fuzz: weekly regression seeds (2026-05-31)#12
Open
lilith wants to merge 1 commit into
Open
Conversation
New OOM in limits_boundaries: scale decode with oversized dims triggers 13.5 GB malloc in WebPAllocateDecBuffer (scale_w=51794, scale_h=65505, use_scale=true). Minimized to 73 bytes. https://claude.ai/code/session_01R7wJyc77Fym34qcakBcqfj
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #12 +/- ##
=======================================
Coverage 78.85% 78.85%
=======================================
Files 18 18
Lines 4460 4460
=======================================
Hits 3517 3517
Misses 943 943 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Weekly automated fuzz sweep for webpx.
New crashes
OOM details:
scale decodewithscale_w=51794,scale_h=65505,use_scale=true, and a craftedmax_total_pixelsvalue that bypasses the limit check. This triggers a 13,571,063,880-byte malloc inWebPAllocateDecBuffer→DecodeInto→WebPDecodeviaDecoder::decode_rgba. Stack trace confirms libwebp allocates output buffer based on scaled dimensions before checking limits. Minimized from 78 → 73 bytes.Per-target stats
Notes
-dict=webp.dict -max_len=65536cargo test --all-features --test fuzz_regressionpasses with the new seeddecode.rs:948(decode_advanced) whenuse_scale=trueallows libwebp to allocate a scaled output buffer whose dimensions (51794×65505×4 = ~13.5 GB) exceed available memory. Themax_total_pixelsfield inLimitInputdid not prevent the allocation.limits_boundariesexec count not captured (run terminated after OOM was found and tmin was run)https://claude.ai/code/session_01R7wJyc77Fym34qcakBcqfj
Generated by Claude Code