Boost logo

Boost :

Subject: [boost] fuzzing boost at OSS-Fuzz
From: Kostya Serebryany (kcc_at_[hidden])
Date: 2017-09-27 03:51:53


I would like to invite boost developers to use OSS-Fuzz, a continuous
automated fuzzing service.

I've made the initial set up that fuzzes boost::regex and it found 8 bugs
there, see

3460 boost: Integer-overflow in
3464 boost: Integer-overflow in boost::re_detail_NUMBER::perl_matcher...
3469 boost: ASSERT: jmp->type == syntax_element_jump
3471 boost: Stack-overflow in boost::re_detail_NUMBER::basic_regex_parser...
3472 boost: Stack-overflow in boost::re_detail_NUMBER::perl_matcher…
3478 boost: Stack-buffer-overflow in
3479 boost: Null-dereference READ in boost::re_detail_NUMBER::basic_regex...

Vinnie Falco pointed me to Jens Weller's blog post about fuzzing beast: .
Jens used libFuzzer, which is one of the two fuzzing engines used by
Adding a boost library to OSS-Fuzz will look very similar to this blog

For those of you who are at CppCon this week: we can discuss this face to


Boost list run by bdawes at, gregod at, cpdaniel at, john at