Skip to content

Conversation

Marcono1234
Copy link
Contributor

That vulnerability was found through manual code review, and usage of Jazzer in combination with https://github.com/Marcono1234/unsafe-address-sanitizer

@simonresch simonresch self-requested a review September 19, 2025 07:18
Copy link
Contributor

@simonresch simonresch left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Very good find! Thanks for linking it here.

Your unsafe-address-sanitizer looks like a powerful addition to a Jazzer fuzz test.

@simonresch simonresch merged commit 036bf8d into CodeIntelligenceTesting:main Sep 19, 2025
8 checks passed
@Marcono1234 Marcono1234 deleted the aircompressor-findings branch September 21, 2025 11:41
@Marcono1234
Copy link
Contributor Author

Marcono1234 commented Sep 21, 2025

Your unsafe-address-sanitizer looks like a powerful addition to a Jazzer fuzz test.

Thanks for the kind words! Also, since the latest version Jazzer itself supports sanitizing array access through Unsafe (#932).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants