Replying to this email means your email address will be shared with the
team that works on this product.
https://issues.oss-fuzz.com/issues/408254000

Reference Info: 408254000 binutils:fuzz_addr2line: Heap-buffer-overflow in
bfd_getb16
component:  Public Trackers > 1362134 > OSS Fuzz
status:  New
reporter:  87...@developer.gserviceaccount.com
cc:  am...@gmail.com, bug-binutils@gnu.org, da...@adalogics.com, and 2 more
collaborators:  co...@oss-fuzz.com
type:  Vulnerability
access level:  Limited visibility
priority:  P2
severity:  S2
hotlist:  Reproducible, Stability-LibFuzzer,
Stability-Memory-AddressSanitizer
retention:  Component default
Project:  binutils
Reported:  Apr 4, 2025

87...@developer.gserviceaccount.com added comment #1:
Detailed Report: https://oss-fuzz.com/testcase?key=4519077014208512

Project: binutils
Fuzzing Engine: libFuzzer
Fuzz Target: fuzz_addr2line
Job Type: libfuzzer_asan_binutils
Platform Id: linux

Crash Type: Heap-buffer-overflow READ 1
Crash Address: 0x5120000008e1
Crash State:
  bfd_getb16
  nds32_elf_do_9_pcrel_reloc
  nds32_elf_9_pcrel_reloc

Sanitizer: address (ASAN)

Recommended Security Severity: Medium

Regressed:
https://oss-fuzz.com/revisions?job=libfuzzer_asan_binutils&range=202408250602:202408260621

Reproducer Testcase:
https://oss-fuzz.com/download?testcase_id=4519077014208512

Issue filed automatically.

See https://google.github.io/oss-fuzz/advanced-topics/reproducing for
instructions to reproduce this bug locally.
When you fix this bug, please
  * mention the fix revision(s).
  * state whether the bug was a short-lived regression or an old bug in any
stable releases.
  * add any other useful information.
This information can help downstream consumers.

If you need to contact the OSS-Fuzz team with a question, concern, or any
other feedback, please file an issue at
https://github.com/google/oss-fuzz/issues. Comments on individual Monorail
issues are not monitored.

This bug is subject to a 90 day disclosure deadline. If 90 days elapse
without an upstream patch, then the bug report will automatically
become visible to the public.


Generated by Google IssueTracker notification system.

Reply via email to