Fuzz introspector: fuzzer-kexecdh
For issues and ideas: https://github.com/ossf/fuzz-introspector/issues

Fuzz blockers

The followings are the branches where fuzzer fails to bypass.

Unique non-covered Complexity Unique Reachable Complexities Unique Reachable Functions All non-covered Complexity All Reachable Complexity Function Name Function Callsite Blocked Branch
156 156 1 :

['buf_put_dss_pub_key']

331 429 buf_put_pub_key call site: 00259 /src/dropbear/src/signkey.c:427
156 156 1 :

['buf_put_rsa_pub_key']

175 273 buf_put_pub_key call site: 00260 /src/dropbear/src/signkey.c:432
69 87 4 :

['buf_setpos', 'buf_new', 'buf_readfile', 'stat']

144 184 svr_getopts call site: 00000 /src/dropbear/src/svr-runopts.c:375
21 21 1 :

['parse_recv_window']

73 87 svr_getopts call site: 00000 /src/dropbear/src/svr-runopts.c:407
20 29 2 :

['m_mp_free_multi', 'm_free_direct']

20 29 dss_key_free call site: 00000 /src/dropbear/src/dss.c:125
20 29 2 :

['m_mp_free_multi', 'm_free_direct']

20 29 rsa_key_free call site: 00000 /src/dropbear/src/rsa.c:146
20 20 1 :

['m_mp_free_multi']

20 20 buf_get_dss_priv_key call site: 00000 /src/dropbear/src/dss.c:113
20 20 1 :

['m_mp_free_multi']

20 20 buf_get_rsa_priv_key call site: 00000 /src/dropbear/src/rsa.c:133
19 19 1 :

['buf_put_ed25519_pub_key']

19 49 buf_put_pub_key call site: 00293 /src/dropbear/src/signkey.c:445
15 27 5 :

['m_malloc', 'fuzz_getpwuid', 'getuid', 'strlen', 'getenv']

15 43 expand_homedir_path call site: 00000 /src/dropbear/src/dbutil.c:640
13 13 1 :

['m_str_to_uint']

13 19 svr_getopts call site: 00000 /src/dropbear/src/svr-runopts.c:441
2 2 1 :

['getgrnam']

75 91 svr_getopts call site: 00000 /src/dropbear/src/svr-runopts.c:396

Fuzzer calltree

0 LLVMFuzzerTestOneInput [function] [call site] 00000
1 fuzz_set_input [function] [call site] 00001
2 wrapfd_setup [function] [call site] 00002
3 wrapfd_remove [function] [call site] 00003
4 __assert_fail [call site] 00004
4 __assert_fail [call site] 00005
4 __assert_fail [call site] 00006
4 close [call site] 00007
3 wrapfd_setseed [function] [call site] 00008
4 nrand48 [call site] 00009
2 fuzz_seed [function] [call site] 00010
3 sha256_init [function] [call site] 00011
4 crypt_argchk [function] [call site] 00012
5 fprintf [call site] 00013
5 abort [call site] 00014
3 sha256_process [function] [call site] 00015
4 crypt_argchk [function] [call site] 00016
4 sha256_compress [function] [call site] 00017
3 sha256_process [function] [call site] 00018
3 sha256_done [function] [call site] 00019
4 crypt_argchk [function] [call site] 00020
4 crypt_argchk [function] [call site] 00021
4 sha256_compress [function] [call site] 00022
4 sha256_compress [function] [call site] 00023
1 m_malloc_set_epoch [function] [call site] 00024
1 _setjmp [call site] 00025
1 buf_getbyte [function] [call site] 00026
2 dropbear_exit [function] [call site] 00027
1 buf_getint [function] [call site] 00028
2 buf_getptr [function] [call site] 00029
3 dropbear_exit [function] [call site] 00030
2 buf_incrpos [function] [call site] 00031
3 dropbear_exit [function] [call site] 00032
1 buf_getstringbuf [function] [call site] 00033
2 buf_getstringbuf_int [function] [call site] 00034
3 buf_getint [function] [call site] 00035
3 dropbear_exit [function] [call site] 00036
3 buf_new [function] [call site] 00037
4 dropbear_exit [function] [call site] 00038
4 m_malloc [function] [call site] 00039
5 dropbear_exit [function] [call site] 00040
5 calloc [call site] 00041
5 dropbear_exit [function] [call site] 00042
5 put_alloc [function] [call site] 00043
6 __assert_fail [call site] 00044
6 __assert_fail [call site] 00045
3 buf_putint [function] [call site] 00046
4 buf_getwriteptr [function] [call site] 00047
5 dropbear_exit [function] [call site] 00048
4 buf_incrwritepos [function] [call site] 00049
5 dropbear_exit [function] [call site] 00050
3 buf_getwriteptr [function] [call site] 00051
3 buf_incrpos [function] [call site] 00052
3 buf_incrlen [function] [call site] 00053
4 dropbear_exit [function] [call site] 00054
3 buf_setpos [function] [call site] 00055
4 dropbear_exit [function] [call site] 00056
1 kexecdh_comb_key [function] [call site] 00058
2 buf_get_ecc_raw_pubkey [function] [call site] 00059
3 buf_setpos [function] [call site] 00060
3 buf_getbyte [function] [call site] 00061
3 dropbear_log [function] [call site] 00062
3 new_ecc_key [function] [call site] 00063
4 m_mp_alloc_init_multi [function] [call site] 00065
5 dropbear_exit [function] [call site] 00071
3 buf_getptr [function] [call site] 00072
3 mp_from_ubin [function] [call site] 00073
3 buf_incrpos [function] [call site] 00091
3 buf_getptr [function] [call site] 00092
3 mp_from_ubin [function] [call site] 00093
3 buf_incrpos [function] [call site] 00094
3 ecc_is_point [function] [call site] 00096
4 m_mp_alloc_init_multi [function] [call site] 00097
4 mp_read_radix [function] [call site] 00113
4 mp_mod [function] [call site] 00125
5 mp_init_size [function] [call site] 00126
5 mp_div [function] [call site] 00127
6 mp_cmp_mag [function] [call site] 00128
6 mp_init_size [function] [call site] 00131
6 mp_init_copy [function] [call site] 00134
6 mp_init_copy [function] [call site] 00138
6 mp_count_bits [function] [call site] 00139
6 mp_mul_2d [function] [call site] 00140
6 mp_mul_2d [function] [call site] 00141
6 mp_cmp_mag [function] [call site] 00158
4 mp_clear_multi [function] [call site] 00225
4 m_free_direct [function] [call site] 00226
5 get_header [function] [call site] 00227
5 remove_alloc [function] [call site] 00228
4 m_free_direct [function] [call site] 00229
4 m_free_direct [function] [call site] 00230
4 m_free_direct [function] [call site] 00231
3 ecc_free [function] [call site] 00234
4 crypt_argchk [function] [call site] 00235
4 ltc_deinit_multi [function] [call site] 00236
3 m_free_direct [function] [call site] 00237
2 dropbear_exit [function] [call site] 00238
2 dropbear_ecc_shared_secret [function] [call site] 00239
3 ltc_ecc_new_point [function] [call site] 00240
4 ltc_init_multi [function] [call site] 00242
4 m_free_direct [function] [call site] 00243
3 m_mp_init [function] [call site] 00245
4 dropbear_exit [function] [call site] 00247
3 mp_read_radix [function] [call site] 00248
3 m_mp_init [function] [call site] 00250
3 m_free_direct [function] [call site] 00253
3 ltc_ecc_del_point [function] [call site] 00254
4 ltc_deinit_multi [function] [call site] 00255
4 m_free_direct [function] [call site] 00256
3 dropbear_exit [function] [call site] 00257
2 buf_put_pub_key [function] [call site] 00258
3 buf_put_dss_pub_key [function] [call site] 00260
4 fail_assert [function] [call site] 00261
5 dropbear_exit [function] [call site] 00262
4 buf_putstring [function] [call site] 00263
5 buf_putint [function] [call site] 00264
5 buf_putbytes [function] [call site] 00265
6 buf_getwriteptr [function] [call site] 00266
6 buf_incrwritepos [function] [call site] 00267
4 buf_putmpint [function] [call site] 00268
5 fail_assert [function] [call site] 00269
5 dropbear_exit [function] [call site] 00270
5 mp_count_bits [function] [call site] 00271
5 buf_putint [function] [call site] 00272
5 buf_putbyte [function] [call site] 00273
6 buf_incrlen [function] [call site] 00274
5 buf_getwriteptr [function] [call site] 00275
5 mp_to_ubin [function] [call site] 00276
6 mp_ubin_size [function] [call site] 00277
7 mp_count_bits [function] [call site] 00278
6 mp_init_copy [function] [call site] 00279
6 mp_div_2d [function] [call site] 00280
5 dropbear_exit [function] [call site] 00282
5 buf_incrwritepos [function] [call site] 00283
4 buf_putmpint [function] [call site] 00284
4 buf_putmpint [function] [call site] 00285
4 buf_putmpint [function] [call site] 00286
3 buf_put_rsa_pub_key [function] [call site] 00287
4 buf_putstring [function] [call site] 00288
4 buf_putmpint [function] [call site] 00289
4 buf_putmpint [function] [call site] 00290
3 signkey_is_ecdsa [function] [call site] 00291
3 signkey_key_ptr [function] [call site] 00292
3 buf_put_ecdsa_pub_key [function] [call site] 00293
4 curve_for_dp [function] [call site] 00294
5 __assert_fail [call site] 00295
4 snprintf [call site] 00296
4 strlen [call site] 00297
4 buf_putstring [function] [call site] 00298
4 strlen [call site] 00299
4 buf_putstring [function] [call site] 00300
4 buf_put_ecc_raw_pubkey_string [function] [call site] 00301
5 buf_putint [function] [call site] 00302
5 buf_getwriteptr [function] [call site] 00303
5 ecc_ansi_x963_export [function] [call site] 00304
6 crypt_argchk [function] [call site] 00305
6 crypt_argchk [function] [call site] 00306
6 ltc_ecc_is_valid_idx [function] [call site] 00307
6 crypt_argchk [function] [call site] 00308
6 zeromem [function] [call site] 00309
7 m_burn [function] [call site] 00310
8 explicit_bzero [call site] 00311
5 dropbear_exit [function] [call site] 00313
5 buf_incrwritepos [function] [call site] 00314
3 buf_put_ed25519_pub_key [function] [call site] 00315
4 fail_assert [function] [call site] 00316
4 buf_putstring [function] [call site] 00317
4 buf_putstring [function] [call site] 00318
3 dropbear_exit [function] [call site] 00319
3 buf_putbufstring [function] [call site] 00320
4 buf_putstring [function] [call site] 00321
3 buf_free [function] [call site] 00322
4 m_free_direct [function] [call site] 00323
2 buf_put_ecc_raw_pubkey_string [function] [call site] 00324
2 buf_put_ecc_raw_pubkey_string [function] [call site] 00325
2 buf_putmpint [function] [call site] 00326
2 m_free_direct [function] [call site] 00328
2 finish_kexhashbuf [function] [call site] 00329
3 buf_setpos [function] [call site] 00330
3 buf_getptr [function] [call site] 00331
3 buf_getwriteptr [function] [call site] 00333
3 buf_setlen [function] [call site] 00334
4 dropbear_exit [function] [call site] 00335
3 buf_burn_free [function] [call site] 00336
4 m_free_direct [function] [call site] 00338
1 m_free_direct [function] [call site] 00342
1 m_malloc_free_epoch [function] [call site] 00346
2 put_alloc [function] [call site] 00347