apache / apache/arrow-java

[Java] FuzzIpcFile: Uncaught exception in java.base/java.nio.HeapByteBuffer.<init>

Aberta
#358 0 comentários 0 reações 0 responsáveis Ver no GitHub
Type: bug
Linguagem predominante
Java
Estrelas
94
Forks
152
Merge médio
3d 16h
PRs com merge (30d)
11

Descrição

Detailed Report: https://oss-fuzz.com/testcase?key=5015797066498048

Project: arrow-java
Fuzzing Engine: libFuzzer
Fuzz Target: FuzzIpcFile
Job Type: libfuzzer_asan_arrow-java
Platform Id: linux

Crash Type: Uncaught exception
Crash Address:
Crash State:
java.base/java.nio.HeapByteBuffer.
java.base/java.nio.ByteBuffer.allocate
org.apache.arrow.vector.ipc.ArrowFileReader.readSchema

Sanitizer: address (ASAN)

Recommended Security Severity: Low

Crash Revision: https://oss-fuzz.com/revisions?job=libfuzzer_asan_arrow-java&revision=202201300605

Reproducer Testcase: https://oss-fuzz.com/download?testcase_id=5015797066498048

Issue filed automatically.

See https://google.github.io/oss-fuzz/advanced-topics/reproducing for instructions to reproduce this bug locally.
When you fix this bug, please
- mention the fix revision(s).
- state whether the bug was a short-lived regression or an old bug in any stable releases.
- add any other useful information.
This information can help downstream consumers.

If you need to contact the OSS-Fuzz team with a question, concern, or any other feedback, please file an issue at https://github.com/google/oss-fuzz/issues. Comments on individual Monorail issues are not monitored.

This bug is subject to a 90 day disclosure deadline. If 90 days elapse
without an upstream patch, then the bug report will automatically
become visible to the public.

**Reporter**: [Liya Fan](https://issues.apache.org/jira/browse/ARROW-15557) / @liyafan82

**Note**: *This issue was originally created as [ARROW-15557](https://issues.apache.org/jira/browse/ARROW-15557). Please see the [migration documentation](https://github.com/apache/arrow/issues/14542) for further details.*

Guia de contribuição

Abrir o guia de contribuição

Direção de pesquisa

Comece com as instruções de reprodução do OSS-Fuzz e o testcase 5015797066498048; em seguida, inspecione org.apache.arrow.vector.ipc.ArrowFileReader.readSchema e a alocação de HeapByteBuffer no crash stack. Reproduza a falha localmente e rastreie o tratamento da entrada em torno da leitura do schema. O trabalho estará concluído quando o testcase não causar mais uma exceção não capturada.

Escrita pelo modelo de indexação a partir do texto da issue.

Avaliação

Stack de tecnologia
java
Domínio
data
Tipo de issue
Bug
Dificuldade
4/5
Tempo estimado
3-5 dias
Status de atividade
Estagnada
Clareza
Razoavelmente clara
Facilidade para iniciantes
35/100

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.