz-2015-10-08-8774.pcap
==1467== 
==1467== Conditional jump or move depends on uninitialised value(s)
==1467==    at 0x67E833B: ip6_to_str_buf_len (address_types.c:275)
==1467==    by 0x67E863C: ipv6_to_str (address_types.c:364)
==1467==    by 0x67E8E03: address_to_str (address_types.c:929)
==1467==    by 0x681CD2A: proto_item_fill_label (proto.c:6726)
==1467==    by 0x680DCC2: proto_tree_print_node (print.c:163)
==1467==    by 0x6811449: proto_tree_children_foreach (proto.c:656)
==1467==    by 0x680DDEB: proto_tree_print_node (print.c:218)
==1467==    by 0x6811449: proto_tree_children_foreach (proto.c:656)
==1467==    by 0x680DDEB: proto_tree_print_node (print.c:218)
==1467==    by 0x6811449: proto_tree_children_foreach (proto.c:656)
==1467==    by 0x680DC5D: proto_tree_print (print.c:132)
==1467==    by 0x4143C9: print_packet (tshark.c:4129)
==1467== 
==1467== Conditional jump or move depends on uninitialised value(s)
==1467==    at 0x682F4F6: word_to_hex_npad (to_str.c:89)
==1467==    by 0x67E843B: ip6_to_str_buf_len (address_types.c:350)
==1467==    by 0x67E863C: ipv6_to_str (address_types.c:364)
==1467==    by 0x67E8E03: address_to_str (address_types.c:929)
==1467==    by 0x681CD2A: proto_item_fill_label (proto.c:6726)
==1467==    by 0x680DCC2: proto_tree_print_node (print.c:163)
==1467==    by 0x6811449: proto_tree_children_foreach (proto.c:656)
==1467==    by 0x680DDEB: proto_tree_print_node (print.c:218)
==1467==    by 0x6811449: proto_tree_children_foreach (proto.c:656)
==1467==    by 0x680DDEB: proto_tree_print_node (print.c:218)
==1467==    by 0x6811449: proto_tree_children_foreach (proto.c:656)
==1467==    by 0x680DC5D: proto_tree_print (print.c:132)
==1467== 
==1467== Conditional jump or move depends on uninitialised value(s)
==1467==    at 0x682F519: word_to_hex_npad (to_str.c:91)
==1467==    by 0x67E843B: ip6_to_str_buf_len (address_types.c:350)
==1467==    by 0x67E863C: ipv6_to_str (address_types.c:364)
==1467==    by 0x67E8E03: address_to_str (address_types.c:929)
==1467==    by 0x681CD2A: proto_item_fill_label (proto.c:6726)
==1467==    by 0x680DCC2: proto_tree_print_node (print.c:163)
==1467==    by 0x6811449: proto_tree_children_foreach (proto.c:656)
==1467==    by 0x680DDEB: proto_tree_print_node (print.c:218)
==1467==    by 0x6811449: proto_tree_children_foreach (proto.c:656)
==1467==    by 0x680DDEB: proto_tree_print_node (print.c:218)
==1467==    by 0x6811449: proto_tree_children_foreach (proto.c:656)
==1467==    by 0x680DC5D: proto_tree_print (print.c:132)
==1467== 
==1467== Conditional jump or move depends on uninitialised value(s)
==1467==    at 0x682F536: word_to_hex_npad (to_str.c:93)
==1467==    by 0x67E843B: ip6_to_str_buf_len (address_types.c:350)
==1467==    by 0x67E863C: ipv6_to_str (address_types.c:364)
==1467==    by 0x67E8E03: address_to_str (address_types.c:929)
==1467==    by 0x681CD2A: proto_item_fill_label (proto.c:6726)
==1467==    by 0x680DCC2: proto_tree_print_node (print.c:163)
==1467==    by 0x6811449: proto_tree_children_foreach (proto.c:656)
==1467==    by 0x680DDEB: proto_tree_print_node (print.c:218)
==1467==    by 0x6811449: proto_tree_children_foreach (proto.c:656)
==1467==    by 0x680DDEB: proto_tree_print_node (print.c:218)
==1467==    by 0x6811449: proto_tree_children_foreach (proto.c:656)
==1467==    by 0x680DC5D: proto_tree_print (print.c:132)
==1467== 
==1467== Use of uninitialised value of size 8
==1467==    at 0x682F559: word_to_hex_npad (to_str.c:58)
==1467==    by 0x67E843B: ip6_to_str_buf_len (address_types.c:350)
==1467==    by 0x67E863C: ipv6_to_str (address_types.c:364)
==1467==    by 0x67E8E03: address_to_str (address_types.c:929)
==1467==    by 0x681CD2A: proto_item_fill_label (proto.c:6726)
==1467==    by 0x680DCC2: proto_tree_print_node (print.c:163)
==1467==    by 0x6811449: proto_tree_children_foreach (proto.c:656)
==1467==    by 0x680DDEB: proto_tree_print_node (print.c:218)
==1467==    by 0x6811449: proto_tree_children_foreach (proto.c:656)
==1467==    by 0x680DDEB: proto_tree_print_node (print.c:218)
==1467==    by 0x6811449: proto_tree_children_foreach (proto.c:656)
==1467==    by 0x680DC5D: proto_tree_print (print.c:132)
==1467== 
==1467== 
==1467== HEAP SUMMARY:
==1467==     in use at exit: 1,037,001 bytes in 28,216 blocks
==1467==   total heap usage: 237,154 allocs, 208,938 frees, 31,016,493 bytes
allocated
==1467== 
==1467== LEAK SUMMARY:
==1467==    definitely lost: 2,932 bytes in 126 blocks
==1467==    indirectly lost: 36,456 bytes in 49 blocks
==1467==      possibly lost: 0 bytes in 0 blocks
==1467==    still reachable: 997,613 bytes in 28,041 blocks
==1467==         suppressed: 0 bytes in 0 blocks
==1467== Rerun with --leak-check=full to see details of leaked memory
==1467== 
==1467== For counts of detected and suppressed errors, rerun with: -v
==1467== Use --track-origins=yes to see where uninitialised values come from
==1467== ERROR SUMMARY: 80 errors from 5 contexts (suppressed: 0 from 0)

[ no debug trace ]


You are receiving this mail because:
  • You are watching all bug changes.