Wireshark-bugs: [Wireshark-bugs] [Bug 11633] New: Buildbot crash output: fuzz-2015-10-23-2336.pc
Date: Sat, 24 Oct 2015 16:10:02 +0000
Bug ID 11633
Summary Buildbot crash output: fuzz-2015-10-23-2336.pcap
Product Wireshark
Version unspecified
Hardware x86-64
URL https://www.wireshark.org/download/automated/captures/fuzz-2015-10-23-2336.pcap
OS Ubuntu
Status CONFIRMED
Severity Major
Priority High
Component Dissection engine (libwireshark)
Assignee bugzilla-admin@wireshark.org
Reporter buildbot-do-not-reply@wireshark.org

Problems have been found with the following capture file:

https://www.wireshark.org/download/automated/captures/fuzz-2015-10-23-2336.pcap

stderr:
Input file: /home/wireshark/menagerie/menagerie/7922-mpls-pm-dlm-dm.pcap

Build host information:
Linux wsbb04 3.13.0-65-generic #105-Ubuntu SMP Mon Sep 21 18:50:58 UTC 2015
x86_64 x86_64 x86_64 GNU/Linux
Distributor ID:    Ubuntu
Description:    Ubuntu 14.04.3 LTS
Release:    14.04
Codename:    trusty

Buildbot information:
BUILDBOT_REPOSITORY=ssh://wireshark-buildbot@code.wireshark.org:29418/wireshark
BUILDBOT_BUILDNUMBER=3341
BUILDBOT_URL=http://buildbot.wireshark.org/wireshark-master/
BUILDBOT_BUILDERNAME=Clang Code Analysis
BUILDBOT_SLAVENAME=clang-code-analysis
BUILDBOT_GOT_REVISION=c1331a1e773d9b49e82b7ec6ca202f3d28cbbbfd

Return value:  0

Dissector bug:  0

Valgrind error count:  49



Git commit
commit c1331a1e773d9b49e82b7ec6ca202f3d28cbbbfd
Author: Pascal Quantin <pascal.quantin@gmail.com>
Date:   Wed Oct 21 13:57:40 2015 +0200

    GSM SMS: do not call GSM SMS port IE subdissectors until message is
reassembled

    Change-Id: Ibf384c01a1d3283e36b87a3d84e6c256341b8664
    Reviewed-on: https://code.wireshark.org/review/11190
    Petri-Dish: Pascal Quantin <pascal.quantin@gmail.com>
    Tested-by: Petri Dish Buildbot <buildbot-no-reply@wireshark.org>
    Reviewed-by: Pascal Quantin <pascal.quantin@gmail.com>


Command and args: ./tools/valgrind-wireshark.sh -T

==26784== Memcheck, a memory error detector
==26784== Copyright (C) 2002-2013, and GNU GPL'd, by Julian Seward et al.
==26784== Using Valgrind-3.10.0.SVN and LibVEX; rerun with -h for copyright
info
==26784== Command:
/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/bin/tshark
-Vx -nr
/fuzz/buildbot/clangcodeanalysis/valgrind-fuzz/fuzz-2015-10-23-2336.pcap
==26784== 
==26784== Conditional jump or move depends on uninitialised value(s)
==26784==    at 0x683F369: display_signed_time (to_str.c:772)
==26784==    by 0x684011B: rel_time_to_secs_str (to_str.c:937)
==26784==    by 0x682B5AC: proto_item_fill_label (proto.c:6646)
==26784==    by 0x681C752: proto_tree_print_node (print.c:164)
==26784==    by 0x681FED9: proto_tree_children_foreach (proto.c:655)
==26784==    by 0x681C87B: proto_tree_print_node (print.c:219)
==26784==    by 0x681FED9: proto_tree_children_foreach (proto.c:655)
==26784==    by 0x681C6ED: proto_tree_print (print.c:133)
==26784==    by 0x4143C9: print_packet (tshark.c:4129)
==26784==    by 0x413971: process_packet (tshark.c:3739)
==26784==    by 0x410E3E: main (tshark.c:3481)
==26784== 
==26784== Conditional jump or move depends on uninitialised value(s)
==26784==    at 0x683F36D: display_signed_time (to_str.c:1281)
==26784==    by 0x684011B: rel_time_to_secs_str (to_str.c:937)
==26784==    by 0x682B5AC: proto_item_fill_label (proto.c:6646)
==26784==    by 0x681C752: proto_tree_print_node (print.c:164)
==26784==    by 0x681FED9: proto_tree_children_foreach (proto.c:655)
==26784==    by 0x681C87B: proto_tree_print_node (print.c:219)
==26784==    by 0x681FED9: proto_tree_children_foreach (proto.c:655)
==26784==    by 0x681C6ED: proto_tree_print (print.c:133)
==26784==    by 0x4143C9: print_packet (tshark.c:4129)
==26784==    by 0x413971: process_packet (tshark.c:3739)
==26784==    by 0x410E3E: main (tshark.c:3481)
==26784== 
==26784== Conditional jump or move depends on uninitialised value(s)
==26784==    at 0x683F383: display_signed_time (to_str.c:1195)
==26784==    by 0x684011B: rel_time_to_secs_str (to_str.c:937)
==26784==    by 0x682B5AC: proto_item_fill_label (proto.c:6646)
==26784==    by 0x681C752: proto_tree_print_node (print.c:164)
==26784==    by 0x681FED9: proto_tree_children_foreach (proto.c:655)
==26784==    by 0x681C87B: proto_tree_print_node (print.c:219)
==26784==    by 0x681FED9: proto_tree_children_foreach (proto.c:655)
==26784==    by 0x681C6ED: proto_tree_print (print.c:133)
==26784==    by 0x4143C9: print_packet (tshark.c:4129)
==26784==    by 0x413971: process_packet (tshark.c:3739)
==26784==    by 0x410E3E: main (tshark.c:3481)
==26784== 
==26784== Conditional jump or move depends on uninitialised value(s)
==26784==    at 0x683F38C: display_signed_time (to_str.c:1198)
==26784==    by 0x684011B: rel_time_to_secs_str (to_str.c:937)
==26784==    by 0x682B5AC: proto_item_fill_label (proto.c:6646)
==26784==    by 0x681C752: proto_tree_print_node (print.c:164)
==26784==    by 0x681FED9: proto_tree_children_foreach (proto.c:655)
==26784==    by 0x681C87B: proto_tree_print_node (print.c:219)
==26784==    by 0x681FED9: proto_tree_children_foreach (proto.c:655)
==26784==    by 0x681C6ED: proto_tree_print (print.c:133)
==26784==    by 0x4143C9: print_packet (tshark.c:4129)
==26784==    by 0x413971: process_packet (tshark.c:3739)
==26784==    by 0x410E3E: main (tshark.c:3481)
==26784== 
==26784== Use of uninitialised value of size 8
==26784==    at 0x683F3B8: display_signed_time (to_str.c:1203)
==26784==    by 0x684011B: rel_time_to_secs_str (to_str.c:937)
==26784==    by 0x682B5AC: proto_item_fill_label (proto.c:6646)
==26784==    by 0x681C752: proto_tree_print_node (print.c:164)
==26784==    by 0x681FED9: proto_tree_children_foreach (proto.c:655)
==26784==    by 0x681C87B: proto_tree_print_node (print.c:219)
==26784==    by 0x681FED9: proto_tree_children_foreach (proto.c:655)
==26784==    by 0x681C6ED: proto_tree_print (print.c:133)
==26784==    by 0x4143C9: print_packet (tshark.c:4129)
==26784==    by 0x413971: process_packet (tshark.c:3739)
==26784==    by 0x410E3E: main (tshark.c:3481)
==26784== 
==26784== Conditional jump or move depends on uninitialised value(s)
==26784==    at 0x683F3D0: display_signed_time (to_str.c:1198)
==26784==    by 0x684011B: rel_time_to_secs_str (to_str.c:937)
==26784==    by 0x682B5AC: proto_item_fill_label (proto.c:6646)
==26784==    by 0x681C752: proto_tree_print_node (print.c:164)
==26784==    by 0x681FED9: proto_tree_children_foreach (proto.c:655)
==26784==    by 0x681C87B: proto_tree_print_node (print.c:219)
==26784==    by 0x681FED9: proto_tree_children_foreach (proto.c:655)
==26784==    by 0x681C6ED: proto_tree_print (print.c:133)
==26784==    by 0x4143C9: print_packet (tshark.c:4129)
==26784==    by 0x413971: process_packet (tshark.c:3739)
==26784==    by 0x410E3E: main (tshark.c:3481)
==26784== 
==26784== Conditional jump or move depends on uninitialised value(s)
==26784==    at 0x683F3D8: display_signed_time (to_str.c:1207)
==26784==    by 0x684011B: rel_time_to_secs_str (to_str.c:937)
==26784==    by 0x682B5AC: proto_item_fill_label (proto.c:6646)
==26784==    by 0x681C752: proto_tree_print_node (print.c:164)
==26784==    by 0x681FED9: proto_tree_children_foreach (proto.c:655)
==26784==    by 0x681C87B: proto_tree_print_node (print.c:219)
==26784==    by 0x681FED9: proto_tree_children_foreach (proto.c:655)
==26784==    by 0x681C6ED: proto_tree_print (print.c:133)
==26784==    by 0x4143C9: print_packet (tshark.c:4129)
==26784==    by 0x413971: process_packet (tshark.c:3739)
==26784==    by 0x410E3E: main (tshark.c:3481)
==26784== 
==26784== Conditional jump or move depends on uninitialised value(s)
==26784==    at 0x683F655: display_signed_time (to_str.c:1195)
==26784==    by 0x684011B: rel_time_to_secs_str (to_str.c:937)
==26784==    by 0x682B5AC: proto_item_fill_label (proto.c:6646)
==26784==    by 0x681C752: proto_tree_print_node (print.c:164)
==26784==    by 0x681FED9: proto_tree_children_foreach (proto.c:655)
==26784==    by 0x681C87B: proto_tree_print_node (print.c:219)
==26784==    by 0x681FED9: proto_tree_children_foreach (proto.c:655)
==26784==    by 0x681C6ED: proto_tree_print (print.c:133)
==26784==    by 0x4143C9: print_packet (tshark.c:4129)
==26784==    by 0x413971: process_packet (tshark.c:3739)
==26784==    by 0x410E3E: main (tshark.c:3481)
==26784== 
==26784== Conditional jump or move depends on uninitialised value(s)
==26784==    at 0x683F65E: display_signed_time (to_str.c:1198)
==26784==    by 0x684011B: rel_time_to_secs_str (to_str.c:937)
==26784==    by 0x682B5AC: proto_item_fill_label (proto.c:6646)
==26784==    by 0x681C752: proto_tree_print_node (print.c:164)
==26784==    by 0x681FED9: proto_tree_children_foreach (proto.c:655)
==26784==    by 0x681C87B: proto_tree_print_node (print.c:219)
==26784==    by 0x681FED9: proto_tree_children_foreach (proto.c:655)
==26784==    by 0x681C6ED: proto_tree_print (print.c:133)
==26784==    by 0x4143C9: print_packet (tshark.c:4129)
==26784==    by 0x413971: process_packet (tshark.c:3739)
==26784==    by 0x410E3E: main (tshark.c:3481)
==26784== 
==26784== Use of uninitialised value of size 8
==26784==    at 0x683F698: display_signed_time (to_str.c:1203)
==26784==    by 0x684011B: rel_time_to_secs_str (to_str.c:937)
==26784==    by 0x682B5AC: proto_item_fill_label (proto.c:6646)
==26784==    by 0x681C752: proto_tree_print_node (print.c:164)
==26784==    by 0x681FED9: proto_tree_children_foreach (proto.c:655)
==26784==    by 0x681C87B: proto_tree_print_node (print.c:219)
==26784==    by 0x681FED9: proto_tree_children_foreach (proto.c:655)
==26784==    by 0x681C6ED: proto_tree_print (print.c:133)
==26784==    by 0x4143C9: print_packet (tshark.c:4129)
==26784==    by 0x413971: process_packet (tshark.c:3739)
==26784==    by 0x410E3E: main (tshark.c:3481)
==26784== 
==26784== Conditional jump or move depends on uninitialised value(s)
==26784==    at 0x683F6B0: display_signed_time (to_str.c:1198)
==26784==    by 0x684011B: rel_time_to_secs_str (to_str.c:937)
==26784==    by 0x682B5AC: proto_item_fill_label (proto.c:6646)
==26784==    by 0x681C752: proto_tree_print_node (print.c:164)
==26784==    by 0x681FED9: proto_tree_children_foreach (proto.c:655)
==26784==    by 0x681C87B: proto_tree_print_node (print.c:219)
==26784==    by 0x681FED9: proto_tree_children_foreach (proto.c:655)
==26784==    by 0x681C6ED: proto_tree_print (print.c:133)
==26784==    by 0x4143C9: print_packet (tshark.c:4129)
==26784==    by 0x413971: process_packet (tshark.c:3739)
==26784==    by 0x410E3E: main (tshark.c:3481)
==26784== 
==26784== Conditional jump or move depends on uninitialised value(s)
==26784==    at 0x683F6B8: display_signed_time (to_str.c:1207)
==26784==    by 0x684011B: rel_time_to_secs_str (to_str.c:937)
==26784==    by 0x682B5AC: proto_item_fill_label (proto.c:6646)
==26784==    by 0x681C752: proto_tree_print_node (print.c:164)
==26784==    by 0x681FED9: proto_tree_children_foreach (proto.c:655)
==26784==    by 0x681C87B: proto_tree_print_node (print.c:219)
==26784==    by 0x681FED9: proto_tree_children_foreach (proto.c:655)
==26784==    by 0x681C6ED: proto_tree_print (print.c:133)
==26784==    by 0x4143C9: print_packet (tshark.c:4129)
==26784==    by 0x413971: process_packet (tshark.c:3739)
==26784==    by 0x410E3E: main (tshark.c:3481)
==26784== 
==26784== Conditional jump or move depends on uninitialised value(s)
==26784==    at 0xC565A03: vfprintf (vfprintf.c:1661)
==26784==    by 0xC623234: __vsnprintf_chk (vsnprintf_chk.c:63)
==26784==    by 0xA20F0D1: g_snprintf (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==26784==    by 0x682B5CB: proto_item_fill_label (proto.c:6647)
==26784==    by 0x681C752: proto_tree_print_node (print.c:164)
==26784==    by 0x681FED9: proto_tree_children_foreach (proto.c:655)
==26784==    by 0x681C87B: proto_tree_print_node (print.c:219)
==26784==    by 0x681FED9: proto_tree_children_foreach (proto.c:655)
==26784==    by 0x681C6ED: proto_tree_print (print.c:133)
==26784==    by 0x4143C9: print_packet (tshark.c:4129)
==26784==    by 0x413971: process_packet (tshark.c:3739)
==26784==    by 0x410E3E: main (tshark.c:3481)
==26784== 
==26784== Conditional jump or move depends on uninitialised value(s)
==26784==    at 0x4C2E0F8: strlen (in
/usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==26784==    by 0xC58873E: fputs (iofputs.c:35)
==26784==    by 0x681F0EF: print_line_text (print_stream.c:131)
==26784==    by 0x681C78D: proto_tree_print_node (print.c:170)
==26784==    by 0x681FED9: proto_tree_children_foreach (proto.c:655)
==26784==    by 0x681C87B: proto_tree_print_node (print.c:219)
==26784==    by 0x681FED9: proto_tree_children_foreach (proto.c:655)
==26784==    by 0x681C6ED: proto_tree_print (print.c:133)
==26784==    by 0x4143C9: print_packet (tshark.c:4129)
==26784==    by 0x413971: process_packet (tshark.c:3739)
==26784==    by 0x410E3E: main (tshark.c:3481)
==26784== 
==26784== Syscall param write(buf) points to uninitialised byte(s)
==26784==    at 0xC605870: __write_nocancel (syscall-template.S:81)
==26784==    by 0xC593002: _IO_file_write@@GLIBC_2.2.5 (fileops.c:1261)
==26784==    by 0xC5944DB: _IO_do_write@@GLIBC_2.2.5 (fileops.c:538)
==26784==    by 0xC5936A0: _IO_file_xsputn@@GLIBC_2.2.5 (fileops.c:1332)
==26784==    by 0xC5887C3: fputs (iofputs.c:40)
==26784==    by 0x681F0EF: print_line_text (print_stream.c:131)
==26784==    by 0x681DD63: print_hex_data_buffer (print.c:1004)
==26784==    by 0x681DA79: print_hex_data (print.c:904)
==26784==    by 0x41443A: print_packet (tshark.c:4152)
==26784==    by 0x413971: process_packet (tshark.c:3739)
==26784==    by 0x410E3E: main (tshark.c:3481)
==26784==  Address 0x4027c22 is not stack'd, malloc'd or (recently) free'd
==26784== 
==26784== 
==26784== HEAP SUMMARY:
==26784==     in use at exit: 1,037,424 bytes in 28,226 blocks
==26784==   total heap usage: 237,075 allocs, 208,849 frees, 31,175,463 bytes
allocated
==26784== 
==26784== LEAK SUMMARY:
==26784==    definitely lost: 2,908 bytes in 125 blocks
==26784==    indirectly lost: 36,448 bytes in 48 blocks
==26784==      possibly lost: 0 bytes in 0 blocks
==26784==    still reachable: 998,068 bytes in 28,053 blocks
==26784==         suppressed: 0 bytes in 0 blocks
==26784== Rerun with --leak-check=full to see details of leaked memory
==26784== 
==26784== For counts of detected and suppressed errors, rerun with: -v
==26784== Use --track-origins=yes to see where uninitialised values come from
==26784== ERROR SUMMARY: 49 errors from 15 contexts (suppressed: 0 from 0)

[ no debug trace ]


You are receiving this mail because:
  • You are watching all bug changes.