[Java] FuzzIpcStream: Uncaught exception in java.base/java.nio.Buffer.createCapacityException
- 主要語言
- Java
- 星號
- 94
- 分支
- 152
- 平均合併
- 3 天 16 小時
- 30 天內合併 PR
- 11
描述
Detailed Report: https://oss-fuzz.com/testcase?key=5095153130405888
Project: arrow-java
Fuzzing Engine: libFuzzer
Fuzz Target: FuzzIpcStream
Job Type: libfuzzer_asan_arrow-java
Platform Id: linux
Crash Type: Uncaught exception
Crash Address:
Crash State:
java.base/java.nio.Buffer.createCapacityException
java.base/java.nio.ByteBuffer.allocate
org.apache.arrow.vector.ipc.message.MessageSerializer.readMessage
Sanitizer: address (ASAN)
Crash Revision: https://oss-fuzz.com/revisions?job=libfuzzer_asan_arrow-java&revision=202201300605
Reproducer Testcase: https://oss-fuzz.com/download?testcase_id=5095153130405888
Issue filed automatically.
See https://google.github.io/oss-fuzz/advanced-topics/reproducing for instructions to reproduce this bug locally.
When you fix this bug, please
- mention the fix revision(s).
- state whether the bug was a short-lived regression or an old bug in any stable releases.
- add any other useful information.
This information can help downstream consumers.
If you need to contact the OSS-Fuzz team with a question, concern, or any other feedback, please file an issue at https://github.com/google/oss-fuzz/issues. Comments on individual Monorail issues are not monitored.
This bug is subject to a 90 day disclosure deadline. If 90 days elapse
without an upstream patch, then the bug report will automatically
become visible to the public.
**Reporter**: [Liya Fan](https://issues.apache.org/jira/browse/ARROW-15560) / @liyafan82
**Note**: *This issue was originally created as [ARROW-15560](https://issues.apache.org/jira/browse/ARROW-15560). Please see the [migration documentation](https://github.com/apache/arrow/issues/14542) for further details.*
貢獻指南
研究方向
從 org.apache.arrow.vector.ipc.message.MessageSerializer.readMessage 開始,使用 testcase 5095153130405888 和 OSS-Fuzz 的重現指南重現 FuzzIpcStream 當機。追蹤回報的 ByteBuffer.allocate 失敗,並驗證提供的 testcase 不再產生未捕捉的例外。
由索引模型根據 Issue 內容生成。
評估
- 技術堆疊
- java
- 領域
- data-engineering
- Issue 類型
- 缺陷
- 難度
- 3/5
- 預估耗時
- 1-2 天
- 活躍度
- 停滯
- 描述清晰度
- 基本清楚
- 新手友好度
- 35/100