https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=15037
Bug ID: 15037
Summary: Buildbot crash output: fuzz-2018-08-06-11938.pcap
Product: Wireshark
Version: unspecified
Hardware: x86-64
OS: Ubuntu
Status: CONFIRMED
Severity: Major
Priority: High
Component: Dissection engine (libwireshark)
Assignee: [email protected]
Reporter: [email protected]
Target Milestone: ---
Problems have been found with the following capture file:
https://www.wireshark.org/download/automated/captures/fuzz-2018-08-06-11938.pcap
stderr:
Input file: /home/wireshark/menagerie/menagerie/10619-80211ad.pcap
Build host information:
Linux wsbb04 4.4.0-130-generic #156-Ubuntu SMP Thu Jun 14 08:53:28 UTC 2018
x86_64 x86_64 x86_64 GNU/Linux
Distributor ID: Ubuntu
Description: Ubuntu 16.04.4 LTS
Release: 16.04
Codename: xenial
Buildbot information:
BUILDBOT_REPOSITORY=ssh://[email protected]:29418/wireshark
BUILDBOT_WORKERNAME=clang-code-analysis
BUILDBOT_BUILDNUMBER=4851
BUILDBOT_URL=http://buildbot.wireshark.org/wireshark-master/
BUILDBOT_BUILDERNAME=Clang Code Analysis
BUILDBOT_GOT_REVISION=1dc6d54d8d6b794549473ced4435c2d749b72076
Return value: 0
Dissector bug: 0
Valgrind error count: 433
Git commit
commit 1dc6d54d8d6b794549473ced4435c2d749b72076
Author: Guy Harris <[email protected]>
Date: Mon Aug 6 12:03:56 2018 -0700
Another dictionary fix.
RFC 5447 says MIP6-Feature-Vector is a 64-bit integer, not an octet
string.
Change-Id: I676cb4de09424259a9020680d11b92b783100482
Reviewed-on: https://code.wireshark.org/review/28999
Reviewed-by: Guy Harris <[email protected]>
Command and args: ./tools/valgrind-wireshark.sh -b
/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install.plain/bin
==21023== Memcheck, a memory error detector
==21023== Copyright (C) 2002-2015, and GNU GPL'd, by Julian Seward et al.
==21023== Using Valgrind-3.11.0 and LibVEX; rerun with -h for copyright info
==21023== Command:
/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install.plain/bin/tshark
-nr /fuzz/buildbot/clangcodeanalysis/valgrind-fuzz/fuzz-2018-08-06-11938.pcap
==21023==
==21023== Conditional jump or move depends on uninitialised value(s)
==21023== at 0x6ECF853: ieee80211_radiotap_iterator_next
(packet-ieee80211-radiotap-iter.c:313)
==21023== by 0x6ED08C5: dissect_radiotap (packet-ieee80211-radiotap.c:2087)
==21023== by 0x7F447F7: call_dissector_through_handle (packet.c:692)
==21023== by 0x7F40669: call_dissector_work (packet.c:777)
==21023== by 0x7F40477: dissector_try_uint_new (packet.c:1359)
==21023== by 0x6D50CC1: dissect_frame (packet-frame.c:579)
==21023== by 0x7F447F7: call_dissector_through_handle (packet.c:692)
==21023== by 0x7F40669: call_dissector_work (packet.c:777)
==21023== by 0x7F434A2: call_dissector_only (packet.c:3090)
==21023== by 0x7F3F0F4: call_dissector_with_data (packet.c:3103)
==21023== by 0x7F3EEF7: dissect_record (packet.c:566)
==21023== by 0x7F2F948: epan_dissect_run_with_taps (epan.c:551)
==21023==
==21023== Conditional jump or move depends on uninitialised value(s)
==21023== at 0x6ECF8B5: ieee80211_radiotap_iterator_next
(packet-ieee80211-radiotap-iter.c:319)
==21023== by 0x6ED08C5: dissect_radiotap (packet-ieee80211-radiotap.c:2087)
==21023== by 0x7F447F7: call_dissector_through_handle (packet.c:692)
==21023== by 0x7F40669: call_dissector_work (packet.c:777)
==21023== by 0x7F40477: dissector_try_uint_new (packet.c:1359)
==21023== by 0x6D50CC1: dissect_frame (packet-frame.c:579)
==21023== by 0x7F447F7: call_dissector_through_handle (packet.c:692)
==21023== by 0x7F40669: call_dissector_work (packet.c:777)
==21023== by 0x7F434A2: call_dissector_only (packet.c:3090)
==21023== by 0x7F3F0F4: call_dissector_with_data (packet.c:3103)
==21023== by 0x7F3EEF7: dissect_record (packet.c:566)
==21023== by 0x7F2F948: epan_dissect_run_with_taps (epan.c:551)
==21023==
==21023== Use of uninitialised value of size 8
==21023== at 0x6ECF8CF: ieee80211_radiotap_iterator_next
(packet-ieee80211-radiotap-iter.c:322)
==21023== by 0x6ED08C5: dissect_radiotap (packet-ieee80211-radiotap.c:2087)
==21023== by 0x7F447F7: call_dissector_through_handle (packet.c:692)
==21023== by 0x7F40669: call_dissector_work (packet.c:777)
==21023== by 0x7F40477: dissector_try_uint_new (packet.c:1359)
==21023== by 0x6D50CC1: dissect_frame (packet-frame.c:579)
==21023== by 0x7F447F7: call_dissector_through_handle (packet.c:692)
==21023== by 0x7F40669: call_dissector_work (packet.c:777)
==21023== by 0x7F434A2: call_dissector_only (packet.c:3090)
==21023== by 0x7F3F0F4: call_dissector_with_data (packet.c:3103)
==21023== by 0x7F3EEF7: dissect_record (packet.c:566)
==21023== by 0x7F2F948: epan_dissect_run_with_taps (epan.c:551)
==21023==
==21023== Use of uninitialised value of size 8
==21023== at 0x6ECF8DD: ieee80211_radiotap_iterator_next
(packet-ieee80211-radiotap-iter.c:323)
==21023== by 0x6ED08C5: dissect_radiotap (packet-ieee80211-radiotap.c:2087)
==21023== by 0x7F447F7: call_dissector_through_handle (packet.c:692)
==21023== by 0x7F40669: call_dissector_work (packet.c:777)
==21023== by 0x7F40477: dissector_try_uint_new (packet.c:1359)
==21023== by 0x6D50CC1: dissect_frame (packet-frame.c:579)
==21023== by 0x7F447F7: call_dissector_through_handle (packet.c:692)
==21023== by 0x7F40669: call_dissector_work (packet.c:777)
==21023== by 0x7F434A2: call_dissector_only (packet.c:3090)
==21023== by 0x7F3F0F4: call_dissector_with_data (packet.c:3103)
==21023== by 0x7F3EEF7: dissect_record (packet.c:566)
==21023== by 0x7F2F948: epan_dissect_run_with_taps (epan.c:551)
==21023==
==21023== Use of uninitialised value of size 8
==21023== at 0x6ECF8EE: ieee80211_radiotap_iterator_next
(packet-ieee80211-radiotap-iter.c:324)
==21023== by 0x6ED08C5: dissect_radiotap (packet-ieee80211-radiotap.c:2087)
==21023== by 0x7F447F7: call_dissector_through_handle (packet.c:692)
==21023== by 0x7F40669: call_dissector_work (packet.c:777)
==21023== by 0x7F40477: dissector_try_uint_new (packet.c:1359)
==21023== by 0x6D50CC1: dissect_frame (packet-frame.c:579)
==21023== by 0x7F447F7: call_dissector_through_handle (packet.c:692)
==21023== by 0x7F40669: call_dissector_work (packet.c:777)
==21023== by 0x7F434A2: call_dissector_only (packet.c:3090)
==21023== by 0x7F3F0F4: call_dissector_with_data (packet.c:3103)
==21023== by 0x7F3EEF7: dissect_record (packet.c:566)
==21023== by 0x7F2F948: epan_dissect_run_with_taps (epan.c:551)
==21023==
==21023== Use of uninitialised value of size 8
==21023== at 0x6ECF8FF: ieee80211_radiotap_iterator_next
(packet-ieee80211-radiotap-iter.c:325)
==21023== by 0x6ED08C5: dissect_radiotap (packet-ieee80211-radiotap.c:2087)
==21023== by 0x7F447F7: call_dissector_through_handle (packet.c:692)
==21023== by 0x7F40669: call_dissector_work (packet.c:777)
==21023== by 0x7F40477: dissector_try_uint_new (packet.c:1359)
==21023== by 0x6D50CC1: dissect_frame (packet-frame.c:579)
==21023== by 0x7F447F7: call_dissector_through_handle (packet.c:692)
==21023== by 0x7F40669: call_dissector_work (packet.c:777)
==21023== by 0x7F434A2: call_dissector_only (packet.c:3090)
==21023== by 0x7F3F0F4: call_dissector_with_data (packet.c:3103)
==21023== by 0x7F3EEF7: dissect_record (packet.c:566)
==21023== by 0x7F2F948: epan_dissect_run_with_taps (epan.c:551)
==21023==
==21023== Use of uninitialised value of size 8
==21023== at 0x6ECF5FC: pletoh16 (pint.h:90)
==21023== by 0x6ECF92F: ieee80211_radiotap_iterator_next
(packet-ieee80211-radiotap-iter.c:329)
==21023== by 0x6ED08C5: dissect_radiotap (packet-ieee80211-radiotap.c:2087)
==21023== by 0x7F447F7: call_dissector_through_handle (packet.c:692)
==21023== by 0x7F40669: call_dissector_work (packet.c:777)
==21023== by 0x7F40477: dissector_try_uint_new (packet.c:1359)
==21023== by 0x6D50CC1: dissect_frame (packet-frame.c:579)
==21023== by 0x7F447F7: call_dissector_through_handle (packet.c:692)
==21023== by 0x7F40669: call_dissector_work (packet.c:777)
==21023== by 0x7F434A2: call_dissector_only (packet.c:3090)
==21023== by 0x7F3F0F4: call_dissector_with_data (packet.c:3103)
==21023== by 0x7F3EEF7: dissect_record (packet.c:566)
==21023==
==21023== Conditional jump or move depends on uninitialised value(s)
==21023== at 0x6ECF9CB: ieee80211_radiotap_iterator_next
(packet-ieee80211-radiotap-iter.c:353)
==21023== by 0x6ED08C5: dissect_radiotap (packet-ieee80211-radiotap.c:2087)
==21023== by 0x7F447F7: call_dissector_through_handle (packet.c:692)
==21023== by 0x7F40669: call_dissector_work (packet.c:777)
==21023== by 0x7F40477: dissector_try_uint_new (packet.c:1359)
==21023== by 0x6D50CC1: dissect_frame (packet-frame.c:579)
==21023== by 0x7F447F7: call_dissector_through_handle (packet.c:692)
==21023== by 0x7F40669: call_dissector_work (packet.c:777)
==21023== by 0x7F434A2: call_dissector_only (packet.c:3090)
==21023== by 0x7F3F0F4: call_dissector_with_data (packet.c:3103)
==21023== by 0x7F3EEF7: dissect_record (packet.c:566)
==21023== by 0x7F2F948: epan_dissect_run_with_taps (epan.c:551)
==21023==
==21023==
==21023== HEAP SUMMARY:
==21023== in use at exit: 125,787 bytes in 369 blocks
==21023== total heap usage: 1,145,747 allocs, 1,145,378 frees, 67,640,887
bytes allocated
==21023==
==21023== LEAK SUMMARY:
==21023== definitely lost: 0 bytes in 0 blocks
==21023== indirectly lost: 0 bytes in 0 blocks
==21023== possibly lost: 0 bytes in 0 blocks
==21023== still reachable: 15,108 bytes in 89 blocks
==21023== of which reachable via heuristic:
==21023== newarray : 1,536 bytes in 16 blocks
==21023== suppressed: 110,679 bytes in 280 blocks
==21023== Rerun with --leak-check=full to see details of leaked memory
==21023==
==21023== For counts of detected and suppressed errors, rerun with: -v
==21023== Use --track-origins=yes to see where uninitialised values come from
==21023== ERROR SUMMARY: 433 errors from 8 contexts (suppressed: 0 from 0)
[ no debug trace ]
--
You are receiving this mail because:
You are watching all bug changes.___________________________________________________________________________
Sent via: Wireshark-bugs mailing list <[email protected]>
Archives: https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
mailto:[email protected]?subject=unsubscribe