{
    "id": "42537641",
    "link": "https://issues.oss-fuzz.com/issues/42537641",
    "title": "MemorySanitizer: use-of-uninitialized-value in cbs_vp9_split_fragment",
    "parent_of_fix_commit": "d50f9701b63a7270922ed754a720fe76e80c0bed",
    "crashes": [
        {
            "kernel-source-commit": "d50f9701b63a7270922ed754a720fe76e80c0bed",
            "crash-report-data": "MemorySanitizer: use-of-uninitialized-value\n    #0 0x560e12c40d01 in cbs_vp9_split_fragment libavcodec/cbs_vp9.c:400:17\n    #1 0x560e12a67bf6 in cbs_read_data libavcodec/cbs.c:279:11\n    #2 0x560e12a0d2bf in ff_cbs_bsf_generic_filter libavcodec/cbs_bsf.c:75:11\n    #3 0x560e12a07b57 in LLVMFuzzerTestOneInput tools/target_bsf_fuzzer.c:155:16\n    #4 0x560e128fc5e0 in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerLoop.cpp:614:13\n    #5 0x560e128e7855 in fuzzer::RunOneTest(fuzzer::Fuzzer*, char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:327:6\n    #6 0x560e128ed2ef in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:862:9\n    #7 0x560e12918592 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10\n    #8 0x7f219cbc4082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) (BuildId: 0323ab4806bee6f846d9ad4bccfc29afdca49a58)\n    #9 0x560e128dfa3d in _start (/out/ffmpeg_BSF_VP9_METADATA_fuzzer+0x1dfa3d)\n\nDEDUP_TOKEN: cbs_vp9_split_fragment--cbs_read_data--ff_cbs_bsf_generic_filter\n  Uninitialized value was created by an allocation of 'sfi' in the stack frame\n    #0 0x560e12c3f88b in cbs_vp9_split_fragment libavcodec/cbs_vp9.c:378:9\n\nDEDUP_TOKEN: cbs_vp9_split_fragment\nSUMMARY: MemorySanitizer: use-of-uninitialized-value libavcodec/cbs_vp9.c:400:17 in cbs_vp9_split_fragment"
        }
    ],
    "sanitizer": "memory",
    "engine": "libfuzzer",
    "target": "ffmpeg_BSF_VP9_METADATA_fuzzer"
}
