Discussion:
[Bug 777525] New: floating point exception in gst_riff_create_audio_caps (different than #777262)
(too old to reply)
"GStreamer" (GNOME Bugzilla)
2017-01-20 09:58:43 UTC
Permalink
Raw Message
https://bugzilla.gnome.org/show_bug.cgi?id=777525

Bug ID: 777525
Summary: floating point exception in gst_riff_create_audio_caps
(different than #777262)
Classification: Platform
Product: GStreamer
Version: unspecified
OS: Linux
Status: NEW
Severity: normal
Priority: Normal
Component: gst-plugins-base
Assignee: gstreamer-***@lists.freedesktop.org
Reporter: ***@hboeck.de
QA Contact: gstreamer-***@lists.freedesktop.org
GNOME version: ---

Created attachment 343888
--> https://bugzilla.gnome.org/attachment.cgi?id=343888&action=edit
poc file

This looks very similar to
https://bugzilla.gnome.org/show_bug.cgi?id=777262
but it still happens after the fix for the above bug.

Found with afl.

==19886==ERROR: AddressSanitizer: FPE on unknown address 0x7f866bc99e64 (pc
0x7f866bc99e64 bp 0x7f866b53ec20 sp 0x7f866b53ea80 T2)
#0 0x7f866bc99e63 in gst_riff_create_audio_caps
/f/gstreamer/gst-plugins-base/gst-libs/gst/riff/riff-media.c:1302:26
#1 0x7f866befbbc6 in gst_asf_demux_add_audio_stream
/f/gstreamer/gst-plugins-ugly/gst/asfdemux/gstasfdemux.c:2681:10
#2 0x7f866befbbc6 in gst_asf_demux_parse_stream_object
/f/gstreamer/gst-plugins-ugly/gst/asfdemux/gstasfdemux.c:3036
#3 0x7f866beeb3fd in gst_asf_demux_process_object
/f/gstreamer/gst-plugins-ugly/gst/asfdemux/gstasfdemux.c:4414:7
#4 0x7f866bef0226 in gst_asf_demux_process_header
/f/gstreamer/gst-plugins-ugly/gst/asfdemux/gstasfdemux.c:3638:11
#5 0x7f866bef0226 in gst_asf_demux_process_object
/f/gstreamer/gst-plugins-ugly/gst/asfdemux/gstasfdemux.c:4421
#6 0x7f866bedd682 in gst_asf_demux_pull_headers
/f/gstreamer/gst-plugins-ugly/gst/asfdemux/gstasfdemux.c:1229:10
#7 0x7f866bedd682 in gst_asf_demux_loop
/f/gstreamer/gst-plugins-ugly/gst/asfdemux/gstasfdemux.c:1984
#8 0x7f867915f883 in gst_task_func
/f/gstreamer/gstreamer/gst/gsttask.c:334:5
#9 0x7f867835cb2d in g_thread_pool_thread_proxy
/var/tmp/portage/dev-libs/glib-2.50.2/work/glib-2.50.2/glib/gthreadpool.c:307
#10 0x7f867835c154 in g_thread_proxy
/var/tmp/portage/dev-libs/glib-2.50.2/work/glib-2.50.2/glib/gthread.c:784
#11 0x7f8677dda453 in start_thread (/lib64/libpthread.so.0+0x7453)
#12 0x7f867790a5dc in clone (/lib64/libc.so.6+0xe75dc)

AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: FPE
/f/gstreamer/gst-plugins-base/gst-libs/gst/riff/riff-media.c:1302:26 in
gst_riff_create_audio_caps
Thread T2 (asfdemux0:sink) created by T1 (typefind:sink) here:
#0 0x42df2d in __interceptor_pthread_create
(/usr/bin/gst-discoverer-1.0+0x42df2d)
#1 0x7f86783791bf in g_system_thread_new
/var/tmp/portage/dev-libs/glib-2.50.2/work/glib-2.50.2/glib/gthread-posix.c:1170

Thread T1 (typefind:sink) created by T0 here:
#0 0x42df2d in __interceptor_pthread_create
(/usr/bin/gst-discoverer-1.0+0x42df2d)
#1 0x7f86783791bf in g_system_thread_new
/var/tmp/portage/dev-libs/glib-2.50.2/work/glib-2.50.2/glib/gthread-posix.c:1170

==19886==ABORTING
--
You are receiving this mail because:
You are the QA Contact for the bug.
You are the assignee for the bug.
"GStreamer" (GNOME Bugzilla)
2017-01-20 10:41:50 UTC
Permalink
Raw Message
https://bugzilla.gnome.org/show_bug.cgi?id=777525

Sebastian Dröge (slomo) <***@coaxion.net> changed:

What |Removed |Added
----------------------------------------------------------------------------
Status|NEW |RESOLVED
CC| |***@coaxion.net
Resolution|--- |FIXED

--- Comment #1 from Sebastian Dröge (slomo) <***@coaxion.net> ---
commit 5d505d108800cef210f67dcfed2801ba36beac2a
Author: Sebastian Dröge <***@centricular.com>
Date: Fri Jan 20 12:41:16 2017 +0200

riff-media: Don't divide block align by zero channels

https://bugzilla.gnome.org/show_bug.cgi?id=777525
--
You are receiving this mail because:
You are the QA Contact for the bug.
You are the assignee for the bug.
"GStreamer" (GNOME Bugzilla)
2017-01-20 10:42:00 UTC
Permalink
Raw Message
https://bugzilla.gnome.org/show_bug.cgi?id=777525

--- Comment #2 from Sebastian Dröge (slomo) <***@coaxion.net> ---
Created attachment 343891
--> https://bugzilla.gnome.org/attachment.cgi?id=343891&action=edit
riff-media: Don't divide block align by zero channels
--
You are receiving this mail because:
You are the QA Contact for the bug.
You are the assignee for the bug.
"GStreamer" (GNOME Bugzilla)
2017-01-20 10:42:17 UTC
Permalink
Raw Message
https://bugzilla.gnome.org/show_bug.cgi?id=777525

Sebastian Dröge (slomo) <***@coaxion.net> changed:

What |Removed |Added
----------------------------------------------------------------------------
Target Milestone|git master |1.11.2
--
You are receiving this mail because:
You are the QA Contact for the bug.
You are the assignee for the bug.
"GStreamer" (GNOME Bugzilla)
2017-01-20 10:42:21 UTC
Permalink
Raw Message
https://bugzilla.gnome.org/show_bug.cgi?id=777525

Sebastian Dröge (slomo) <***@coaxion.net> changed:

What |Removed |Added
----------------------------------------------------------------------------
Attachment #343891|none |committed
status| |
--
You are receiving this mail because:
You are the QA Contact for the bug.
You are the assignee for the bug.
"GStreamer" (GNOME Bugzilla)
2017-01-25 12:29:52 UTC
Permalink
Raw Message
https://bugzilla.gnome.org/show_bug.cgi?id=777525

Sebastian Dröge (slomo) <***@coaxion.net> changed:

What |Removed |Added
----------------------------------------------------------------------------
Target Milestone|1.11.2 |1.10.3
--
You are receiving this mail because:
You are the QA Contact for the bug.
You are the assignee for the bug.
"GStreamer" (GNOME Bugzilla)
2017-02-14 06:24:20 UTC
Permalink
Raw Message
https://bugzilla.gnome.org/show_bug.cgi?id=777525

Salvatore Bonaccorso <***@debian.org> changed:

What |Removed |Added
----------------------------------------------------------------------------
CC| |***@debian.org
Alias| |CVE-2017-5844
--
You are receiving this mail because:
You are the QA Contact for the bug.
You are the assignee for the bug.
Loading...