Crash on jobs 2^32-2

2018-07-11 Thread Simon Wörner
Dear all,
The following crash was found by a modified
version of the kAFL fuzzer (https://github.com/RUB-SysSec/kAFL).

The crash can be reproduced by running:
$ ls
$ jobs 4278190079 # 2^32-2

We can the crash for
- GNU bash, version 4.4.19(1)-release (x86_64-pc-linux-gnu)
- GNU bash, version 4.4.23(2) (x86_64-unknown-linux-gnu)
- git master branch (commit 64447609994bfddeef1061948022c074093e9a9f)
- git devel branch (commit a078e04c3d9163541cce590c3fd00f243fe77613)

Credits: Simon Wörner, Sergej Schumilo, Cornelius Aschermann (all of
Ruhr-Universität Bochum)

Best regards,
Simon Wörner




Re: Crash on jobs 2^32-2

2018-07-11 Thread Piotr Grzybowski


 oh wow, this is nice:

#define get_job_by_jid(ind) (jobs[(ind)])

155   if ((job == NO_JOB) || jobs == 0 || get_job_by_jid (job) == 0)

definitely this if needs looking into.

cheers,
pg

On 11 Jul 2018, at 15:41, Simon Wörner wrote:

> Dear all,
> The following crash was found by a modified
> version of the kAFL fuzzer (https://github.com/RUB-SysSec/kAFL).
> 
> The crash can be reproduced by running:
> $ ls
> $ jobs 4278190079 # 2^32-2
> 
> We can the crash for
> - GNU bash, version 4.4.19(1)-release (x86_64-pc-linux-gnu)
> - GNU bash, version 4.4.23(2) (x86_64-unknown-linux-gnu)
> - git master branch (commit 64447609994bfddeef1061948022c074093e9a9f)
> - git devel branch (commit a078e04c3d9163541cce590c3fd00f243fe77613)
> 
> Credits: Simon Wörner, Sergej Schumilo, Cornelius Aschermann (all of
> Ruhr-Universität Bochum)
> 
> Best regards,
> Simon Wörner
> 
>