Uploaded image for project: 'Core ReactOS'
  1. Core ReactOS
  2. CORE-18124

Fuzzing NtUserGetAsyncKeyState with ROCALL causes BSoD

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Major
    • 0.4.15
    • Win32SS

    Description

      ReactOS 0.4.15-x86-dev (Build 20220320-755631e). Debug log exceeds max size, here's the trace:

       Entered debugger on last-chance exception (Exception Code: 0xc0000005) (Page Fault)
      Memory at 0xD95BEEC0 could not be accessed
      kdb:> bt
      Eip:
      <win32k.sys:4bd0a (win32ss/user/ntuser/keyboard.c:647 (NtUserGetAsyncKeyState))>
      Frames:
      <ntoskrnl.exe:3fe5 (:0 (KiSystemCallTrampoline))>
      <ntoskrnl.exe:14e739 (ntoskrnl/ke/i386/traphdlr.c:1840 (KiSystemServiceHandler))>
      <ntoskrnl.exe:3e2f (:0 (KiFastCallEntry))>
      <ntdll.dll:10181>
      <ROCALL_checked.exe:1203>
      <kernel32.dll:1c97b>
      kdb:> cont*** Fatal System Error: 0x0000001e
                             (0xC0000005,0xF94B2D0A,0xF8E52C74,0x00000000)
      Entered debugger on embedded INT3 at 0x0008:0x8058B77B.
      kdb:> bt
      Eip:
      <ntoskrnl.exe:18b77c (home/runner/work/reactos/reactos/build/../src/sdk/lib/rtl/i386/debug_asm.S:56 (RtlpBreakWithStatusInstruction))>
      Frames:
      <ntoskrnl.exe:8c329 (ntoskrnl/ke/bug.c:1066 (KeBugCheckWithTf))>
      <ntoskrnl.exe:8c893 (ntoskrnl/ke/bug.c:1413 (KeBugCheckEx))>
      <ntoskrnl.exe:1487f0 (ntoskrnl/ke/i386/exp.c:888 (KiDispatchException))>
      <ntoskrnl.exe:148c1e (ntoskrnl/ke/i386/exp.c:1081 (KiDispatchExceptionFromTrapFrame))>
      <ntoskrnl.exe:14da65 (ntoskrnl/include/internal/i386/ke.h:759 (KiTrap0EHandler))>
      <ntoskrnl.exe:36ae (:0 (KiTrap0E))>
      <win32k.sys:4bd05 (win32ss/user/ntuser/keyboard.c:647 (NtUserGetAsyncKeyState))>
      <ntoskrnl.exe:3fe5 (:0 (KiSystemCallTrampoline))>
      <ntoskrnl.exe:14e739 (ntoskrnl/ke/i386/traphdlr.c:1840 (KiSystemServiceHandler))>
      <ntoskrnl.exe:3e2f (:0 (KiFastCallEntry))>
      <ntdll.dll:10181>
      <ROCALL_checked.exe:1203>
      <kernel32.dll:1c97b>
      kdb:> 

      Attachments

        Activity

          People

            ThFabba ThFabba
            ctasan ctasan
            Votes:
            1 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: