[llvm-bugs] [Bug 32889] New: Stack-overflow in demangler (11)

via llvm-bugs llvm-bugs at lists.llvm.org
Tue May 2 03:35:12 PDT 2017


https://bugs.llvm.org/show_bug.cgi?id=32889

            Bug ID: 32889
           Summary: Stack-overflow in demangler (11)
           Product: libc++abi
           Version: unspecified
          Hardware: All
                OS: Linux
            Status: NEW
          Severity: normal
          Priority: P
         Component: All Bugs
          Assignee: unassignedbugs at nondot.org
          Reporter: dungnguy at comp.nus.edu.sg
                CC: llvm-bugs at lists.llvm.org, mclow.lists at gmail.com

Dear All,

This bug was found with AFLGo, a directed version of AFL/AFLFast. Thanks also
to Marcel Böhme and Van-Thuan Pham.

First, you need to build the project
(https://github.com/llvm-mirror/libcxxabi/blob/master/fuzz/cxa_demangle_fuzzer.cpp)
to obtain the binary file.

To reproduce:
$ printf "DTc" > test
$ for o in $(seq 1 15000); do printf "o"; done >> test; echo "" >> test; cat
test | ./cxa_demangle_fuzzer
Segmentation fault

ASAN says:
==30344==ERROR: AddressSanitizer: stack-overflow on address 0x7fffe25c2700 (pc
0x0000006c554e bp 0x7fffe25c4eb0 sp 0x7fffe25c2700 T0)
    #0 0x6c554d in char const* __cxxabiv1::(anonymous
namespace)::parse_expression<__cxxabiv1::(anonymous namespace)::Db>(char
const*, char const*, __cxxabiv1::(anonymous namespace)::Db&)
/src/llvm_libcxxabi/src/cxa_demangle.cpp:3321
    #1 0x75db2f in char const* __cxxabiv1::(anonymous
namespace)::parse_binary_expression<__cxxabiv1::(anonymous namespace)::Db>(char
const*, char const*, __cxxabiv1::(anonymous namespace)::Db::String const&,
__cxxabiv1::(anonymous namespace)::Db&)
/src/llvm_libcxxabi/src/cxa_demangle.cpp:3252:22
    #2 0x6c862f in char const* __cxxabiv1::(anonymous
namespace)::parse_expression<__cxxabiv1::(anonymous namespace)::Db>(char
const*, char const*, __cxxabiv1::(anonymous namespace)::Db&)
/src/llvm_libcxxabi/src/cxa_demangle.cpp:3620:21
    #3 0x75db2f in char const* __cxxabiv1::(anonymous
namespace)::parse_binary_expression<__cxxabiv1::(anonymous namespace)::Db>(char
const*, char const*, __cxxabiv1::(anonymous namespace)::Db::String const&,
__cxxabiv1::(anonymous namespace)::Db&)
/src/llvm_libcxxabi/src/cxa_demangle.cpp:3252:22
    #4 0x6c862f in char const* __cxxabiv1::(anonymous
namespace)::parse_expression<__cxxabiv1::(anonymous namespace)::Db>(char
const*, char const*, __cxxabiv1::(anonymous namespace)::Db&)
/src/llvm_libcxxabi/src/cxa_demangle.cpp:3620:21
    #5 0x75db2f in char const* __cxxabiv1::(anonymous
namespace)::parse_binary_expression<__cxxabiv1::(anonymous namespace)::Db>(char
const*, char const*, __cxxabiv1::(anonymous namespace)::Db::String const&,
__cxxabiv1::(anonymous namespace)::Db&)
/src/llvm_libcxxabi/src/cxa_demangle.cpp:3252:22
    #6 0x6c862f in char const* __cxxabiv1::(anonymous
namespace)::parse_expression<__cxxabiv1::(anonymous namespace)::Db>(char
const*, char const*, __cxxabiv1::(anonymous namespace)::Db&)
/src/llvm_libcxxabi/src/cxa_demangle.cpp:3620:21

Regards,
Manh-Dung Nguyen

-- 
You are receiving this mail because:
You are on the CC list for the bug.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.llvm.org/pipermail/llvm-bugs/attachments/20170502/891d3e5e/attachment.html>


More information about the llvm-bugs mailing list