Problems have been found with the following capture file:https://www.wireshark.org/download/automated/captures/fuzz-2015-04-15-23757.pcapstderr:Input file: /home/wireshark/menagerie/menagerie/12570-TESTCYCL_46145_4GLOCL18.pcapBuild host information:Linux wsbb04 3.13.0-46-generic #79-Ubuntu SMP Tue Mar 10 20:06:50 UTC 2015 x86_64 x86_64 x86_64 GNU/LinuxDistributor ID: UbuntuDescription: Ubuntu 14.04.2 LTSRelease: 14.04Codename: trustyBuildbot information:BUILDBOT_REPOSITORY=ssh://wireshark-buildbot@code.wireshark.org:29418/wiresharkBUILDBOT_BUILDNUMBER=3204BUILDBOT_URL=http://buildbot.wireshark.org/trunk/BUILDBOT_BUILDERNAME=Clang Code AnalysisBUILDBOT_SLAVENAME=clang-code-analysisBUILDBOT_GOT_REVISION=b9ce255353c44c3cf6bc710304dc5fb8be0f45d9Return value: 0Dissector bug: 0Valgrind error count: 1Git commitcommit b9ce255353c44c3cf6bc710304dc5fb8be0f45d9Author: Michal Labedzki <michal.labedzki@tieto.com>Date: Tue Mar 24 19:37:05 2015 +0100 Bluetooth: OBEX: Update to PBAP 1.2, GOEP 2.1, CTN 1.0 and GPP 1.0 Add a lot of fields. Change-Id: If12a30b1840c0dbe934bc6af264a068935912832 Reviewed-on: https://code.wireshark.org/review/8043 Petri-Dish: Michal Labedzki <michal.labedzki@tieto.com> Tested-by: Petri Dish Buildbot <buildbot-no-reply@wireshark.org> Reviewed-by: Michal Labedzki <michal.labedzki@tieto.com>Command and args: ./tools/valgrind-wireshark.sh==31979== Memcheck, a memory error detector==31979== Copyright (C) 2002-2013, and GNU GPL'd, by Julian Seward et al.==31979== Using Valgrind-3.10.0.SVN and LibVEX; rerun with -h for copyright info==31979== Command: /home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/bin/tshark -nr /fuzz/buildbot/clangcodeanalysis/valgrind-fuzz/fuzz-2015-04-15-23757.pcap==31979====31979== Use of uninitialised value of size 8==31979== at 0x9F5C068: ??? (in /lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)==31979== by 0x6A26009: dissect_giop_common (packet-giop.c:4869)==31979== by 0x6E85AB7: tcp_dissect_pdus (packet-tcp.c:2477)==31979== by 0x6A249A5: dissect_giop_tcp (packet-giop.c:4984)==31979== by 0x6A247F0: dissect_giop_heur (packet-giop.c:5027)==31979== by 0x672E156: dissector_try_heuristic (packet.c:2041)==31979== by 0x6E85E34: decode_tcp_ports (packet-tcp.c:4141)==31979== by 0x6E86E19: process_tcp_payload (packet-tcp.c:4187)==31979== by 0x6E8636E: dissect_tcp_payload (packet-tcp.c:1997)==31979== by 0x6E89E70: dissect_tcp (packet-tcp.c:5075)==31979== by 0x672D12D: call_dissector_work (packet.c:614)==31979== by 0x672CFAE: dissector_try_uint_new (packet.c:1132)==31979====31979== Use of uninitialised value of size 8==31979== at 0x9F5BE9B: ??? (in /lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)==31979== by 0x9F5C106: ??? (in /lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)==31979== by 0x6A26009: dissect_giop_common (packet-giop.c:4869)==31979== by 0x6E85AB7: tcp_dissect_pdus (packet-tcp.c:2477)==31979== by 0x6A249A5: dissect_giop_tcp (packet-giop.c:4984)==31979== by 0x6A247F0: dissect_giop_heur (packet-giop.c:5027)==31979== by 0x672E156: dissector_try_heuristic (packet.c:2041)==31979== by 0x6E85E34: decode_tcp_ports (packet-tcp.c:4141)==31979== by 0x6E86E19: process_tcp_payload (packet-tcp.c:4187)==31979== by 0x6E8636E: dissect_tcp_payload (packet-tcp.c:1997)==31979== by 0x6E89E70: dissect_tcp (packet-tcp.c:5075)==31979== by 0x672D12D: call_dissector_work (packet.c:614)==31979====31979== Use of uninitialised value of size 8==31979== at 0x9F5BF38: ??? (in /lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)==31979== by 0x9F5C106: ??? (in /lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)==31979== by 0x6A26009: dissect_giop_common (packet-giop.c:4869)==31979== by 0x6E85AB7: tcp_dissect_pdus (packet-tcp.c:2477)==31979== by 0x6A249A5: dissect_giop_tcp (packet-giop.c:4984)==31979== by 0x6A247F0: dissect_giop_heur (packet-giop.c:5027)==31979== by 0x672E156: dissector_try_heuristic (packet.c:2041)==31979== by 0x6E85E34: decode_tcp_ports (packet-tcp.c:4141)==31979== by 0x6E86E19: process_tcp_payload (packet-tcp.c:4187)==31979== by 0x6E8636E: dissect_tcp_payload (packet-tcp.c:1997)==31979== by 0x6E89E70: dissect_tcp (packet-tcp.c:5075)==31979== by 0x672D12D: call_dissector_work (packet.c:614)==31979====31979== Use of uninitialised value of size 8==31979== at 0x9F5BF49: ??? (in /lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)==31979== by 0x9F5C106: ??? (in /lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)==31979== by 0x6A26009: dissect_giop_common (packet-giop.c:4869)==31979== by 0x6E85AB7: tcp_dissect_pdus (packet-tcp.c:2477)==31979== by 0x6A249A5: dissect_giop_tcp (packet-giop.c:4984)==31979== by 0x6A247F0: dissect_giop_heur (packet-giop.c:5027)==31979== by 0x672E156: dissector_try_heuristic (packet.c:2041)==31979== by 0x6E85E34: decode_tcp_ports (packet-tcp.c:4141)==31979== by 0x6E86E19: process_tcp_payload (packet-tcp.c:4187)==31979== by 0x6E8636E: dissect_tcp_payload (packet-tcp.c:1997)==31979== by 0x6E89E70: dissect_tcp (packet-tcp.c:5075)==31979== by 0x672D12D: call_dissector_work (packet.c:614)==31979====31979== Use of uninitialised value of size 8==31979== at 0x9F5BF5D: ??? (in /lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)==31979== by 0x9F5C106: ??? (in /lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)==31979== by 0x6A26009: dissect_giop_common (packet-giop.c:4869)==31979== by 0x6E85AB7: tcp_dissect_pdus (packet-tcp.c:2477)==31979== by 0x6A249A5: dissect_giop_tcp (packet-giop.c:4984)==31979== by 0x6A247F0: dissect_giop_heur (packet-giop.c:5027)==31979== by 0x672E156: dissector_try_heuristic (packet.c:2041)==31979== by 0x6E85E34: decode_tcp_ports (packet-tcp.c:4141)==31979== by 0x6E86E19: process_tcp_payload (packet-tcp.c:4187)==31979== by 0x6E8636E: dissect_tcp_payload (packet-tcp.c:1997)==31979== by 0x6E89E70: dissect_tcp (packet-tcp.c:5075)==31979== by 0x672D12D: call_dissector_work (packet.c:614)==31979====31979== Conditional jump or move depends on uninitialised value(s)==31979== at 0x9F5BF61: ??? (in /lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)==31979== by 0x9F5C106: ??? (in /lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)==31979== by 0x6A26009: dissect_giop_common (packet-giop.c:4869)==31979== by 0x6E85AB7: tcp_dissect_pdus (packet-tcp.c:2477)==31979== by 0x6A249A5: dissect_giop_tcp (packet-giop.c:4984)==31979== by 0x6A247F0: dissect_giop_heur (packet-giop.c:5027)==31979== by 0x672E156: dissector_try_heuristic (packet.c:2041)==31979== by 0x6E85E34: decode_tcp_ports (packet-tcp.c:4141)==31979== by 0x6E86E19: process_tcp_payload (packet-tcp.c:4187)==31979== by 0x6E8636E: dissect_tcp_payload (packet-tcp.c:1997)==31979== by 0x6E89E70: dissect_tcp (packet-tcp.c:5075)==31979== by 0x672D12D: call_dissector_work (packet.c:614)==31979====31979== Use of uninitialised value of size 8==31979== at 0x9F5BED9: ??? (in /lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)==31979== by 0x9F5C106: ??? (in /lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)==31979== by 0x6A26009: dissect_giop_common (packet-giop.c:4869)==31979== by 0x6E85AB7: tcp_dissect_pdus (packet-tcp.c:2477)==31979== by 0x6A249A5: dissect_giop_tcp (packet-giop.c:4984)==31979== by 0x6A247F0: dissect_giop_heur (packet-giop.c:5027)==31979== by 0x672E156: dissector_try_heuristic (packet.c:2041)==31979== by 0x6E85E34: decode_tcp_ports (packet-tcp.c:4141)==31979== by 0x6E86E19: process_tcp_payload (packet-tcp.c:4187)==31979== by 0x6E8636E: dissect_tcp_payload (packet-tcp.c:1997)==31979== by 0x6E89E70: dissect_tcp (packet-tcp.c:5075)==31979== by 0x672D12D: call_dissector_work (packet.c:614)==31979====31979== Conditional jump or move depends on uninitialised value(s)==31979== at 0x9F5C06D: ??? (in /lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)==31979== by 0x6A26009: dissect_giop_common (packet-giop.c:4869)==31979== by 0x6E85AB7: tcp_dissect_pdus (packet-tcp.c:2477)==31979== by 0x6A249A5: dissect_giop_tcp (packet-giop.c:4984)==31979== by 0x672D10F: call_dissector_work (packet.c:612)==31979== by 0x671DDFE: try_conversation_dissector (conversation.c:1312)==31979== by 0x6E85CE6: decode_tcp_ports (packet-tcp.c:4083)==31979== by 0x6E86E19: process_tcp_payload (packet-tcp.c:4187)==31979== by 0x6E8636E: dissect_tcp_payload (packet-tcp.c:1997)==31979== by 0x6E89E70: dissect_tcp (packet-tcp.c:5075)==31979== by 0x672D12D: call_dissector_work (packet.c:614)==31979== by 0x672CFAE: dissector_try_uint_new (packet.c:1132)==31979====31979== Conditional jump or move depends on uninitialised value(s)==31979== at 0x9F5C0A4: ??? (in /lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)==31979== by 0x6A26009: dissect_giop_common (packet-giop.c:4869)==31979== by 0x6E85AB7: tcp_dissect_pdus (packet-tcp.c:2477)==31979== by 0x6A249A5: dissect_giop_tcp (packet-giop.c:4984)==31979== by 0x672D10F: call_dissector_work (packet.c:612)==31979== by 0x671DDFE: try_conversation_dissector (conversation.c:1312)==31979== by 0x6E85CE6: decode_tcp_ports (packet-tcp.c:4083)==31979== by 0x6E86E19: process_tcp_payload (packet-tcp.c:4187)==31979== by 0x6E8636E: dissect_tcp_payload (packet-tcp.c:1997)==31979== by 0x6E89E70: dissect_tcp (packet-tcp.c:5075)==31979== by 0x672D12D: call_dissector_work (packet.c:614)==31979== by 0x672CFAE: dissector_try_uint_new (packet.c:1132)==31979====31979== Use of uninitialised value of size 8==31979== at 0x9F5C0AC: ??? (in /lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)==31979== by 0x6A26009: dissect_giop_common (packet-giop.c:4869)==31979== by 0x6E85AB7: tcp_dissect_pdus (packet-tcp.c:2477)==31979== by 0x6A249A5: dissect_giop_tcp (packet-giop.c:4984)==31979== by 0x672D10F: call_dissector_work (packet.c:612)==31979== by 0x671DDFE: try_conversation_dissector (conversation.c:1312)==31979== by 0x6E85CE6: decode_tcp_ports (packet-tcp.c:4083)==31979== by 0x6E86E19: process_tcp_payload (packet-tcp.c:4187)==31979== by 0x6E8636E: dissect_tcp_payload (packet-tcp.c:1997)==31979== by 0x6E89E70: dissect_tcp (packet-tcp.c:5075)==31979== by 0x672D12D: call_dissector_work (packet.c:614)==31979== by 0x672CFAE: dissector_try_uint_new (packet.c:1132)==31979====31979== Conditional jump or move depends on uninitialised value(s)==31979== at 0x9F5C0C2: ??? (in /lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)==31979== by 0x6A26009: dissect_giop_common (packet-giop.c:4869)==31979== by 0x6E85AB7: tcp_dissect_pdus (packet-tcp.c:2477)==31979== by 0x6A249A5: dissect_giop_tcp (packet-giop.c:4984)==31979== by 0x672D10F: call_dissector_work (packet.c:612)==31979== by 0x671DDFE: try_conversation_dissector (conversation.c:1312)==31979== by 0x6E85CE6: decode_tcp_ports (packet-tcp.c:4083)==31979== by 0x6E86E19: process_tcp_payload (packet-tcp.c:4187)==31979== by 0x6E8636E: dissect_tcp_payload (packet-tcp.c:1997)==31979== by 0x6E89E70: dissect_tcp (packet-tcp.c:5075)==31979== by 0x672D12D: call_dissector_work (packet.c:614)==31979== by 0x672CFAE: dissector_try_uint_new (packet.c:1132)==31979====31979== Conditional jump or move depends on uninitialised value(s)==31979== at 0x9F5BEAD: ??? (in /lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)==31979== by 0x9F5C106: ??? (in /lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)==31979== by 0x6A26009: dissect_giop_common (packet-giop.c:4869)==31979== by 0x6E85AB7: tcp_dissect_pdus (packet-tcp.c:2477)==31979== by 0x6A249A5: dissect_giop_tcp (packet-giop.c:4984)==31979== by 0x672D10F: call_dissector_work (packet.c:612)==31979== by 0x671DDFE: try_conversation_dissector (conversation.c:1312)==31979== by 0x6E85CE6: decode_tcp_ports (packet-tcp.c:4083)==31979== by 0x6E86E19: process_tcp_payload (packet-tcp.c:4187)==31979== by 0x6E8636E: dissect_tcp_payload (packet-tcp.c:1997)==31979== by 0x6E89E70: dissect_tcp (packet-tcp.c:5075)==31979== by 0x672D12D: call_dissector_work (packet.c:614)==31979====31979== Use of uninitialised value of size 8==31979== at 0x9F5BEC2: ??? (in /lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)==31979== by 0x9F5C106: ??? (in /lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)==31979== by 0x6A26009: dissect_giop_common (packet-giop.c:4869)==31979== by 0x6E85AB7: tcp_dissect_pdus (packet-tcp.c:2477)==31979== by 0x6A249A5: dissect_giop_tcp (packet-giop.c:4984)==31979== by 0x672D10F: call_dissector_work (packet.c:612)==31979== by 0x671DDFE: try_conversation_dissector (conversation.c:1312)==31979== by 0x6E85CE6: decode_tcp_ports (packet-tcp.c:4083)==31979== by 0x6E86E19: process_tcp_payload (packet-tcp.c:4187)==31979== by 0x6E8636E: dissect_tcp_payload (packet-tcp.c:1997)==31979== by 0x6E89E70: dissect_tcp (packet-tcp.c:5075)==31979== by 0x672D12D: call_dissector_work (packet.c:614)==31979====31979== Conditional jump or move depends on uninitialised value(s)==31979== at 0x9F5BEDD: ??? (in /lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)==31979== by 0x9F5C106: ??? (in /lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)==31979== by 0x6A26009: dissect_giop_common (packet-giop.c:4869)==31979== by 0x6E85AB7: tcp_dissect_pdus (packet-tcp.c:2477)==31979== by 0x6A249A5: dissect_giop_tcp (packet-giop.c:4984)==31979== by 0x672D10F: call_dissector_work (packet.c:612)==31979== by 0x671DDFE: try_conversation_dissector (conversation.c:1312)==31979== by 0x6E85CE6: decode_tcp_ports (packet-tcp.c:4083)==31979== by 0x6E86E19: process_tcp_payload (packet-tcp.c:4187)==31979== by 0x6E8636E: dissect_tcp_payload (packet-tcp.c:1997)==31979== by 0x6E89E70: dissect_tcp (packet-tcp.c:5075)==31979== by 0x672D12D: call_dissector_work (packet.c:614)==31979====31979====31979== HEAP SUMMARY:==31979== in use at exit: 1,292,501 bytes in 31,437 blocks==31979== total heap usage: 1,343,499 allocs, 1,312,062 frees, 77,928,045 bytes allocated==31979====31979== LEAK SUMMARY:==31979== definitely lost: 8,504 bytes in 606 blocks==31979== indirectly lost: 98,616 bytes in 1,064 blocks==31979== possibly lost: 0 bytes in 0 blocks==31979== still reachable: 1,185,381 bytes in 29,767 blocks==31979== suppressed: 0 bytes in 0 blocks==31979== Rerun with --leak-check=full to see details of leaked memory==31979====31979== For counts of detected and suppressed errors, rerun with: -v==31979== Use --track-origins=yes to see where uninitialised values come from==31979== ERROR SUMMARY: 4684 errors from 14 contexts (suppressed: 1 from 1)[ no debug trace ]
Line 4869 is g_hash_table_insert(giop_info->optypes, GUINT_TO_POINTER(header.req_id), GUINT_TO_POINTER((guint)header.message_type));and it's probably either header.req_id or header.message_type that's not initialized.This is probably a bug introduced by I10ca51f745710dca3b57a03cc89126f7b1dc06b4, which adds support for reassembly of GIOP fragments.