ABCDEFGHIJKLMNOPQRSTUVWXYZ
1
Ada Logics OSS-Fuzz integrations
2
https://adalogics.com
3
4
Abstract
5
This sheet is an overview of our work with OSS-Fuzz and fuzzing open source projects. The data we show in this sheet is all public and the search queries below identify how you can get the data yourself. You can find a link below on a blog post detailing our efforts.
6
7
Links
8
Blog post discussing this data: https://adalogics.com/blog/fuzzing-100-open-source-projects-with-oss-fuzz
9
OSS-Fuzz Github repository https://github.com/google/oss-fuzz
10
How OSS-Fuzz fits into the grand scheme of things in open source security: https://security.googleblog.com/2021/08/updates-on-our-continued-collaboration.html
11
Ada Logics fuzz training: https://adalogics.com/training-source-fuzz
12
Ada logics LLVM for security engineering training: https://adalogics.com/training-llvm-for-security
13
14
Queries used for searching
15
In the below queries please substitute "PROJ_NAME" with the project you are interested in.
16
Query for bugshttps://bugs.chromium.org/p/oss-fuzz/issues/list?q=PROJ_NAME%20Type%3DBug&can=1
17
Query for security bugshttps://bugs.chromium.org/p/oss-fuzz/issues/list?q=PROJ_NAME%20Type%3DBug-Security&can=1
18
Query for bugs + reproduciblehttps://bugs.chromium.org/p/oss-fuzz/issues/list?q=PROJ_NAME%20Type%3DBug%20label%3AReproducible&can=1
19
Query for security bugs + reproduciblehttps://bugs.chromium.org/p/oss-fuzz/issues/list?q=PROJ_NAME%20Type%3DBug-Security%20label%3AReproducible&can=1
20
Query for bugs + verifiedhttps://bugs.chromium.org/p/oss-fuzz/issues/list?q=PROJ_NAME%20Type%3DBug%20verified&can=1
21
Query for security bugs + verifiedhttps://bugs.chromium.org/p/oss-fuzz/issues/list?q=PROJ_NAME%20Type%3DBug-Security%20verified&can=1
22
23
Overall stats
24
The data we use in this sheet is based purely on the data in Monorail. In particular, there may be some false positives included in the data for example bugs that are due to fuzzers being coded up wrongly (and later fixed) etc.
25
Bugs on Monorail1545
26
Security bugs on Monorail559
27
Total issues2104
28
Bugs verified (fixed)1038
29
Security bugs verified (fixed)292
30
Total issues verified1330
31
Bugs that are either not fixed, declared WontFix or false positives:774
32
33
34
Project specsMonorail public stats
35
Project nameGithub URLLanguageBugsSecurity BugsBugs verified (fixed)Security bugs verified (fixed)
36
apache-httpd112112
37
blackfriday1010
38
caddy8210
39
cascadia51110
40
cctz1000
41
cfengine2000
42
cilium0500
43
Civetweb1010
44
Clib11040
45
containerd3310
46
dgraph3310
47
dnsmasq1201
48
dovecot13393
49
dragonfly3700
50
duckdb9271
51
fastjson2400
52
flatbuffers3010296
53
flate2-rs0000
54
fluent-bit1155210044
55
gitea224170
56
go-ethereum149100
57
go-redis5200
58
gpac3012132
59
grpc-gateway5500
60
h30101
61
haproxy112102
62
Hiredis11270
63
httlib22100
64
httparse0000
65
hugo2010
66
hyperium5050
67
igraph84
68
image-png3030
69
imageio12710
70
istio19690
71
janet3020
72
json5format7000
73
jsoncons553473
74
jsonparser6240
75
jsonschema0000
76
juju3200
77
kamailio2020
78
kOps0000
79
Leptonica66455831
80
levelDB5020
81
libiec618507272
82
libigl0000
83
liblouis0000
84
libpg_query6211
85
libphonenumber0000
86
librdkafka8652
87
libredwg53393426
88
libucl8622143
89
libyang44314030
90
lighttpd0000
91
linkerd2-proxy130130
92
llhttp0000
93
loki2310
94
lotus4500
95
Lua8836
96
md4c6310
97
meshoptimizer2020
98
minify3811340
99
Mongoose5151
100
muduo0000