Re: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=43743
enh via xml <[email protected]> Wed, 29 Jun 2022 17:02:04 -0700
| Newsgroups | gmane.comp.gnome.lib.xml.general |
|---|---|
| Message-ID | <CAJgzZopk28Bd-e8kY1dqnpVbVT6atxJOqKhBuj_OUOMK_6gt3A@mail.gmail.com> |
--===============8906265745368649227== Content-Type: multipart/alternative; boundary="0000000000007d425305e29efb09" --0000000000007d425305e29efb09 Content-Type: text/plain; charset="UTF-8" On Mon, Jun 27, 2022 at 6:14 AM Nick Wellnhofer <[email protected]> wrote: > On 24/06/2022 21:48, enh via xml wrote: > > did anyone report > https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=43743 > > <https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=43743> to > libxml2 directly? > > No, this wasn't reported. For now, these issues should be reported to the > libxml2 bug tracker. That said, I will resubscribe to OSS-Fuzz soon and > handle > new issues directly. > (sorry, your reply got stuck in gmail's spam filter :-( ) heh, the reason i found this in my spam filter is that i was hassling our oss-fuzz people and asking why they were only sending these bugs to a bunch of browser vendors rather than to you, who might actually be able to do something about them, and they wanted me to ask you whether you wanted to be in the config. sounds like you're already on top of things and they'll get their pull request when you have time anyway :-) > > sadly, it looks like there are actually a bunch of fuzzer-found bugs > that may > > never have been reported upstream? (i haven't checked; i'm just > guessing.) see > > https://bugs.chromium.org/p/oss-fuzz/issues/list?q=libxml2&can=2 > > <https://bugs.chromium.org/p/oss-fuzz/issues/list?q=libxml2&can=2> for > example. > > Most of the timeout and OOM issues are hard to fix. I'll try to address > some > of them in the next months. > yeah, the ones that get me (with Android non-third-party code where i have to _fix_ things rather than just cherrypick other people's fixes) are the stack overflows on large inputs. i really need to find out how to tell the _fuzzer_ i don't care rather than having to close bugs manually all the time! > Nick > --0000000000007d425305e29efb09 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote">= <div dir=3D"ltr" class=3D"gmail_attr">On Mon, Jun 27, 2022 at 6:14 AM Nick = Wellnhofer <<a href=3D"mailto:[email protected]" target=3D"_blank">wel= [email protected]</a>> wrote:<br></div><blockquote class=3D"gmail_quote" = style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);pa= dding-left:1ex">On 24/06/2022 21:48, enh via xml wrote:<br> > did anyone report <a href=3D"https://bugs.chromium.org/p/oss-fuzz/issu= es/detail?id=3D43743" rel=3D"noreferrer" target=3D"_blank">https://bugs.chr= omium.org/p/oss-fuzz/issues/detail?id=3D43743</a> <br> > <<a href=3D"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id= =3D43743" rel=3D"noreferrer" target=3D"_blank">https://bugs.chromium.org/p/= oss-fuzz/issues/detail?id=3D43743</a>> to libxml2 directly?<br> <br> No, this wasn't reported. For now, these issues should be reported to t= he <br> libxml2 bug tracker. That said, I will resubscribe to OSS-Fuzz soon and han= dle <br> new issues directly.<br></blockquote><div><br></div><div>(sorry, your reply= got stuck in gmail's spam filter :-( )</div><div><br></div><div>heh, t= he reason i found this in my spam filter is that i was hassling our oss-fuz= z people and asking why they were only sending these bugs to a bunch of bro= wser vendors rather than to you, who might actually be able to do something= about them, and they wanted me to ask you whether you wanted to be in the = config. sounds like you're already on top of things and they'll get= their pull request when you have time anyway :-)</div><div>=C2=A0</div><bl= ockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-lef= t:1px solid rgb(204,204,204);padding-left:1ex"> > sadly, it looks like there are actually a bunch of fuzzer-found bugs t= hat may <br> > never have been reported upstream? (i haven't checked; i'm jus= t guessing.) see <br> > <a href=3D"https://bugs.chromium.org/p/oss-fuzz/issues/list?q=3Dlibxml= 2&can=3D2" rel=3D"noreferrer" target=3D"_blank">https://bugs.chromium.o= rg/p/oss-fuzz/issues/list?q=3Dlibxml2&can=3D2</a> <br> > <<a href=3D"https://bugs.chromium.org/p/oss-fuzz/issues/list?q=3Dli= bxml2&can=3D2" rel=3D"noreferrer" target=3D"_blank">https://bugs.chromi= um.org/p/oss-fuzz/issues/list?q=3Dlibxml2&can=3D2</a>> for example.<= br> <br> Most of the timeout and OOM issues are hard to fix. I'll try to address= some <br> of them in the next months.<br></blockquote><div><br></div><div>yeah, the o= nes that get me (with Android non-third-party code where i have to _fix_ th= ings rather than just cherrypick other people's fixes) are the stack ov= erflows on large inputs. i really need to find out how to tell the _fuzzer_= i don't care rather than having to close bugs manually all the time!</= div><div>=C2=A0</div><blockquote class=3D"gmail_quote" style=3D"margin:0px = 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"> Nick<br> </blockquote></div></div> --0000000000007d425305e29efb09-- --===============8906265745368649227== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ xml mailing list, project page http://xmlsoft.org/ [email protected] https://mail.gnome.org/mailman/listinfo/xml --===============8906265745368649227==--