Closed Bug 1477493 Opened 6 years ago Closed 6 years ago

AddressSanitizer: stack-use-after-scope [@ __interceptor_strcmp] with READ of size 1 in libglapi through [@ LookupSymbol]

Categories

(Core :: Graphics, defect, P3)

x86_64
Linux
defect

Tracking

()

RESOLVED FIXED

People

(Reporter: decoder, Assigned: jgilbert)

References

(Blocks 1 open bug)

Details

(Keywords: crash, regression, sec-vector)

Attachments

(3 files)

The attached crash information was submitted via the ASan Nightly Reporter on mozilla-central-asan-nightly revision 63.0a1-20180721100146-https://hg.mozilla.org/mozilla-central/rev/9daa53881b7ae80bf6b093dac5d7744cf7fd18b1. For detailed crash information, see attachment. Marking s-s because this could be a security problem, though the actual problem could be in Mesa/libglapi.
Attached file Detailed Crash Information (deleted) —
Group: core-security → gfx-core-security
This is likely fairly safe, though probably bone-headed. I can take a closer look tomorrow.
Assignee: nobody → jgilbert
Flags: needinfo?(jgilbert)
...Monday it is!
No longer blocks: asan-nightly-project
I can't repro. It feels like this might be: https://bugs.freedesktop.org/show_bug.cgi?id=81992 Fixed by: https://cgit.freedesktop.org/mesa/mesa/commit/?id=1110113a7f0b6f9b21dd26dee8e95a021041c71c Do we have an about:support or driver version info for affected systems?
Flags: needinfo?(jgilbert) → needinfo?(choller)
Forwarding needinfo to the original reporter. Can you provide information as requested in comment 5? Thanks!
Flags: needinfo?(choller) → needinfo?(timhabigt)
Attached file about_support.txt (deleted) —
Flags: needinfo?(timhabigt)
Attached file glxinfo.txt (deleted) —
Output of glxinfo
If you update Mesa, does this error go away? 10.5+ should be fixed.
Flags: needinfo?(timhabigt)
I could reproduce the error reliably. I will upgrade Mesa and try again.
Also, does this cause any errors outside of the ASAN assert?
I got the "Your tab just crashed" error message. After upgrading Mesa to version 11.2.0, I can no longer reproduce the crash.
Flags: needinfo?(timhabigt)
Ok, great! I'm hoping we can open this bug and expect ASAN build users to update Mesa if they run into this. Alternatively, is there a whitelist we can add this issue to? :decoder?
Flags: needinfo?(choller)
There is unfortunately no whitelist, but I can filter for this issue on the server that receives the reports so reports from users that haven't upgraded won't hurt.
Flags: needinfo?(choller)
Priority: -- → P3
Group: gfx-core-security
Status: NEW → RESOLVED
Closed: 6 years ago
Keywords: sec-vector
Resolution: --- → FIXED
NB: Mesa 10.5 was released in early 2015.
Since this was a bug in Mesa and not in Firefox, changing the status to INVALID.
Resolution: FIXED → INVALID
decoder would prefer to leave sec-vector issues as FIXED.
Resolution: INVALID → FIXED
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: