oh wow, this is nice:

#define get_job_by_jid(ind) (jobs[(ind)])

155           if ((job == NO_JOB) || jobs == 0 || get_job_by_jid (job) == 0)

definitely this if needs looking into.

cheers,
pg

On 11 Jul 2018, at 15:41, Simon Wörner wrote:

> Dear all,
> The following crash was found by a modified
> version of the kAFL fuzzer (https://github.com/RUB-SysSec/kAFL).
> 
> The crash can be reproduced by running:
> $ ls
> $ jobs 4278190079 # 2^32-2
> 
> We can the crash for
> - GNU bash, version 4.4.19(1)-release (x86_64-pc-linux-gnu)
> - GNU bash, version 4.4.23(2) (x86_64-unknown-linux-gnu)
> - git master branch (commit 64447609994bfddeef1061948022c074093e9a9f)
> - git devel branch (commit a078e04c3d9163541cce590c3fd00f243fe77613)
> 
> Credits: Simon Wörner, Sergej Schumilo, Cornelius Aschermann (all of
> Ruhr-Universität Bochum)
> 
> Best regards,
> Simon Wörner
> 
> 


Reply via email to