Fuzz introspector: asn1_decode_simple_ber_fuzzer
For issues and ideas: https://github.com/ossf/fuzz-introspector/issues

Fuzz blockers

The followings are the branches where fuzzer fails to bypass.

Unique non-covered Complexity Unique Reachable Complexities Unique Reachable Functions All non-covered Complexity All Reachable Complexity Function Name Function Callsite Blocked Branch
104 104 1 :

['_asn1_get_indefinite_length_string']

104 104 asn1_get_length_ber call site: 00009 /src/libtasn1/lib/decoding.c:257
0 0 None 0 0 _asn1_decode_simple_der call site: 00016 /src/libtasn1/lib/decoding.c:2126
0 0 None 0 0 _asn1_decode_simple_der call site: 00016 /src/libtasn1/lib/decoding.c:2134
0 0 None 0 0 _asn1_decode_simple_der call site: 00017 /src/libtasn1/lib/decoding.c:2142
0 0 None 0 0 _asn1_decode_simple_der call site: 00017 /src/libtasn1/lib/decoding.c:2145
0 0 None 0 0 _asn1_decode_simple_ber call site: 00002 /src/libtasn1/lib/decoding.c:2252
0 0 None 0 0 _asn1_decode_simple_ber call site: 00002 /src/libtasn1/lib/decoding.c:2260
0 0 None 0 0 _asn1_decode_simple_ber call site: 00004 /src/libtasn1/lib/decoding.c:2342
0 0 None 0 0 _asn1_decode_simple_ber call site: 00004 /src/libtasn1/lib/decoding.c:2420
0 0 1 :

['free']

0 0 _asn1_decode_simple_ber call site: 00004 /src/libtasn1/lib/decoding.c:2456
0 0 None 0 0 append call site: 00006 /src/libtasn1/lib/decoding.c:2202
0 0 None 0 0 _asn1_realloc call site: 00006 /src/libtasn1/lib/./int.h:210

Fuzzer calltree

0 LLVMFuzzerTestOneInput [function] [call site] 00000
1 asn1_decode_simple_ber [function] [call site] 00001
2 _asn1_decode_simple_ber [function] [call site] 00002
3 asn1_get_tag_der [function] [call site] 00003
3 _asn1_decode_simple_ber [function] [call site] 00004
4 append [function] [call site] 00005
5 _asn1_realloc [function] [call site] 00006
6 realloc [call site] 00007
4 asn1_get_length_ber [function] [call site] 00008
5 asn1_get_length_der [function] [call site] 00009
5 _asn1_get_indefinite_length_string [function] [call site] 00010
6 asn1_get_tag_der [function] [call site] 00011
6 asn1_get_length_der [function] [call site] 00012
4 _asn1_decode_simple_ber [function] [call site] 00013
5 asn1_get_length_der [function] [call site] 00015
5 _asn1_decode_simple_der [function] [call site] 00016
6 asn1_get_tag_der [function] [call site] 00017
6 asn1_get_length_der [function] [call site] 00018
1 __assert_fail [call site] 00020
1 asn1_decode_simple_ber [function] [call site] 00021
1 __assert_fail [call site] 00022