google / google/oss-fuzz

Issue 52037 is also a false positive

Open
#8,666 9 comments 0 reactions 0 assignees View on GitHub
Dominant language
Shell
Stars
12.6k
Forks
2.9k
Avg merge
2d 2h
Merged PRs (30d)
62

Description

How do I mark false positives? This one, 53037, is also a false positive. The fuzzer is calling an internal function that is called only after the inputs have been sanitized. So to complain that the inputs are not checked for sanity is a false positive.

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the false-positive report referenced as 53037 and the surrounding issue discussion. Determine how false positives are marked when an internal function is reached only after inputs are sanitized; done means documenting or confirming the appropriate handling for this report.

Written by the indexing model from the issue text.

Assessment

Domain
security, testing-qa
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.