diff --git a/rawDump/test_sgxsqlite b/rawDump/test_sgxsqlite new file mode 100644 index 000000000..d182918f1 --- /dev/null +++ b/rawDump/test_sgxsqlite @@ -0,0 +1,839 @@ +Test Case SGX_SQLite (time used: 52m58.083s, machine Intel Xeon E3-1275 with 64GB memory): + +[EMULATION] attempted sequence: ('ecall_opendb', 'ecall_execute_sql', 'ecall_closedb', 'ecall_opendb', 'ecall_execute_sql', 'ecall_closedb') +[LIMITATION] number of seeds attempted exceed ... +[EMULATION] attempted sequence: ('ecall_opendb', 'ecall_execute_sql', 'ecall_closedb', 'ecall_opendb', 'ecall_closedb', 'ecall_execute_sql') +[UAF-REPORT] Potential Use-after-free (UAF) at 0x6118c: mov ecx, dword ptr [rax + 0x64] +Try to use memory at 0x30000e7a - 0x30000e7d +Allocated memory range is 0x30000e0e - 0x300010b6 +Allocated memory at 0x14d14 and Freed at 0x14d89 + +Recent 200 emulated instructions: +0xd340: mov qword ptr [rdx + rcx*8], r8 +0xd344: pop rbp +0xd345: ret +0xd2e0: mov edi, 9 +0xd2e5: mov esi, 1 +0xd2ea: call 0xd320 +0xd320: push rbp +0xd321: mov rbp, rsp +0xd324: mov dword ptr [rbp - 4], edi +0xd327: mov dword ptr [rbp - 8], esi +0xd32a: movsxd rax, dword ptr [rbp - 8] +0xd32e: movsxd rcx, dword ptr [rbp - 4] +0xd332: lea rdx, qword ptr [rip + 0x30c9af] +0xd339: mov r8, qword ptr [rdx + rcx*8] +0xd33d: sub r8, rax +0xd340: mov qword ptr [rdx + rcx*8], r8 +0xd344: pop rbp +0xd345: ret +0xd2ef: mov rcx, qword ptr [rip + 0x309d5a] +0xd2f6: mov rdi, qword ptr [rbp - 8] +0xd2fa: call rcx +0x14d60: push rbp +0x14d61: mov rbp, rsp +0x14d64: sub rsp, 0x10 +0x14d68: mov qword ptr [rbp - 8], rdi +0x14d6c: mov rax, qword ptr [rbp - 8] +0x14d70: mov qword ptr [rbp - 0x10], rax +0x14d74: mov rax, qword ptr [rbp - 0x10] +0x14d78: add rax, -8 +0x14d7e: mov qword ptr [rbp - 0x10], rax +0x14d82: mov rax, qword ptr [rbp - 0x10] +0x14d86: mov rdi, rax +0x14d89: call 0xbc967 +0x14d8e: add rsp, 0x10 +0x14d92: pop rbp +0x14d93: ret +0xd2fc: jmp 0xd30b +0xd30b: add rsp, 0x10 +0xd30f: pop rbp +0xd310: ret +0x31b9e: add rsp, 0x40 +0x31ba2: pop rbp +0x31ba3: ret +0x31637: mov dword ptr [rbp - 4], 0 +0x3163e: mov eax, dword ptr [rbp - 4] +0x31641: add rsp, 0x30 +0x31645: pop rbp +0x31646: ret +0x1e0f7: add rsp, 0x10 +0x1e0fb: pop rbp +0x1e0fc: ret +0x9e14: lea rdi, qword ptr [rip + 0xe66dd] +0x9e1b: mov dword ptr [rbp - 4], eax +0x9e1e: call 0x7060 +0x7060: push rbp +0x7061: mov rbp, rsp +0x7064: sub rsp, 0x50 +0x7068: mov qword ptr [rbp - 0x10], rdi +0x706c: mov dword ptr [rbp - 0x14], 0 +0x7073: cmp qword ptr [rbp - 0x10], 0 +0x7078: je 0x708f +0x707a: mov rdi, qword ptr [rbp - 0x10] +0x707e: call 0xbfce7 +0xbfce7: push rbp +0xbfce8: mov rbp, rsp +0xbfceb: sub rsp, 0x10 +0xbfcef: mov qword ptr [rbp - 8], rdi +0xbfcf3: mov rax, qword ptr [rbp - 8] +0xbfcf7: mov rdi, rax +0xbfcfa: call 0xce800 +0xce800: push rsi +0xce801: mov rdx, rdi +0xce804: mov rcx, rdx +0xce807: and rdx, 0xfffffffffffffff0 +0xce80b: pxor xmm0, xmm0 +0xce80f: pcmpeqb xmm0, xmmword ptr [rdx] +0xce813: pmovmskb eax, xmm0 +0xce817: and ecx, 0xf +0xce81a: shr eax, cl +0xce81c: bsf eax, eax +0xce81f: jne 0xce82c +0xce821: mov rax, rdx +0xce824: add rdx, rcx +0xce827: call 0xcee20 +0xcee20: pxor xmm0, xmm0 +0xcee24: add rax, 0x10 +0xcee28: movdqa xmm1, xmmword ptr [rax] +0xcee2c: pcmpeqb xmm1, xmm0 +0xcee30: pmovmskb ecx, xmm1 +0xcee34: test ecx, ecx +0xcee36: je 0xcee24 +0xcee24: add rax, 0x10 +0xcee28: movdqa xmm1, xmmword ptr [rax] +0xcee2c: pcmpeqb xmm1, xmm0 +0xcee30: pmovmskb ecx, xmm1 +0xcee34: test ecx, ecx +0xcee36: je 0xcee24 +0xcee38: bsf ecx, ecx +0xcee3b: sub rcx, rdx +0xcee3e: add rax, rcx +0xcee41: ret +0xce82c: pop rcx +0xce82d: ret +0xbfcff: leave +0xbfd00: ret +0x7083: add rax, 1 +0x7089: mov qword ptr [rbp - 0x40], rax +0x708d: jmp 0x7099 +0x7099: mov rax, qword ptr [rbp - 0x40] +0x709d: mov qword ptr [rbp - 0x20], rax +0x70a1: mov qword ptr [rbp - 0x28], 0 +0x70a9: mov qword ptr [rbp - 0x30], 8 +0x70b1: mov qword ptr [rbp - 0x38], 0 +0x70b9: cmp qword ptr [rbp - 0x10], 0 +0x70be: je 0x70de +0x70c0: mov rdi, qword ptr [rbp - 0x10] +0x70c4: mov rsi, qword ptr [rbp - 0x20] +0x70c8: call 0xb34d7 +0xb34d7: push rbp +0xb34d8: mov rbp, rsp +0xb34db: mov qword ptr [rbp - 0x28], rdi +0xb34df: mov qword ptr [rbp - 0x30], rsi +0xb34e3: mov rax, qword ptr [rbp - 0x28] +0xb34e7: mov qword ptr [rbp - 0x18], rax +0xb34eb: mov qword ptr [rbp - 0x20], 0 +0xb34f3: lea rax, qword ptr [rip - 0xb34fa] +0xb34fa: mov qword ptr [rbp - 0x10], rax +0xb34fe: mov rdx, qword ptr [rip + 0x265f7b] +0xb3505: mov rax, qword ptr [rbp - 0x10] +0xb3509: add rax, rdx +0xb350c: sub rax, 1 +0xb3510: mov qword ptr [rbp - 8], rax +0xb3514: cmp qword ptr [rbp - 0x30], 0 +0xb3519: je 0xb3530 +0xb351b: mov rdx, qword ptr [rbp - 0x18] +0xb351f: mov rax, qword ptr [rbp - 0x30] +0xb3523: add rax, rdx +0xb3526: sub rax, 1 +0xb352a: mov qword ptr [rbp - 0x20], rax +0xb352e: jmp 0xb3538 +0xb3538: mov rax, qword ptr [rbp - 0x18] +0xb353c: cmp rax, qword ptr [rbp - 0x20] +0xb3540: ja 0xb355d +0xb3542: mov rax, qword ptr [rbp - 0x18] +0xb3546: cmp rax, qword ptr [rbp - 0x10] +0xb354a: jb 0xb355d +0xb354c: mov rax, qword ptr [rbp - 0x20] +0xb3550: cmp rax, qword ptr [rbp - 8] +0xb3554: ja 0xb355d +0xb355d: mov eax, 0 +0xb3562: pop rbp +0xb3563: ret +0x70cd: cmp eax, 0 +0x70d0: jne 0x70de +0x70d2: mov dword ptr [rbp - 4], 2 +0x70d9: jmp 0x71d6 +0x71d6: mov eax, dword ptr [rbp - 4] +0x71d9: add rsp, 0x50 +0x71dd: pop rbp +0x71de: ret +0x9e23: add rsp, 0x10 +0x9e27: pop rbp +0x9e28: ret +0x90f0: push rbp +0x90f1: mov rbp, rsp +0x90f4: sub rsp, 0x20 +0x90f8: xor eax, eax +0x90fa: mov ecx, eax +0x90fc: mov rdx, qword ptr fs:[0x28] +0x9105: mov qword ptr [rbp - 8], rdx +0x9109: mov qword ptr [rbp - 0x18], rdi +0x910d: mov qword ptr [rbp - 0x10], 0 +0x9115: mov rdi, qword ptr [rip + 0x310bc4] +0x911c: mov rsi, qword ptr [rbp - 0x18] +0x9120: lea rdx, qword ptr [rip + 0x59] +0x9127: lea r8, qword ptr [rbp - 0x10] +0x912b: call 0x1f290 +0x1f290: push rbp +0x1f291: mov rbp, rsp +0x1f294: sub rsp, 0x90 +0x1f29b: mov rax, qword ptr fs:[0x28] +0x1f2a4: mov qword ptr [rbp - 8], rax +0x1f2a8: mov qword ptr [rbp - 0x28], rdi +0x1f2ac: mov qword ptr [rbp - 0x30], rsi +0x1f2b0: mov qword ptr [rbp - 0x38], rdx +0x1f2b4: mov qword ptr [rbp - 0x40], rcx +0x1f2b8: mov qword ptr [rbp - 0x48], r8 +0x1f2bc: mov dword ptr [rbp - 0x4c], 0 +0x1f2c3: mov qword ptr [rbp - 0x18], 0 +0x1f2cb: mov qword ptr [rbp - 0x58], 0 +0x1f2d3: mov rdi, qword ptr [rbp - 0x28] +0x1f2d7: call 0x61160 +0x61160: push rbp +0x61161: mov rbp, rsp +0x61164: sub rsp, 0x20 +0x61168: mov qword ptr [rbp - 0x10], rdi +0x6116c: cmp qword ptr [rbp - 0x10], 0 +0x61171: jne 0x61188 +0x61188: mov rax, qword ptr [rbp - 0x10] +0x6118c: mov ecx, dword ptr [rax + 0x64] +Seed information: +0x30000000 [ 0xff ] 0x30000001 [ 0xff ] 0x30000002 [ 0xff ] 0x30000003 [ 0xff ] 0x30000004 [ 0xff ] 0x30000005 [ 0xff ] 0x30000006 [ 0xff ] 0x30000007 [ 0xff ] 0x30000008 [ 0xff ] 0x30000009 [ 0xff ] 0x3000000a [ 0xff ] 0x3000000b [ 0xff ] 0x3000000c [ 0xff ] 0x3000000d [ 0xff ] 0x3000000e [ 0xff ] 0x3000000f [ 0xff ] 0x30000010 [ 0xff ] 0x30000011 [ 0xff ] 0x30000012 [ 0xff ] 0x30000013 [ 0xff ] 0x30000014 [ 0xff ] 0x30000015 [ 0xff ] 0x30000016 [ 0xff ] 0x30000017 [ 0xff ] 0x30000018 [ 0xff ] 0x30000019 [ 0xff ] 0x3000001a [ 0xff ] 0x3000001b [ 0xff ] 0x3000001c [ 0xff ] 0x3000001d [ 0xff ] 0x3000001e [ 0xff ] 0x3000001f [ 0xff ] 0x30000020 [ 0xff ] 0x30000021 [ 0xff ] 0x30000022 [ 0xff ] 0x30000023 [ 0xff ] 0x30000024 [ 0xff ] 0x30000025 [ 0xff ] 0x30000026 [ 0xff ] 0x30000027 [ 0xff ] 0x30000028 [ 0xff ] 0x30000029 [ 0xff ] 0x3000002a [ 0xff ] 0x3000002b [ 0xff ] 0x3000002c [ 0xff ] 0x3000002d [ 0xff ] 0x3000002e [ 0xff ] 0x3000002f [ 0xff ] 0x30000030 [ 0xff ] 0x30000031 [ 0xff ] 0x30000032 [ 0x0 ] 0x30000a32 [ 0xff ] 0x30000a33 [ 0xff ] 0x30000a34 [ 0xff ] 0x30000a35 [ 0xff ] 0x30000a36 [ 0xff ] 0x30000a37 [ 0xff ] 0x30000a38 [ 0xff ] 0x30000a39 [ 0xff ] 0x30000a3a [ 0xff ] 0x30000a3b [ 0xff ] 0x30000a3c [ 0xff ] 0x30000a3d [ 0xff ] 0x30000a3e [ 0xff ] 0x30000a3f [ 0xff ] 0x30000a40 [ 0xff ] 0x30000a41 [ 0xff ] 0x30000a42 [ 0xff ] 0x30000a43 [ 0xff ] 0x30000a44 [ 0xff ] 0x30000a45 [ 0xff ] 0x30000a46 [ 0xff ] 0x30000a47 [ 0xff ] 0x30000a48 [ 0xff ] 0x30000a49 [ 0xff ] 0x30000a4a [ 0xff ] 0x30000a4b [ 0xff ] 0x30000a4c [ 0xff ] 0x30000a4d [ 0xff ] 0x30000a4e [ 0xff ] 0x30000a4f [ 0xff ] 0x30000a50 [ 0xff ] 0x30000a51 [ 0xff ] 0x30000a52 [ 0xff ] 0x30000a53 [ 0xff ] 0x30000a54 [ 0xff ] 0x30000a55 [ 0xff ] 0x30000a56 [ 0xff ] 0x30000a57 [ 0xff ] 0x30000a58 [ 0xff ] 0x30000a59 [ 0xff ] 0x30000a5a [ 0xff ] 0x30000a5b [ 0xff ] 0x30000a5c [ 0xff ] 0x30000a5d [ 0xff ] 0x30000a5e [ 0xff ] 0x30000a5f [ 0xff ] 0x30000a60 [ 0xff ] 0x30000a61 [ 0xff ] 0x30000a62 [ 0xff ] 0x30000a64 [ 0x3a ] 0x30000a65 [ 0xff ] 0x30000a66 [ 0xff ] 0x30000a67 [ 0xff ] 0x30000a68 [ 0xff ] 0x30000a69 [ 0xff ] 0x30000a6a [ 0xff ] 0x30000a6b [ 0xff ] 0x30000a6c [ 0xff ] 0x30000a6d [ 0xff ] 0x30000a6e [ 0xff ] 0x30000a6f [ 0xff ] 0x30000a70 [ 0xff ] 0x30000a71 [ 0xff ] 0x30000a72 [ 0xff ] 0x30000a73 [ 0xff ] 0x30000a74 [ 0xff ] 0x30000a75 [ 0xff ] 0x30000a76 [ 0xff ] 0x30000a77 [ 0xff ] 0x30000a78 [ 0xff ] 0x30000a79 [ 0xff ] 0x30000a7a [ 0xff ] 0x30000a7b [ 0xff ] 0x30000a7c [ 0xff ] 0x30000a7d [ 0xff ] 0x30000a7e [ 0xff ] 0x30000a7f [ 0xff ] 0x30000a80 [ 0xff ] 0x30000a81 [ 0xff ] 0x30000a82 [ 0xff ] 0x30000a83 [ 0xff ] 0x30000a84 [ 0xff ] 0x30000a85 [ 0xff ] 0x30000a86 [ 0xff ] 0x30000a87 [ 0xff ] 0x30000a88 [ 0xff ] 0x30000a89 [ 0xff ] 0x30000a8a [ 0xff ] 0x30000a8b [ 0xff ] 0x30000a8c [ 0xff ] 0x30000a8d [ 0xff ] 0x30000a8e [ 0xff ] 0x30000a8f [ 0xff ] 0x30000a90 [ 0xff ] 0x30000a91 [ 0xff ] 0x30000a92 [ 0xff ] 0x30000a93 [ 0xff ] 0x30000a94 [ 0xff ] 0x30000a95 [ 0xff ] 0x30000a96 [ 0x0 ] 0x30001b86 [ 0xff ] 0x30001b87 [ 0xff ] 0x30001b88 [ 0xff ] 0x30001b89 [ 0xff ] 0x30001b8a [ 0xff ] 0x30001b8b [ 0xff ] 0x30001b8c [ 0xff ] 0x30001b8d [ 0xff ] 0x30001b8e [ 0xff ] 0x30001b8f [ 0xff ] 0x30001b90 [ 0xff ] 0x30001b91 [ 0xff ] 0x30001b92 [ 0xff ] 0x30001b93 [ 0xff ] 0x30001b94 [ 0xff ] 0x30001b95 [ 0xff ] 0x30001b96 [ 0xff ] 0x30001b97 [ 0xff ] 0x30001b98 [ 0xff ] 0x30001b99 [ 0xff ] 0x30001b9a [ 0xff ] 0x30001b9b [ 0xff ] 0x30001b9c [ 0xff ] 0x30001b9d [ 0xff ] 0x30001b9e [ 0xff ] 0x30001b9f [ 0xff ] 0x30001ba0 [ 0xff ] 0x30001ba1 [ 0xff ] 0x30001ba2 [ 0xff ] 0x30001ba3 [ 0xff ] 0x30001ba4 [ 0xff ] 0x30001ba5 [ 0xff ] 0x30001ba6 [ 0xff ] 0x30001ba7 [ 0xff ] 0x30001ba8 [ 0xff ] 0x30001ba9 [ 0xff ] 0x30001baa [ 0xff ] 0x30001bab [ 0xff ] 0x30001bac [ 0xff ] 0x30001bad [ 0xff ] 0x30001bae [ 0xff ] 0x30001baf [ 0xff ] 0x30001bb0 [ 0xff ] 0x30001bb1 [ 0xff ] 0x30001bb2 [ 0xff ] 0x30001bb3 [ 0xff ] 0x30001bb4 [ 0xff ] 0x30001bb5 [ 0xff ] 0x30001bb6 [ 0xff ] 0x30001bb8 [ 0x0 ] 0x3000147e [ 0xff ] 0x3000147f [ 0xff ] 0x30001480 [ 0xff ] 0x30001481 [ 0xff ] 0x30001482 [ 0xff ] 0x30001483 [ 0xff ] 0x30001484 [ 0xff ] 0x30001485 [ 0xff ] 0x30001486 [ 0xff ] 0x30001487 [ 0xff ] 0x30001488 [ 0xff ] 0x30001489 [ 0xff ] 0x3000148a [ 0xff ] 0x3000148b [ 0xff ] 0x3000148c [ 0xff ] 0x3000148d [ 0xff ] 0x3000148e [ 0xff ] 0x3000148f [ 0xff ] 0x30001490 [ 0xff ] 0x30001491 [ 0xff ] 0x30001492 [ 0xff ] 0x30001493 [ 0xff ] 0x30001494 [ 0xff ] 0x30001495 [ 0xff ] 0x30001496 [ 0xff ] 0x30001497 [ 0xff ] 0x30001498 [ 0xff ] 0x30001499 [ 0xff ] 0x3000149a [ 0xff ] 0x3000149b [ 0xff ] 0x3000149c [ 0xff ] 0x3000149d [ 0xff ] 0x3000149e [ 0xff ] 0x3000149f [ 0xff ] 0x300014a0 [ 0xff ] 0x300014a1 [ 0xff ] 0x300014a2 [ 0xff ] 0x300014a3 [ 0xff ] 0x300014a4 [ 0xff ] 0x300014a5 [ 0xff ] 0x300014a6 [ 0xff ] 0x300014a7 [ 0xff ] 0x300014a8 [ 0xff ] 0x300014a9 [ 0xff ] 0x300014aa [ 0xff ] 0x300014ab [ 0xff ] 0x300014ac [ 0xff ] 0x300014ad [ 0xff ] 0x300014ae [ 0xff ] 0x300014b0 [ 0x0 ] 0x300204fe [ 0x0 ] 0x30000d4c [ 0xff ] 0x30000d4d [ 0xff ] 0x30000d4e [ 0xff ] 0x30000d4f [ 0xff ] 0x30000d50 [ 0xff ] 0x30000d51 [ 0xff ] 0x30000d52 [ 0xff ] 0x30000d53 [ 0xff ] 0x30000d54 [ 0xff ] 0x30000d55 [ 0xff ] 0x30000d56 [ 0xff ] 0x30000d57 [ 0xff ] 0x30000d58 [ 0xff ] 0x30000d59 [ 0xff ] 0x30000d5a [ 0xff ] 0x30000d5b [ 0xff ] 0x30000d5c [ 0xff ] 0x30000d5d [ 0xff ] 0x30000d5e [ 0xff ] 0x30000d5f [ 0xff ] 0x30000d60 [ 0xff ] 0x30000d61 [ 0xff ] 0x30000d62 [ 0xff ] 0x30000d63 [ 0xff ] 0x30000d64 [ 0xff ] 0x30000d65 [ 0xff ] 0x30000d66 [ 0xff ] 0x30000d67 [ 0xff ] 0x30000d68 [ 0xff ] 0x30000d69 [ 0xff ] 0x30000d6a [ 0xff ] 0x30000d6b [ 0xff ] 0x30000d6c [ 0xff ] 0x30000d6d [ 0xff ] 0x30000d6e [ 0xff ] 0x30000d6f [ 0xff ] 0x30000d70 [ 0x0 ] 0x30000d71 [ 0xff ] 0x30000d72 [ 0xff ] 0x30000d73 [ 0xff ] 0x30000d74 [ 0xff ] 0x30000d75 [ 0xff ] 0x30000d76 [ 0xff ] 0x30000d77 [ 0xff ] 0x30000d78 [ 0xff ] 0x30000d79 [ 0xff ] 0x30000d7a [ 0xff ] 0x30000d7b [ 0xff ] 0x30000d7c [ 0xff ] 0x30000d7d [ 0xff ] 0x30000daa [ 0xff ] 0x30000dab [ 0xff ] 0x30000dac [ 0xff ] 0x30000dad [ 0xff ] 0x30000dae [ 0xff ] 0x30000daf [ 0xff ] 0x30000db0 [ 0xff ] 0x30000db1 [ 0xff ] 0x30000db2 [ 0xff ] 0x30000db3 [ 0xff ] 0x30000db4 [ 0xff ] 0x30000db5 [ 0xff ] 0x30000db6 [ 0xff ] 0x30000db7 [ 0xff ] 0x30000db8 [ 0xff ] 0x30000db9 [ 0xff ] 0x30000dba [ 0xff ] 0x30000dbb [ 0xff ] 0x30000dbc [ 0xff ] 0x30000dbd [ 0xff ] 0x30000dbe [ 0xff ] 0x30000dbf [ 0xff ] 0x30000dc0 [ 0xff ] 0x30000dc1 [ 0xff ] 0x30000dc2 [ 0xff ] 0x30000dc3 [ 0xff ] 0x30000dc4 [ 0xff ] 0x30000dc5 [ 0xff ] 0x30000dc6 [ 0xff ] 0x30000dc7 [ 0xff ] 0x30000dc8 [ 0xff ] 0x30000dc9 [ 0xff ] 0x30000dca [ 0xff ] 0x30000dcb [ 0xff ] 0x30000dcc [ 0xff ] 0x30000dcd [ 0xff ] 0x30000dce [ 0xff ] 0x30000dcf [ 0xff ] 0x30000dd0 [ 0xff ] 0x30000dd1 [ 0xff ] 0x30000dd2 [ 0xff ] 0x30000dd3 [ 0xff ] 0x30000dd4 [ 0xff ] 0x30000dd5 [ 0xff ] 0x30000dd6 [ 0xff ] 0x30000dd7 [ 0xff ] 0x30000dd8 [ 0xff ] 0x30000dd9 [ 0xff ] 0x30000dda [ 0xff ] 0x30000ddc [ 0xff ] 0x30000ddd [ 0xff ] 0x30000dde [ 0xff ] 0x30000ddf [ 0xff ] 0x30000de0 [ 0xff ] 0x30000de1 [ 0xff ] 0x30000de2 [ 0xff ] 0x30000de3 [ 0xff ] 0x30000de4 [ 0xff ] 0x30000de5 [ 0xff ] 0x30000de6 [ 0xff ] 0x30000de7 [ 0xff ] 0x30000de8 [ 0xff ] 0x30000de9 [ 0xff ] 0x30000dea [ 0xff ] 0x30000deb [ 0xff ] 0x30000dec [ 0xff ] 0x30000ded [ 0xff ] 0x30000dee [ 0xff ] 0x30000def [ 0xff ] 0x30000df0 [ 0xff ] 0x30000df1 [ 0xff ] 0x30000df2 [ 0xff ] 0x30000df3 [ 0xff ] 0x30000df4 [ 0xff ] 0x30000df5 [ 0xff ] 0x30000df6 [ 0xff ] 0x30000df7 [ 0xff ] 0x30000df8 [ 0xff ] 0x30000df9 [ 0xff ] 0x30000dfa [ 0xff ] 0x30000dfb [ 0xff ] 0x30000dfc [ 0xff ] 0x30000dfd [ 0xff ] 0x30000dfe [ 0xff ] 0x30000dff [ 0xff ] 0x30000e00 [ 0xff ] 0x30000e01 [ 0xff ] 0x30000e02 [ 0xff ] 0x30000e03 [ 0xff ] 0x30000e04 [ 0xff ] 0x30000e05 [ 0xff ] 0x30000e06 [ 0xff ] 0x30000e07 [ 0xff ] 0x30000e08 [ 0xff ] 0x30000e09 [ 0xff ] 0x30000e0a [ 0xff ] 0x30000e0b [ 0xff ] 0x30000e0c [ 0xff ] 0x30000e0e [ 0x0 ] 0x3003ef96 [ 0x0 ] 0x3001f7b2 [ 0x0 ] 0x3001f7e4 [ 0x0 ] 0x3001f7e5 [ 0xff ] 0x3001f7e6 [ 0x0 ] 0x3001f7e7 [ 0xff ] 0x3001f7e8 [ 0xff ] 0x3001f7e9 [ 0xff ] 0x3001f7ea [ 0xff ] 0x3001f7eb [ 0xff ] 0x3001f7ec [ 0xff ] 0x3001f7ed [ 0x0 ] 0x3001f7ee [ 0xff ] 0x3001f7ef [ 0xff ] [UAF-REPORT] Potential Use-after-free (UAF) at 0x31660: mov ecx, dword ptr [rax + 0x64] +Try to use memory at 0x300026d2 - 0x300026d5 +Allocated memory range is 0x30002666 - 0x3000290e +Allocated memory at 0x14d14 and Freed at 0x14d89 + +Recent 200 emulated instructions: +0xd32e: movsxd rcx, dword ptr [rbp - 4] +0xd332: lea rdx, qword ptr [rip + 0x30c9af] +0xd339: mov r8, qword ptr [rdx + rcx*8] +0xd33d: sub r8, rax +0xd340: mov qword ptr [rdx + rcx*8], r8 +0xd344: pop rbp +0xd345: ret +0xd2ef: mov rcx, qword ptr [rip + 0x309d5a] +0xd2f6: mov rdi, qword ptr [rbp - 8] +0xd2fa: call rcx +0x14d60: push rbp +0x14d61: mov rbp, rsp +0x14d64: sub rsp, 0x10 +0x14d68: mov qword ptr [rbp - 8], rdi +0x14d6c: mov rax, qword ptr [rbp - 8] +0x14d70: mov qword ptr [rbp - 0x10], rax +0x14d74: mov rax, qword ptr [rbp - 0x10] +0x14d78: add rax, -8 +0x14d7e: mov qword ptr [rbp - 0x10], rax +0x14d82: mov rax, qword ptr [rbp - 0x10] +0x14d86: mov rdi, rax +0x14d89: call 0xbc967 +0x14d8e: add rsp, 0x10 +0x14d92: pop rbp +0x14d93: ret +0xd2fc: jmp 0xd30b +0xd30b: add rsp, 0x10 +0xd30f: pop rbp +0xd310: ret +0x31b9e: add rsp, 0x40 +0x31ba2: pop rbp +0x31ba3: ret +0x31637: mov dword ptr [rbp - 4], 0 +0x3163e: mov eax, dword ptr [rbp - 4] +0x31641: add rsp, 0x30 +0x31645: pop rbp +0x31646: ret +0x1e0f7: add rsp, 0x10 +0x1e0fb: pop rbp +0x1e0fc: ret +0x9e14: lea rdi, qword ptr [rip + 0xe66dd] +0x9e1b: mov dword ptr [rbp - 4], eax +0x9e1e: call 0x7060 +0x7060: push rbp +0x7061: mov rbp, rsp +0x7064: sub rsp, 0x50 +0x7068: mov qword ptr [rbp - 0x10], rdi +0x706c: mov dword ptr [rbp - 0x14], 0 +0x7073: cmp qword ptr [rbp - 0x10], 0 +0x7078: je 0x708f +0x707a: mov rdi, qword ptr [rbp - 0x10] +0x707e: call 0xbfce7 +0xbfce7: push rbp +0xbfce8: mov rbp, rsp +0xbfceb: sub rsp, 0x10 +0xbfcef: mov qword ptr [rbp - 8], rdi +0xbfcf3: mov rax, qword ptr [rbp - 8] +0xbfcf7: mov rdi, rax +0xbfcfa: call 0xce800 +0xce800: push rsi +0xce801: mov rdx, rdi +0xce804: mov rcx, rdx +0xce807: and rdx, 0xfffffffffffffff0 +0xce80b: pxor xmm0, xmm0 +0xce80f: pcmpeqb xmm0, xmmword ptr [rdx] +0xce813: pmovmskb eax, xmm0 +0xce817: and ecx, 0xf +0xce81a: shr eax, cl +0xce81c: bsf eax, eax +0xce81f: jne 0xce82c +0xce821: mov rax, rdx +0xce824: add rdx, rcx +0xce827: call 0xcee20 +0xcee20: pxor xmm0, xmm0 +0xcee24: add rax, 0x10 +0xcee28: movdqa xmm1, xmmword ptr [rax] +0xcee2c: pcmpeqb xmm1, xmm0 +0xcee30: pmovmskb ecx, xmm1 +0xcee34: test ecx, ecx +0xcee36: je 0xcee24 +0xcee24: add rax, 0x10 +0xcee28: movdqa xmm1, xmmword ptr [rax] +0xcee2c: pcmpeqb xmm1, xmm0 +0xcee30: pmovmskb ecx, xmm1 +0xcee34: test ecx, ecx +0xcee36: je 0xcee24 +0xcee38: bsf ecx, ecx +0xcee3b: sub rcx, rdx +0xcee3e: add rax, rcx +0xcee41: ret +0xce82c: pop rcx +0xce82d: ret +0xbfcff: leave +0xbfd00: ret +0x7083: add rax, 1 +0x7089: mov qword ptr [rbp - 0x40], rax +0x708d: jmp 0x7099 +0x7099: mov rax, qword ptr [rbp - 0x40] +0x709d: mov qword ptr [rbp - 0x20], rax +0x70a1: mov qword ptr [rbp - 0x28], 0 +0x70a9: mov qword ptr [rbp - 0x30], 8 +0x70b1: mov qword ptr [rbp - 0x38], 0 +0x70b9: cmp qword ptr [rbp - 0x10], 0 +0x70be: je 0x70de +0x70c0: mov rdi, qword ptr [rbp - 0x10] +0x70c4: mov rsi, qword ptr [rbp - 0x20] +0x70c8: call 0xb34d7 +0xb34d7: push rbp +0xb34d8: mov rbp, rsp +0xb34db: mov qword ptr [rbp - 0x28], rdi +0xb34df: mov qword ptr [rbp - 0x30], rsi +0xb34e3: mov rax, qword ptr [rbp - 0x28] +0xb34e7: mov qword ptr [rbp - 0x18], rax +0xb34eb: mov qword ptr [rbp - 0x20], 0 +0xb34f3: lea rax, qword ptr [rip - 0xb34fa] +0xb34fa: mov qword ptr [rbp - 0x10], rax +0xb34fe: mov rdx, qword ptr [rip + 0x265f7b] +0xb3505: mov rax, qword ptr [rbp - 0x10] +0xb3509: add rax, rdx +0xb350c: sub rax, 1 +0xb3510: mov qword ptr [rbp - 8], rax +0xb3514: cmp qword ptr [rbp - 0x30], 0 +0xb3519: je 0xb3530 +0xb351b: mov rdx, qword ptr [rbp - 0x18] +0xb351f: mov rax, qword ptr [rbp - 0x30] +0xb3523: add rax, rdx +0xb3526: sub rax, 1 +0xb352a: mov qword ptr [rbp - 0x20], rax +0xb352e: jmp 0xb3538 +0xb3538: mov rax, qword ptr [rbp - 0x18] +0xb353c: cmp rax, qword ptr [rbp - 0x20] +0xb3540: ja 0xb355d +0xb3542: mov rax, qword ptr [rbp - 0x18] +0xb3546: cmp rax, qword ptr [rbp - 0x10] +0xb354a: jb 0xb355d +0xb354c: mov rax, qword ptr [rbp - 0x20] +0xb3550: cmp rax, qword ptr [rbp - 8] +0xb3554: ja 0xb355d +0xb355d: mov eax, 0 +0xb3562: pop rbp +0xb3563: ret +0x70cd: cmp eax, 0 +0x70d0: jne 0x70de +0x70d2: mov dword ptr [rbp - 4], 2 +0x70d9: jmp 0x71d6 +0x71d6: mov eax, dword ptr [rbp - 4] +0x71d9: add rsp, 0x50 +0x71dd: pop rbp +0x71de: ret +0x9e23: add rsp, 0x10 +0x9e27: pop rbp +0x9e28: ret +0x90f0: push rbp +0x90f1: mov rbp, rsp +0x90f4: sub rsp, 0x20 +0x90f8: xor eax, eax +0x90fa: mov ecx, eax +0x90fc: mov rdx, qword ptr fs:[0x28] +0x9105: mov qword ptr [rbp - 8], rdx +0x9109: mov qword ptr [rbp - 0x18], rdi +0x910d: mov qword ptr [rbp - 0x10], 0 +0x9115: mov rdi, qword ptr [rip + 0x310bc4] +0x911c: mov rsi, qword ptr [rbp - 0x18] +0x9120: lea rdx, qword ptr [rip + 0x59] +0x9127: lea r8, qword ptr [rbp - 0x10] +0x912b: call 0x1f290 +0x1f290: push rbp +0x1f291: mov rbp, rsp +0x1f294: sub rsp, 0x90 +0x1f29b: mov rax, qword ptr fs:[0x28] +0x1f2a4: mov qword ptr [rbp - 8], rax +0x1f2a8: mov qword ptr [rbp - 0x28], rdi +0x1f2ac: mov qword ptr [rbp - 0x30], rsi +0x1f2b0: mov qword ptr [rbp - 0x38], rdx +0x1f2b4: mov qword ptr [rbp - 0x40], rcx +0x1f2b8: mov qword ptr [rbp - 0x48], r8 +0x1f2bc: mov dword ptr [rbp - 0x4c], 0 +0x1f2c3: mov qword ptr [rbp - 0x18], 0 +0x1f2cb: mov qword ptr [rbp - 0x58], 0 +0x1f2d3: mov rdi, qword ptr [rbp - 0x28] +0x1f2d7: call 0x61160 +0x61160: push rbp +0x61161: mov rbp, rsp +0x61164: sub rsp, 0x20 +0x61168: mov qword ptr [rbp - 0x10], rdi +0x6116c: cmp qword ptr [rbp - 0x10], 0 +0x61171: jne 0x61188 +0x61188: mov rax, qword ptr [rbp - 0x10] +0x6118c: mov ecx, dword ptr [rax + 0x64] +0x6118f: mov dword ptr [rbp - 0x14], ecx +0x61192: cmp dword ptr [rbp - 0x14], 0xa029a697 +0x61199: je 0x611be +0x6119b: mov rdi, qword ptr [rbp - 0x10] +0x6119f: call 0x31650 +0x31650: push rbp +0x31651: mov rbp, rsp +0x31654: sub rsp, 0x20 +0x31658: mov qword ptr [rbp - 0x10], rdi +0x3165c: mov rax, qword ptr [rbp - 0x10] +0x31660: mov ecx, dword ptr [rax + 0x64] +Seed information: +0x30000000 [ 0x40 ] 0x30000001 [ 0xff ] 0x30000002 [ 0xff ] 0x30000003 [ 0xff ] 0x30000004 [ 0xff ] 0x30000005 [ 0xff ] 0x30000006 [ 0xff ] 0x30000007 [ 0xff ] 0x30000008 [ 0xff ] 0x30000009 [ 0xff ] 0x3000000a [ 0xff ] 0x3000000b [ 0xff ] 0x3000000c [ 0xff ] 0x3000000d [ 0xff ] 0x3000000e [ 0x80 ] 0x3000000f [ 0xff ] 0x30000010 [ 0xff ] 0x30000011 [ 0xff ] 0x30000012 [ 0xff ] 0x30000013 [ 0xff ] 0x30000014 [ 0xff ] 0x30000015 [ 0xff ] 0x30000016 [ 0xff ] 0x30000017 [ 0xff ] 0x30000018 [ 0xff ] 0x30000019 [ 0xff ] 0x3000001a [ 0xff ] 0x3000001b [ 0xff ] 0x3000001c [ 0xff ] 0x3000001d [ 0xff ] 0x3000001e [ 0xff ] 0x3000001f [ 0xff ] 0x30000020 [ 0xff ] 0x30000021 [ 0xff ] 0x30000022 [ 0xff ] 0x30000023 [ 0xff ] 0x30000024 [ 0xff ] 0x30000025 [ 0xff ] 0x30000026 [ 0xff ] 0x30000027 [ 0xff ] 0x30000028 [ 0xff ] 0x30000029 [ 0xff ] 0x3000002a [ 0xff ] 0x3000002b [ 0xff ] 0x3000002c [ 0xff ] 0x3000002d [ 0xff ] 0x3000002e [ 0xff ] 0x3000002f [ 0xff ] 0x30000030 [ 0xff ] 0x30000031 [ 0xff ] 0x30000032 [ 0x0 ] 0x30000a32 [ 0xff ] 0x30000a33 [ 0xff ] 0x30000a34 [ 0xff ] 0x30000a35 [ 0xff ] 0x30000a36 [ 0xff ] 0x30000a37 [ 0xff ] 0x30000a38 [ 0xff ] 0x30000a39 [ 0xff ] 0x30000a3a [ 0xff ] 0x30000a3b [ 0xff ] 0x30000a3c [ 0xff ] 0x30000a3d [ 0xff ] 0x30000a3e [ 0xff ] 0x30000a3f [ 0xff ] 0x30000a40 [ 0xff ] 0x30000a41 [ 0xff ] 0x30000a42 [ 0xff ] 0x30000a43 [ 0xff ] 0x30000a44 [ 0xff ] 0x30000a45 [ 0xff ] 0x30000a46 [ 0xff ] 0x30000a47 [ 0xff ] 0x30000a48 [ 0xff ] 0x30000a49 [ 0xff ] 0x30000a4a [ 0xff ] 0x30000a4b [ 0xff ] 0x30000a4c [ 0xff ] 0x30000a4d [ 0xff ] 0x30000a4e [ 0xff ] 0x30000a4f [ 0xff ] 0x30000a50 [ 0xff ] 0x30000a51 [ 0xff ] 0x30000a52 [ 0xff ] 0x30000a53 [ 0xff ] 0x30000a54 [ 0xff ] 0x30000a55 [ 0xff ] 0x30000a56 [ 0xff ] 0x30000a57 [ 0xff ] 0x30000a58 [ 0xff ] 0x30000a59 [ 0xff ] 0x30000a5a [ 0xff ] 0x30000a5b [ 0xff ] 0x30000a5c [ 0xff ] 0x30000a5d [ 0xff ] 0x30000a5e [ 0xff ] 0x30000a5f [ 0xff ] 0x30000a60 [ 0xff ] 0x30000a61 [ 0xff ] 0x30000a62 [ 0xff ] 0x30000a64 [ 0x3a ] 0x30000a65 [ 0xff ] 0x30000a66 [ 0xff ] 0x30000a67 [ 0xff ] 0x30000a68 [ 0xff ] 0x30000a69 [ 0xff ] 0x30000a6a [ 0xff ] 0x30000a6b [ 0xff ] 0x30000a6c [ 0xff ] 0x30000a6d [ 0xff ] 0x30000a6e [ 0xff ] 0x30000a6f [ 0xff ] 0x30000a70 [ 0xff ] 0x30000a71 [ 0xff ] 0x30000a72 [ 0xff ] 0x30000a73 [ 0xff ] 0x30000a74 [ 0xff ] 0x30000a75 [ 0xff ] 0x30000a76 [ 0xff ] 0x30000a77 [ 0xff ] 0x30000a78 [ 0xff ] 0x30000a79 [ 0xff ] 0x30000a7a [ 0xff ] 0x30000a7b [ 0xff ] 0x30000a7c [ 0xff ] 0x30000a7d [ 0xff ] 0x30000a7e [ 0xff ] 0x30000a7f [ 0xff ] 0x30000a80 [ 0xff ] 0x30000a81 [ 0xff ] 0x30000a82 [ 0xff ] 0x30000a83 [ 0xff ] 0x30000a84 [ 0xff ] 0x30000a85 [ 0xff ] 0x30000a86 [ 0xff ] 0x30000a87 [ 0xff ] 0x30000a88 [ 0xff ] 0x30000a89 [ 0xff ] 0x30000a8a [ 0xff ] 0x30000a8b [ 0xff ] 0x30000a8c [ 0xff ] 0x30000a8d [ 0xff ] 0x30000a8e [ 0xff ] 0x30000a8f [ 0xff ] 0x30000a90 [ 0xff ] 0x30000a91 [ 0xff ] 0x30000a92 [ 0xff ] 0x30000a93 [ 0xff ] 0x30000a94 [ 0xff ] 0x30000a95 [ 0xff ] 0x30000a96 [ 0x0 ] 0x30001b86 [ 0xff ] 0x30001b87 [ 0xff ] 0x30001b88 [ 0xff ] 0x30001b89 [ 0xff ] 0x30001b8a [ 0xff ] 0x30001b8b [ 0xff ] 0x30001b8c [ 0xff ] 0x30001b8d [ 0xff ] 0x30001b8e [ 0xff ] 0x30001b8f [ 0xff ] 0x30001b90 [ 0xff ] 0x30001b91 [ 0xff ] 0x30001b92 [ 0xff ] 0x30001b93 [ 0xff ] 0x30001b94 [ 0xff ] 0x30001b95 [ 0xff ] 0x30001b96 [ 0xff ] 0x30001b97 [ 0xff ] 0x30001b98 [ 0xff ] 0x30001b99 [ 0xff ] 0x30001b9a [ 0xff ] 0x30001b9b [ 0xff ] 0x30001b9c [ 0xff ] 0x30001b9d [ 0xff ] 0x30001b9e [ 0xff ] 0x30001b9f [ 0xff ] 0x30001ba0 [ 0xff ] 0x30001ba1 [ 0xff ] 0x30001ba2 [ 0xff ] 0x30001ba3 [ 0xff ] 0x30001ba4 [ 0xff ] 0x30001ba5 [ 0xff ] 0x30001ba6 [ 0xff ] 0x30001ba7 [ 0xff ] 0x30001ba8 [ 0xff ] 0x30001ba9 [ 0xff ] 0x30001baa [ 0xff ] 0x30001bab [ 0xff ] 0x30001bac [ 0xff ] 0x30001bad [ 0xff ] 0x30001bae [ 0xff ] 0x30001baf [ 0xff ] 0x30001bb0 [ 0xff ] 0x30001bb1 [ 0xff ] 0x30001bb2 [ 0xff ] 0x30001bb3 [ 0xff ] 0x30001bb4 [ 0xff ] 0x30001bb5 [ 0xff ] 0x30001bb6 [ 0xff ] 0x30001bb8 [ 0x0 ] 0x3000147e [ 0xff ] 0x3000147f [ 0xff ] 0x30001480 [ 0xff ] 0x30001481 [ 0xff ] 0x30001482 [ 0xff ] 0x30001483 [ 0xff ] 0x30001484 [ 0xff ] 0x30001485 [ 0xff ] 0x30001486 [ 0xff ] 0x30001487 [ 0xff ] 0x30001488 [ 0xff ] 0x30001489 [ 0xff ] 0x3000148a [ 0xff ] 0x3000148b [ 0xff ] 0x3000148c [ 0xff ] 0x3000148d [ 0xff ] 0x3000148e [ 0xff ] 0x3000148f [ 0xff ] 0x30001490 [ 0xff ] 0x30001491 [ 0xff ] 0x30001492 [ 0xff ] 0x30001493 [ 0xff ] 0x30001494 [ 0xff ] 0x30001495 [ 0xff ] 0x30001496 [ 0xff ] 0x30001497 [ 0xff ] 0x30001498 [ 0xff ] 0x30001499 [ 0xff ] 0x3000149a [ 0xff ] 0x3000149b [ 0xff ] 0x3000149c [ 0xff ] 0x3000149d [ 0xff ] 0x3000149e [ 0xff ] 0x3000149f [ 0xff ] 0x300014a0 [ 0xff ] 0x300014a1 [ 0xff ] 0x300014a2 [ 0xff ] 0x300014a3 [ 0xff ] 0x300014a4 [ 0xff ] 0x300014a5 [ 0xff ] 0x300014a6 [ 0xff ] 0x300014a7 [ 0xff ] 0x300014a8 [ 0xff ] 0x300014a9 [ 0xff ] 0x300014aa [ 0xff ] 0x300014ab [ 0xff ] 0x300014ac [ 0xff ] 0x300014ad [ 0xff ] 0x300014ae [ 0xff ] 0x300014b0 [ 0x0 ] 0x300204fe [ 0x0 ] 0x30000d4c [ 0xff ] 0x30000d4d [ 0xff ] 0x30000d4e [ 0xff ] 0x30000d4f [ 0xff ] 0x30000d50 [ 0xff ] 0x30000d51 [ 0xff ] 0x30000d52 [ 0xff ] 0x30000d53 [ 0xff ] 0x30000d54 [ 0xff ] 0x30000d55 [ 0xff ] 0x30000d56 [ 0xff ] 0x30000d57 [ 0xff ] 0x30000d58 [ 0xff ] 0x30000d59 [ 0xff ] 0x30000d5a [ 0xff ] 0x30000d5b [ 0xff ] 0x30000d5c [ 0xff ] 0x30000d5d [ 0xff ] 0x30000d5e [ 0xff ] 0x30000d5f [ 0xff ] 0x30000d60 [ 0xff ] 0x30000d61 [ 0xff ] 0x30000d62 [ 0xff ] 0x30000d63 [ 0xff ] 0x30000d64 [ 0xff ] 0x30000d65 [ 0xff ] 0x30000d66 [ 0xff ] 0x30000d67 [ 0xff ] 0x30000d68 [ 0xff ] 0x30000d69 [ 0xff ] 0x30000d6a [ 0xff ] 0x30000d6b [ 0xff ] 0x30000d6c [ 0xff ] 0x30000d6d [ 0xff ] 0x30000d6e [ 0xff ] 0x30000d6f [ 0xff ] 0x30000d70 [ 0x0 ] 0x30000d71 [ 0xff ] 0x30000d72 [ 0xff ] 0x30000d73 [ 0xff ] 0x30000d74 [ 0xff ] 0x30000d75 [ 0xff ] 0x30000d76 [ 0xff ] 0x30000d77 [ 0xff ] 0x30000d78 [ 0xff ] 0x30000d79 [ 0xff ] 0x30000d7a [ 0xff ] 0x30000d7b [ 0xff ] 0x30000d7c [ 0xff ] 0x30000d7d [ 0xff ] 0x30000daa [ 0xff ] 0x30000dab [ 0xff ] 0x30000dac [ 0xff ] 0x30000dad [ 0xff ] 0x30000dae [ 0xff ] 0x30000daf [ 0xff ] 0x30000db0 [ 0xff ] 0x30000db1 [ 0xff ] 0x30000db2 [ 0xff ] 0x30000db3 [ 0xff ] 0x30000db4 [ 0xff ] 0x30000db5 [ 0xff ] 0x30000db6 [ 0xff ] 0x30000db7 [ 0xff ] 0x30000db8 [ 0xff ] 0x30000db9 [ 0xff ] 0x30000dba [ 0xff ] 0x30000dbb [ 0xff ] 0x30000dbc [ 0xff ] 0x30000dbd [ 0xff ] 0x30000dbe [ 0xff ] 0x30000dbf [ 0xff ] 0x30000dc0 [ 0xff ] 0x30000dc1 [ 0xff ] 0x30000dc2 [ 0xff ] 0x30000dc3 [ 0xff ] 0x30000dc4 [ 0xff ] 0x30000dc5 [ 0xff ] 0x30000dc6 [ 0xff ] 0x30000dc7 [ 0xff ] 0x30000dc8 [ 0xff ] 0x30000dc9 [ 0xff ] 0x30000dca [ 0xff ] 0x30000dcb [ 0xff ] 0x30000dcc [ 0xff ] 0x30000dcd [ 0xff ] 0x30000dce [ 0xff ] 0x30000dcf [ 0xff ] 0x30000dd0 [ 0xff ] 0x30000dd1 [ 0xff ] 0x30000dd2 [ 0xff ] 0x30000dd3 [ 0xff ] 0x30000dd4 [ 0xff ] 0x30000dd5 [ 0xff ] 0x30000dd6 [ 0xff ] 0x30000dd7 [ 0xff ] 0x30000dd8 [ 0xff ] 0x30000dd9 [ 0xff ] 0x30000dda [ 0xff ] 0x30000ddc [ 0xff ] 0x30000ddd [ 0xff ] 0x30000dde [ 0xff ] 0x30000ddf [ 0xff ] 0x30000de0 [ 0x0 ] 0x30000de1 [ 0xff ] 0x30000de2 [ 0xff ] 0x30000de3 [ 0xff ] 0x30000de4 [ 0xff ] 0x30000de5 [ 0xff ] 0x30000de6 [ 0xff ] 0x30000de7 [ 0xff ] 0x30000de8 [ 0xff ] 0x30000de9 [ 0xff ] 0x30000dea [ 0xff ] 0x30000deb [ 0xff ] 0x30000dec [ 0xff ] 0x30000ded [ 0xff ] 0x30000dee [ 0xff ] 0x30000def [ 0xff ] 0x30000df0 [ 0xff ] 0x30000df1 [ 0xff ] 0x30000df2 [ 0xff ] 0x30000df3 [ 0xff ] 0x30000df4 [ 0xff ] 0x30000df5 [ 0xff ] 0x30000df6 [ 0xff ] 0x30000df7 [ 0xff ] 0x30000df8 [ 0xff ] 0x30000df9 [ 0xff ] 0x30000dfa [ 0xff ] 0x30000dfb [ 0xff ] 0x30000dfc [ 0xff ] 0x30000dfd [ 0xff ] 0x30000dfe [ 0xff ] 0x30000dff [ 0xff ] 0x30000e00 [ 0xff ] 0x30000e01 [ 0xff ] 0x30000e02 [ 0xff ] 0x30000e03 [ 0xff ] 0x30000e04 [ 0xff ] 0x30000e05 [ 0xff ] 0x30000e06 [ 0xff ] 0x30000e07 [ 0xff ] 0x30000e08 [ 0xff ] 0x30000e09 [ 0xff ] 0x30000e0a [ 0xff ] 0x30000e0b [ 0xff ] 0x30000e0c [ 0xff ] 0x30000e0e [ 0x0 ] 0x3003ef96 [ 0x0 ] 0x3001f7b2 [ 0x0 ] 0x3001f7e4 [ 0x0 ] 0x3001f7e5 [ 0xff ] 0x3001f7e6 [ 0x0 ] 0x3001f7e7 [ 0xff ] 0x3001f7e8 [ 0xff ] 0x3001f7e9 [ 0xff ] 0x3001f7ea [ 0xff ] 0x3001f7eb [ 0xff ] 0x3001f7ec [ 0xff ] 0x3001f7ed [ 0x0 ] 0x3001f7ee [ 0xff ] 0x3001f7ef [ 0xff ] [UAF-REPORT] Potential Use-after-free (UAF) at 0x11cdd: mov rax, qword ptr [rax] +Try to use memory at 0x30000d02 - 0x30000d09 +Allocated memory range is 0x300008c2 - 0x300018ca +Allocated memory at 0x14d14 and Freed at 0x14d89 + +Recent 200 emulated instructions: +0xdf4a: mov dword ptr [rbp - 0x268], 0 +0xdf54: mov ecx, dword ptr [rbp - 0x23c] +0xdf5a: and ecx, 0x10 +0xdf5d: mov dword ptr [rbp - 0x26c], ecx +0xdf63: mov ecx, dword ptr [rbp - 0x23c] +0xdf69: and ecx, 8 +0xdf6c: mov dword ptr [rbp - 0x270], ecx +0xdf72: mov ecx, dword ptr [rbp - 0x23c] +0xdf78: and ecx, 4 +0xdf7b: mov dword ptr [rbp - 0x274], ecx +0xdf81: mov ecx, dword ptr [rbp - 0x23c] +0xdf87: and ecx, 1 +0xdf8a: mov dword ptr [rbp - 0x278], ecx +0xdf90: mov ecx, dword ptr [rbp - 0x23c] +0xdf96: and ecx, 2 +0xdf99: mov dword ptr [rbp - 0x27c], ecx +0xdf9f: cmp dword ptr [rbp - 0x274], 0 +0xdfa6: mov byte ptr [rbp - 0x291], al +0xdfac: je 0xdff5 +0xdfae: cmp dword ptr [rbp - 0x25c], 0x4000 +0xdfb8: mov al, 1 +0xdfba: mov byte ptr [rbp - 0x292], al +0xdfc0: je 0xdfe9 +0xdfc2: cmp dword ptr [rbp - 0x25c], 0x800 +0xdfcc: mov al, 1 +0xdfce: mov byte ptr [rbp - 0x292], al +0xdfd4: je 0xdfe9 +0xdfd6: cmp dword ptr [rbp - 0x25c], 0x80000 +0xdfe0: sete al +0xdfe3: mov byte ptr [rbp - 0x292], al +0xdfe9: mov al, byte ptr [rbp - 0x292] +0xdfef: mov byte ptr [rbp - 0x291], al +0xdff5: mov al, byte ptr [rbp - 0x291] +0xdffb: and al, 1 +0xdffd: movzx ecx, al +0xe000: mov dword ptr [rbp - 0x280], ecx +0xe006: mov rdx, qword ptr [rbp - 0x230] +0xe00d: mov qword ptr [rbp - 0x288], rdx +0xe014: mov ecx, dword ptr [rip + 0x30bff6] +0xe01a: mov dword ptr [rbp - 0x298], ecx +0xe020: call 0xb2230 +0xb2230: push rbp +0xb2231: mov rbp, rsp +0xb2234: sub rsp, 0x120 +0xb223b: mov rax, qword ptr fs:[0x28] +0xb2244: mov qword ptr [rbp - 8], rax +0xb2248: lea rdi, qword ptr [rbp - 0x114] +0xb224f: call 0x7f40 +0xb2254: mov dword ptr [rbp - 0x118], eax +0xb225a: cmp dword ptr [rbp - 0x118], 0 +0xb2261: je 0xb229d +0xb229d: mov eax, dword ptr [rbp - 0x114] +0xb22a3: mov rcx, qword ptr fs:[0x28] +0xb22ac: mov rdx, qword ptr [rbp - 8] +0xb22b0: cmp rcx, rdx +0xb22b3: mov dword ptr [rbp - 0x120], eax +0xb22b9: jne 0xb22ca +0xb22bb: mov eax, dword ptr [rbp - 0x120] +0xb22c1: add rsp, 0x120 +0xb22c8: pop rbp +0xb22c9: ret +0xe025: mov ecx, dword ptr [rbp - 0x298] +0xe02b: cmp ecx, eax +0xe02d: je 0xe045 +0xe045: xor esi, esi +0xe047: mov rax, qword ptr [rbp - 0x250] +0xe04e: mov rdi, rax +0xe051: mov edx, 0x70 +0xe056: call 0xbf0dd +0xbf0dd: push rbp +0xbf0de: mov rbp, rsp +0xbf0e1: sub rsp, 0x20 +0xbf0e5: mov qword ptr [rbp - 8], rdi +0xbf0e9: mov dword ptr [rbp - 0xc], esi +0xbf0ec: mov qword ptr [rbp - 0x18], rdx +0xbf0f0: mov eax, dword ptr [rbp - 0xc] +0xbf0f3: cdqe +0xbf0f5: mov rcx, rax +0xbf0f8: mov rdx, qword ptr [rbp - 0x18] +0xbf0fc: mov rax, qword ptr [rbp - 8] +0xbf100: mov rsi, rcx +0xbf103: mov rdi, rax +0xbf106: call 0xc69c0 +0xc69c0: push rsi +0xc69c1: lea rax, qword ptr [rip + 0x254440] +0xc69c8: mov ecx, dword ptr [rax] +0xc69ca: and ecx, 0x9d97ff +0xc69d0: cmp ecx, 0x9d97ff +0xc69d6: jne 0xc69e1 +0xc69e1: lea rax, qword ptr [rip + 0x254420] +0xc69e8: mov cl, byte ptr [rax] +0xc69ea: and cl, 0x7f +0xc69ed: cmp cl, 0x7f +0xc69f0: jne 0xc69fb +0xc69f2: add rsp, 8 +0xc69f6: jmp 0xc69a0 +0xc69a0: jmp 0xd6150 +0xd6150: cmp rdx, 1 +0xd6154: mov rax, rdi +0xd6157: jne 0xd615d +0xd615d: movabs r9, 0x101010101010101 +0xd6167: mov r8, rdx +0xd616a: movzx rdx, sil +0xd616e: imul rdx, r9 +0xd6172: cmp r8, 0x41 +0xd6176: jge 0xd6580 +0xd6580: cmp dword ptr [rip + 0x242a39], 2 +0xd6587: jl 0xd6c70 +0xd658d: movq xmm0, rdx +0xd6592: lea r11, qword ptr [rip + 0x37] +0xd6599: punpcklqdq xmm0, xmm0 +0xd659d: mov r10, 0x10 +0xd65a4: mov r9, rdi +0xd65a7: and r9, 0xf +0xd65ab: sub r10, r9 +0xd65ae: and r10, 0xf +0xd65b2: add rdi, r10 +0xd65b5: sub r8, r10 +0xd65b8: mov rcx, qword ptr [r11 + r10*8] +0xd65bc: lea r11, qword ptr [rcx + r11] +0xd65c0: jmp r11 +0xd6682: mov word ptr [rdi - 2], dx +0xd6686: jmp 0xd66ac +0xd66ac: lea r9, qword ptr [rip + 0x67d] +0xd66b3: cmp r8, 0xb0 +0xd66ba: jge 0xd6b99 +0xd66c0: add rdi, r8 +0xd66c3: mov rcx, qword ptr [r9 + r8*8] +0xd66c7: lea r9, qword ptr [rcx + r9] +0xd66cb: jmp r9 +0xd6b19: movdqa xmmword ptr [rdi - 0x6e], xmm0 +0xd6b1e: movdqa xmmword ptr [rdi - 0x5e], xmm0 +0xd6b23: movdqa xmmword ptr [rdi - 0x4e], xmm0 +0xd6b28: movdqa xmmword ptr [rdi - 0x3e], xmm0 +0xd6b2d: movdqa xmmword ptr [rdi - 0x2e], xmm0 +0xd6b32: movdqa xmmword ptr [rdi - 0x1e], xmm0 +0xd6b37: mov qword ptr [rdi - 0xe], rdx +0xd6b3b: mov dword ptr [rdi - 6], edx +0xd6b3e: mov word ptr [rdi - 2], dx +0xd6b42: ret 0 +0xbf10b: leave +0xbf10c: ret +0xe05b: cmp dword ptr [rbp - 0x25c], 0x100 +0xe065: jne 0xe0db +0xe067: mov rdi, qword ptr [rbp - 0x288] +0xe06e: mov esi, dword ptr [rbp - 0x23c] +0xe074: call 0x11c60 +0x11c60: push rbp +0x11c61: mov rbp, rsp +0x11c64: sub rsp, 0xd0 +0x11c6b: mov rax, qword ptr fs:[0x28] +0x11c74: mov qword ptr [rbp - 8], rax +0x11c78: mov qword ptr [rbp - 0xa0], rdi +0x11c7f: mov dword ptr [rbp - 0xa4], esi +0x11c85: mov qword ptr [rbp - 0xb0], 0 +0x11c90: mov rax, qword ptr [rip + 0x305841] +0x11c97: mov rdi, qword ptr [rbp - 0xa0] +0x11c9e: lea rsi, qword ptr [rbp - 0x98] +0x11ca5: call rax +0xb2710: push rbp +0xb2711: mov rbp, rsp +0xb2714: sub rsp, 0x140 +0xb271b: mov rax, qword ptr fs:[0x28] +0xb2724: mov qword ptr [rbp - 8], rax +0xb2728: mov qword ptr [rbp - 0x120], rdi +0xb272f: mov qword ptr [rbp - 0x128], rsi +0xb2736: mov rsi, qword ptr [rbp - 0x120] +0xb273d: mov rdx, qword ptr [rbp - 0x128] +0xb2744: lea rdi, qword ptr [rbp - 0x114] +0xb274b: mov ecx, 0x90 +0xb2750: call 0x77e0 +0xb2755: mov dword ptr [rbp - 0x12c], eax +0xb275b: cmp dword ptr [rbp - 0x12c], 0 +0xb2762: je 0xb279e +0xb279e: mov eax, dword ptr [rbp - 0x114] +0xb27a4: mov rcx, qword ptr fs:[0x28] +0xb27ad: mov rdx, qword ptr [rbp - 8] +0xb27b1: cmp rcx, rdx +0xb27b4: mov dword ptr [rbp - 0x134], eax +0xb27ba: jne 0xb27cb +0xb27bc: mov eax, dword ptr [rbp - 0x134] +0xb27c2: add rsp, 0x140 +0xb27c9: pop rbp +0xb27ca: ret +0x11ca7: xor ecx, ecx +0x11ca9: cmp ecx, eax +0x11cab: jne 0x11de9 +0x11cb1: call 0x10830 +0x10830: push rbp +0x10831: mov rbp, rsp +0x10834: pop rbp +0x10835: ret +0x11cb6: mov rax, qword ptr [rip + 0x30835b] +0x11cbd: mov qword ptr [rbp - 0xb8], rax +0x11cc4: xor eax, eax +0x11cc6: cmp qword ptr [rbp - 0xb8], 0 +0x11cce: mov byte ptr [rbp - 0xc1], al +0x11cd4: je 0x11d18 +0x11cd6: mov rax, qword ptr [rbp - 0xb8] +0x11cdd: mov rax, qword ptr [rax] +Seed information: +0x30000000 [ 0x20 ] 0x30000001 [ 0xff ] 0x30000002 [ 0xff ] 0x30000003 [ 0x0 ] 0x30000004 [ 0xff ] 0x30000005 [ 0xff ] 0x30000006 [ 0xff ] 0x30000007 [ 0xff ] 0x30000008 [ 0xff ] 0x30000009 [ 0xff ] 0x3000000a [ 0xff ] 0x3000000b [ 0xff ] 0x3000000c [ 0xff ] 0x3000000d [ 0xff ] 0x3000000e [ 0xff ] 0x3000000f [ 0xff ] 0x30000010 [ 0xff ] 0x30000011 [ 0xff ] 0x30000012 [ 0xff ] 0x30000013 [ 0xff ] 0x30000014 [ 0xff ] 0x30000015 [ 0xff ] 0x30000016 [ 0xff ] 0x30000017 [ 0xff ] 0x30000018 [ 0xff ] 0x30000019 [ 0xff ] 0x3000001a [ 0xff ] 0x3000001b [ 0xff ] 0x3000001c [ 0xff ] 0x3000001d [ 0xff ] 0x3000001e [ 0xff ] 0x3000001f [ 0xff ] 0x30000020 [ 0xff ] 0x30000021 [ 0xff ] 0x30000022 [ 0xff ] 0x30000023 [ 0xff ] 0x30000024 [ 0xff ] 0x30000025 [ 0xff ] 0x30000026 [ 0xff ] 0x30000027 [ 0xff ] 0x30000028 [ 0xff ] 0x30000029 [ 0xff ] 0x3000002a [ 0xff ] 0x3000002b [ 0xff ] 0x3000002c [ 0xff ] 0x3000002d [ 0xff ] 0x3000002e [ 0xff ] 0x3000002f [ 0xff ] 0x30000030 [ 0xff ] 0x30000031 [ 0xff ] 0x30000032 [ 0x0 ] 0x30000a32 [ 0xff ] 0x30000a33 [ 0xff ] 0x30000a34 [ 0xff ] 0x30000a35 [ 0xff ] 0x30000a36 [ 0xff ] 0x30000a37 [ 0xff ] 0x30000a38 [ 0xff ] 0x30000a39 [ 0xff ] 0x30000a3a [ 0xff ] 0x30000a3b [ 0xff ] 0x30000a3c [ 0xff ] 0x30000a3d [ 0xff ] 0x30000a3e [ 0xff ] 0x30000a3f [ 0xff ] 0x30000a40 [ 0xff ] 0x30000a41 [ 0xff ] 0x30000a42 [ 0xff ] 0x30000a43 [ 0xff ] 0x30000a44 [ 0xff ] 0x30000a45 [ 0xff ] 0x30000a46 [ 0xff ] 0x30000a47 [ 0xff ] 0x30000a48 [ 0xff ] 0x30000a49 [ 0xff ] 0x30000a4a [ 0xff ] 0x30000a4b [ 0xff ] 0x30000a4c [ 0xff ] 0x30000a4d [ 0xff ] 0x30000a4e [ 0xff ] 0x30000a4f [ 0xff ] 0x30000a50 [ 0xff ] 0x30000a51 [ 0xff ] 0x30000a52 [ 0xff ] 0x30000a53 [ 0xff ] 0x30000a54 [ 0xff ] 0x30000a55 [ 0xff ] 0x30000a56 [ 0xff ] 0x30000a57 [ 0xff ] 0x30000a58 [ 0xff ] 0x30000a59 [ 0xff ] 0x30000a5a [ 0xff ] 0x30000a5b [ 0xff ] 0x30000a5c [ 0xff ] 0x30000a5d [ 0xff ] 0x30000a5e [ 0xff ] 0x30000a5f [ 0xff ] 0x30000a60 [ 0xff ] 0x30000a61 [ 0xff ] 0x30000a62 [ 0xff ] 0x30000a64 [ 0x3a ] 0x30000a65 [ 0xff ] 0x30000a66 [ 0xff ] 0x30000a67 [ 0xff ] 0x30000a68 [ 0xff ] 0x30000a69 [ 0xff ] 0x30000a6a [ 0xff ] 0x30000a6b [ 0xff ] 0x30000a6c [ 0xff ] 0x30000a6d [ 0xff ] 0x30000a6e [ 0xff ] 0x30000a6f [ 0xff ] 0x30000a70 [ 0xff ] 0x30000a71 [ 0xff ] 0x30000a72 [ 0xff ] 0x30000a73 [ 0xff ] 0x30000a74 [ 0xff ] 0x30000a75 [ 0xff ] 0x30000a76 [ 0xff ] 0x30000a77 [ 0xff ] 0x30000a78 [ 0xff ] 0x30000a79 [ 0xff ] 0x30000a7a [ 0xff ] 0x30000a7b [ 0xff ] 0x30000a7c [ 0xff ] 0x30000a7d [ 0xff ] 0x30000a7e [ 0xff ] 0x30000a7f [ 0xff ] 0x30000a80 [ 0xff ] 0x30000a81 [ 0xff ] 0x30000a82 [ 0xff ] 0x30000a83 [ 0xff ] 0x30000a84 [ 0xff ] 0x30000a85 [ 0xff ] 0x30000a86 [ 0xff ] 0x30000a87 [ 0xff ] 0x30000a88 [ 0xff ] 0x30000a89 [ 0xff ] 0x30000a8a [ 0xff ] 0x30000a8b [ 0xff ] 0x30000a8c [ 0xff ] 0x30000a8d [ 0xff ] 0x30000a8e [ 0xff ] 0x30000a8f [ 0xff ] 0x30000a90 [ 0xff ] 0x30000a91 [ 0xff ] 0x30000a92 [ 0xff ] 0x30000a93 [ 0xff ] 0x30000a94 [ 0xff ] 0x30000a95 [ 0xff ] 0x30000a96 [ 0x0 ] 0x30001b86 [ 0xff ] 0x30001b87 [ 0xff ] 0x30001b88 [ 0xff ] 0x30001b89 [ 0xff ] 0x30001b8a [ 0xff ] 0x30001b8b [ 0xff ] 0x30001b8c [ 0xff ] 0x30001b8d [ 0xff ] 0x30001b8e [ 0xff ] 0x30001b8f [ 0xff ] 0x30001b90 [ 0xff ] 0x30001b91 [ 0xff ] 0x30001b92 [ 0xff ] 0x30001b93 [ 0xff ] 0x30001b94 [ 0xff ] 0x30001b95 [ 0xff ] 0x30001b96 [ 0xff ] 0x30001b97 [ 0xff ] 0x30001b98 [ 0xff ] 0x30001b99 [ 0xff ] 0x30001b9a [ 0xff ] 0x30001b9b [ 0xff ] 0x30001b9c [ 0xff ] 0x30001b9d [ 0xff ] 0x30001b9e [ 0xff ] 0x30001b9f [ 0xff ] 0x30001ba0 [ 0xff ] 0x30001ba1 [ 0xff ] 0x30001ba2 [ 0xff ] 0x30001ba3 [ 0xff ] 0x30001ba4 [ 0xff ] 0x30001ba5 [ 0xff ] 0x30001ba6 [ 0xff ] 0x30001ba7 [ 0xff ] 0x30001ba8 [ 0xff ] 0x30001ba9 [ 0xff ] 0x30001baa [ 0xff ] 0x30001bab [ 0xff ] 0x30001bac [ 0xff ] 0x30001bad [ 0xff ] 0x30001bae [ 0xff ] 0x30001baf [ 0xff ] 0x30001bb0 [ 0xff ] 0x30001bb1 [ 0xff ] 0x30001bb2 [ 0xff ] 0x30001bb3 [ 0xff ] 0x30001bb4 [ 0xff ] 0x30001bb5 [ 0xff ] 0x30001bb6 [ 0xff ] 0x30001bb8 [ 0x0 ] 0x3000147e [ 0xff ] 0x3000147f [ 0xff ] 0x30001480 [ 0xff ] 0x30001481 [ 0xff ] 0x30001482 [ 0xff ] 0x30001483 [ 0xff ] 0x30001484 [ 0xff ] 0x30001485 [ 0xff ] 0x30001486 [ 0xff ] 0x30001487 [ 0xff ] 0x30001488 [ 0xff ] 0x30001489 [ 0xff ] 0x3000148a [ 0xff ] 0x3000148b [ 0xff ] 0x3000148c [ 0xff ] 0x3000148d [ 0xff ] 0x3000148e [ 0xff ] 0x3000148f [ 0xff ] 0x30001490 [ 0xff ] 0x30001491 [ 0xff ] 0x30001492 [ 0xff ] 0x30001493 [ 0xff ] 0x30001494 [ 0xff ] 0x30001495 [ 0xff ] 0x30001496 [ 0xff ] 0x30001497 [ 0xff ] 0x30001498 [ 0xff ] 0x30001499 [ 0xff ] 0x3000149a [ 0xff ] 0x3000149b [ 0xff ] 0x3000149c [ 0xff ] 0x3000149d [ 0xff ] 0x3000149e [ 0xff ] 0x3000149f [ 0xff ] 0x300014a0 [ 0xff ] 0x300014a1 [ 0xff ] 0x300014a2 [ 0xff ] 0x300014a3 [ 0xff ] 0x300014a4 [ 0xff ] 0x300014a5 [ 0xff ] 0x300014a6 [ 0xff ] 0x300014a7 [ 0xff ] 0x300014a8 [ 0xff ] 0x300014a9 [ 0xff ] 0x300014aa [ 0xff ] 0x300014ab [ 0xff ] 0x300014ac [ 0xff ] 0x300014ad [ 0xff ] 0x300014ae [ 0xff ] 0x300014b0 [ 0x0 ] 0x300204fe [ 0x0 ] 0x30000d4c [ 0xff ] 0x30000d4d [ 0xff ] 0x30000d4e [ 0xff ] 0x30000d4f [ 0xff ] 0x30000d50 [ 0xff ] 0x30000d51 [ 0xff ] 0x30000d52 [ 0xff ] 0x30000d53 [ 0xff ] 0x30000d54 [ 0xff ] 0x30000d55 [ 0xff ] 0x30000d56 [ 0xff ] 0x30000d57 [ 0xff ] 0x30000d58 [ 0xff ] 0x30000d59 [ 0xff ] 0x30000d5a [ 0xff ] 0x30000d5b [ 0xff ] 0x30000d5c [ 0xff ] 0x30000d5d [ 0xff ] 0x30000d5e [ 0xff ] 0x30000d5f [ 0xff ] 0x30000d60 [ 0xff ] 0x30000d61 [ 0xff ] 0x30000d62 [ 0xff ] 0x30000d63 [ 0xff ] 0x30000d64 [ 0xff ] 0x30000d65 [ 0xff ] 0x30000d66 [ 0xff ] 0x30000d67 [ 0xff ] 0x30000d68 [ 0xff ] 0x30000d69 [ 0xff ] 0x30000d6a [ 0xff ] 0x30000d6b [ 0xff ] 0x30000d6c [ 0xff ] 0x30000d6d [ 0xff ] 0x30000d6e [ 0xff ] 0x30000d6f [ 0xff ] 0x30000d70 [ 0x0 ] 0x30000d71 [ 0xff ] 0x30000d72 [ 0xff ] 0x30000d73 [ 0xff ] 0x30000d74 [ 0xff ] 0x30000d75 [ 0xff ] 0x30000d76 [ 0xff ] 0x30000d77 [ 0xff ] 0x30000d78 [ 0xff ] 0x30000d79 [ 0xff ] 0x30000d7a [ 0xff ] 0x30000d7b [ 0xff ] 0x30000d7c [ 0xff ] 0x30000d7d [ 0xff ] 0x30000daa [ 0xff ] 0x30000dab [ 0xff ] 0x30000dac [ 0xff ] 0x30000dad [ 0xff ] 0x30000dae [ 0xff ] 0x30000daf [ 0xff ] 0x30000db0 [ 0xff ] 0x30000db1 [ 0xff ] 0x30000db2 [ 0xff ] 0x30000db3 [ 0xff ] 0x30000db4 [ 0xff ] 0x30000db5 [ 0xff ] 0x30000db6 [ 0xff ] 0x30000db7 [ 0xff ] 0x30000db8 [ 0xff ] 0x30000db9 [ 0xff ] 0x30000dba [ 0xff ] 0x30000dbb [ 0xff ] 0x30000dbc [ 0xff ] 0x30000dbd [ 0xff ] 0x30000dbe [ 0xff ] 0x30000dbf [ 0xff ] 0x30000dc0 [ 0xff ] 0x30000dc1 [ 0xff ] 0x30000dc2 [ 0xff ] 0x30000dc3 [ 0xff ] 0x30000dc4 [ 0xff ] 0x30000dc5 [ 0xff ] 0x30000dc6 [ 0xff ] 0x30000dc7 [ 0xff ] 0x30000dc8 [ 0xff ] 0x30000dc9 [ 0xff ] 0x30000dca [ 0xff ] 0x30000dcb [ 0xff ] 0x30000dcc [ 0xff ] 0x30000dcd [ 0xff ] 0x30000dce [ 0xff ] 0x30000dcf [ 0xff ] 0x30000dd0 [ 0xff ] 0x30000dd1 [ 0xff ] 0x30000dd2 [ 0xff ] 0x30000dd3 [ 0xff ] 0x30000dd4 [ 0xff ] 0x30000dd5 [ 0xff ] 0x30000dd6 [ 0xff ] 0x30000dd7 [ 0xff ] 0x30000dd8 [ 0xff ] 0x30000dd9 [ 0xff ] 0x30000dda [ 0xff ] 0x30000ddc [ 0xff ] 0x30000ddd [ 0xff ] 0x30000dde [ 0xff ] 0x30000ddf [ 0xff ] 0x30000de0 [ 0x0 ] 0x30000de1 [ 0xff ] 0x30000de2 [ 0xff ] 0x30000de3 [ 0xff ] 0x30000de4 [ 0xff ] 0x30000de5 [ 0xff ] 0x30000de6 [ 0xff ] 0x30000de7 [ 0xff ] 0x30000de8 [ 0xff ] 0x30000de9 [ 0xff ] 0x30000dea [ 0xff ] 0x30000deb [ 0xff ] 0x30000dec [ 0xff ] 0x30000ded [ 0xff ] 0x30000dee [ 0xff ] 0x30000def [ 0xff ] 0x30000df0 [ 0xff ] 0x30000df1 [ 0xff ] 0x30000df2 [ 0xff ] 0x30000df3 [ 0xff ] 0x30000df4 [ 0xff ] 0x30000df5 [ 0xff ] 0x30000df6 [ 0xff ] 0x30000df7 [ 0xff ] 0x30000df8 [ 0xff ] 0x30000df9 [ 0xff ] 0x30000dfa [ 0xff ] 0x30000dfb [ 0xff ] 0x30000dfc [ 0xff ] 0x30000dfd [ 0xff ] 0x30000dfe [ 0xff ] 0x30000dff [ 0xff ] 0x30000e00 [ 0xff ] 0x30000e01 [ 0xff ] 0x30000e02 [ 0xff ] 0x30000e03 [ 0xff ] 0x30000e04 [ 0xff ] 0x30000e05 [ 0xff ] 0x30000e06 [ 0xff ] 0x30000e07 [ 0xff ] 0x30000e08 [ 0xff ] 0x30000e09 [ 0xff ] 0x30000e0a [ 0xff ] 0x30000e0b [ 0xff ] 0x30000e0c [ 0xff ] 0x30000e0e [ 0x0 ] 0x30002634 [ 0x0 ] 0x30002635 [ 0xff ] 0x30002636 [ 0xff ] 0x30002637 [ 0xff ] 0x30002638 [ 0xff ] 0x30002639 [ 0xff ] 0x3000263a [ 0xff ] 0x3000263b [ 0xff ] 0x3000263c [ 0xff ] 0x3000263d [ 0xff ] 0x3000263e [ 0xff ] 0x3000263f [ 0xff ] 0x3003ef96 [ 0x0 ] 0x3001f7b2 [ 0x0 ] 0x3001f7e4 [ 0x0 ] 0x3001f7e5 [ 0xff ] 0x3001f7e6 [ 0x0 ] 0x3001f7e7 [ 0xff ] 0x3001f7e8 [ 0xff ] 0x3001f7e9 [ 0xff ] 0x3001f7ea [ 0xff ] 0x3001f7eb [ 0xff ] 0x3001f7ec [ 0xff ] 0x3001f7ed [ 0x0 ] 0x3001f7ee [ 0xff ] 0x3001f7ef [ 0xff ] [UAF-REPORT] Potential Use-after-free (UAF) at 0x11d2b: mov rax, qword ptr [rax + 0x38] +Try to use memory at 0x30000d3a - 0x30000d41 +Allocated memory range is 0x300008c2 - 0x300018ca +Allocated memory at 0x14d14 and Freed at 0x14d89 + +Recent 200 emulated instructions: +0xdf87: and ecx, 1 +0xdf8a: mov dword ptr [rbp - 0x278], ecx +0xdf90: mov ecx, dword ptr [rbp - 0x23c] +0xdf96: and ecx, 2 +0xdf99: mov dword ptr [rbp - 0x27c], ecx +0xdf9f: cmp dword ptr [rbp - 0x274], 0 +0xdfa6: mov byte ptr [rbp - 0x291], al +0xdfac: je 0xdff5 +0xdfae: cmp dword ptr [rbp - 0x25c], 0x4000 +0xdfb8: mov al, 1 +0xdfba: mov byte ptr [rbp - 0x292], al +0xdfc0: je 0xdfe9 +0xdfc2: cmp dword ptr [rbp - 0x25c], 0x800 +0xdfcc: mov al, 1 +0xdfce: mov byte ptr [rbp - 0x292], al +0xdfd4: je 0xdfe9 +0xdfd6: cmp dword ptr [rbp - 0x25c], 0x80000 +0xdfe0: sete al +0xdfe3: mov byte ptr [rbp - 0x292], al +0xdfe9: mov al, byte ptr [rbp - 0x292] +0xdfef: mov byte ptr [rbp - 0x291], al +0xdff5: mov al, byte ptr [rbp - 0x291] +0xdffb: and al, 1 +0xdffd: movzx ecx, al +0xe000: mov dword ptr [rbp - 0x280], ecx +0xe006: mov rdx, qword ptr [rbp - 0x230] +0xe00d: mov qword ptr [rbp - 0x288], rdx +0xe014: mov ecx, dword ptr [rip + 0x30bff6] +0xe01a: mov dword ptr [rbp - 0x298], ecx +0xe020: call 0xb2230 +0xb2230: push rbp +0xb2231: mov rbp, rsp +0xb2234: sub rsp, 0x120 +0xb223b: mov rax, qword ptr fs:[0x28] +0xb2244: mov qword ptr [rbp - 8], rax +0xb2248: lea rdi, qword ptr [rbp - 0x114] +0xb224f: call 0x7f40 +0xb2254: mov dword ptr [rbp - 0x118], eax +0xb225a: cmp dword ptr [rbp - 0x118], 0 +0xb2261: je 0xb229d +0xb229d: mov eax, dword ptr [rbp - 0x114] +0xb22a3: mov rcx, qword ptr fs:[0x28] +0xb22ac: mov rdx, qword ptr [rbp - 8] +0xb22b0: cmp rcx, rdx +0xb22b3: mov dword ptr [rbp - 0x120], eax +0xb22b9: jne 0xb22ca +0xb22bb: mov eax, dword ptr [rbp - 0x120] +0xb22c1: add rsp, 0x120 +0xb22c8: pop rbp +0xb22c9: ret +0xe025: mov ecx, dword ptr [rbp - 0x298] +0xe02b: cmp ecx, eax +0xe02d: je 0xe045 +0xe045: xor esi, esi +0xe047: mov rax, qword ptr [rbp - 0x250] +0xe04e: mov rdi, rax +0xe051: mov edx, 0x70 +0xe056: call 0xbf0dd +0xbf0dd: push rbp +0xbf0de: mov rbp, rsp +0xbf0e1: sub rsp, 0x20 +0xbf0e5: mov qword ptr [rbp - 8], rdi +0xbf0e9: mov dword ptr [rbp - 0xc], esi +0xbf0ec: mov qword ptr [rbp - 0x18], rdx +0xbf0f0: mov eax, dword ptr [rbp - 0xc] +0xbf0f3: cdqe +0xbf0f5: mov rcx, rax +0xbf0f8: mov rdx, qword ptr [rbp - 0x18] +0xbf0fc: mov rax, qword ptr [rbp - 8] +0xbf100: mov rsi, rcx +0xbf103: mov rdi, rax +0xbf106: call 0xc69c0 +0xc69c0: push rsi +0xc69c1: lea rax, qword ptr [rip + 0x254440] +0xc69c8: mov ecx, dword ptr [rax] +0xc69ca: and ecx, 0x9d97ff +0xc69d0: cmp ecx, 0x9d97ff +0xc69d6: jne 0xc69e1 +0xc69e1: lea rax, qword ptr [rip + 0x254420] +0xc69e8: mov cl, byte ptr [rax] +0xc69ea: and cl, 0x7f +0xc69ed: cmp cl, 0x7f +0xc69f0: jne 0xc69fb +0xc69f2: add rsp, 8 +0xc69f6: jmp 0xc69a0 +0xc69a0: jmp 0xd6150 +0xd6150: cmp rdx, 1 +0xd6154: mov rax, rdi +0xd6157: jne 0xd615d +0xd615d: movabs r9, 0x101010101010101 +0xd6167: mov r8, rdx +0xd616a: movzx rdx, sil +0xd616e: imul rdx, r9 +0xd6172: cmp r8, 0x41 +0xd6176: jge 0xd6580 +0xd6580: cmp dword ptr [rip + 0x242a39], 2 +0xd6587: jl 0xd6c70 +0xd658d: movq xmm0, rdx +0xd6592: lea r11, qword ptr [rip + 0x37] +0xd6599: punpcklqdq xmm0, xmm0 +0xd659d: mov r10, 0x10 +0xd65a4: mov r9, rdi +0xd65a7: and r9, 0xf +0xd65ab: sub r10, r9 +0xd65ae: and r10, 0xf +0xd65b2: add rdi, r10 +0xd65b5: sub r8, r10 +0xd65b8: mov rcx, qword ptr [r11 + r10*8] +0xd65bc: lea r11, qword ptr [rcx + r11] +0xd65c0: jmp r11 +0xd6682: mov word ptr [rdi - 2], dx +0xd6686: jmp 0xd66ac +0xd66ac: lea r9, qword ptr [rip + 0x67d] +0xd66b3: cmp r8, 0xb0 +0xd66ba: jge 0xd6b99 +0xd66c0: add rdi, r8 +0xd66c3: mov rcx, qword ptr [r9 + r8*8] +0xd66c7: lea r9, qword ptr [rcx + r9] +0xd66cb: jmp r9 +0xd6b19: movdqa xmmword ptr [rdi - 0x6e], xmm0 +0xd6b1e: movdqa xmmword ptr [rdi - 0x5e], xmm0 +0xd6b23: movdqa xmmword ptr [rdi - 0x4e], xmm0 +0xd6b28: movdqa xmmword ptr [rdi - 0x3e], xmm0 +0xd6b2d: movdqa xmmword ptr [rdi - 0x2e], xmm0 +0xd6b32: movdqa xmmword ptr [rdi - 0x1e], xmm0 +0xd6b37: mov qword ptr [rdi - 0xe], rdx +0xd6b3b: mov dword ptr [rdi - 6], edx +0xd6b3e: mov word ptr [rdi - 2], dx +0xd6b42: ret 0 +0xbf10b: leave +0xbf10c: ret +0xe05b: cmp dword ptr [rbp - 0x25c], 0x100 +0xe065: jne 0xe0db +0xe067: mov rdi, qword ptr [rbp - 0x288] +0xe06e: mov esi, dword ptr [rbp - 0x23c] +0xe074: call 0x11c60 +0x11c60: push rbp +0x11c61: mov rbp, rsp +0x11c64: sub rsp, 0xd0 +0x11c6b: mov rax, qword ptr fs:[0x28] +0x11c74: mov qword ptr [rbp - 8], rax +0x11c78: mov qword ptr [rbp - 0xa0], rdi +0x11c7f: mov dword ptr [rbp - 0xa4], esi +0x11c85: mov qword ptr [rbp - 0xb0], 0 +0x11c90: mov rax, qword ptr [rip + 0x305841] +0x11c97: mov rdi, qword ptr [rbp - 0xa0] +0x11c9e: lea rsi, qword ptr [rbp - 0x98] +0x11ca5: call rax +0xb2710: push rbp +0xb2711: mov rbp, rsp +0xb2714: sub rsp, 0x140 +0xb271b: mov rax, qword ptr fs:[0x28] +0xb2724: mov qword ptr [rbp - 8], rax +0xb2728: mov qword ptr [rbp - 0x120], rdi +0xb272f: mov qword ptr [rbp - 0x128], rsi +0xb2736: mov rsi, qword ptr [rbp - 0x120] +0xb273d: mov rdx, qword ptr [rbp - 0x128] +0xb2744: lea rdi, qword ptr [rbp - 0x114] +0xb274b: mov ecx, 0x90 +0xb2750: call 0x77e0 +0xb2755: mov dword ptr [rbp - 0x12c], eax +0xb275b: cmp dword ptr [rbp - 0x12c], 0 +0xb2762: je 0xb279e +0xb279e: mov eax, dword ptr [rbp - 0x114] +0xb27a4: mov rcx, qword ptr fs:[0x28] +0xb27ad: mov rdx, qword ptr [rbp - 8] +0xb27b1: cmp rcx, rdx +0xb27b4: mov dword ptr [rbp - 0x134], eax +0xb27ba: jne 0xb27cb +0xb27bc: mov eax, dword ptr [rbp - 0x134] +0xb27c2: add rsp, 0x140 +0xb27c9: pop rbp +0xb27ca: ret +0x11ca7: xor ecx, ecx +0x11ca9: cmp ecx, eax +0x11cab: jne 0x11de9 +0x11cb1: call 0x10830 +0x10830: push rbp +0x10831: mov rbp, rsp +0x10834: pop rbp +0x10835: ret +0x11cb6: mov rax, qword ptr [rip + 0x30835b] +0x11cbd: mov qword ptr [rbp - 0xb8], rax +0x11cc4: xor eax, eax +0x11cc6: cmp qword ptr [rbp - 0xb8], 0 +0x11cce: mov byte ptr [rbp - 0xc1], al +0x11cd4: je 0x11d18 +0x11cd6: mov rax, qword ptr [rbp - 0xb8] +0x11cdd: mov rax, qword ptr [rax] +0x11ce0: cmp rax, qword ptr [rbp - 0x98] +0x11ce7: mov cl, 1 +0x11ce9: mov byte ptr [rbp - 0xc2], cl +0x11cef: jne 0x11d0c +0x11d0c: mov al, byte ptr [rbp - 0xc2] +0x11d12: mov byte ptr [rbp - 0xc1], al +0x11d18: mov al, byte ptr [rbp - 0xc1] +0x11d1e: test al, 1 +0x11d20: jne 0x11d24 +0x11d24: mov rax, qword ptr [rbp - 0xb8] +0x11d2b: mov rax, qword ptr [rax + 0x38] +Seed information: +0x30000000 [ 0x80 ] 0x30000001 [ 0xff ] 0x30000002 [ 0xff ] 0x30000003 [ 0xff ] 0x30000004 [ 0xff ] 0x30000005 [ 0xff ] 0x30000006 [ 0xff ] 0x30000007 [ 0xff ] 0x30000008 [ 0xff ] 0x30000009 [ 0xff ] 0x3000000a [ 0xff ] 0x3000000b [ 0xff ] 0x3000000c [ 0xff ] 0x3000000d [ 0xff ] 0x3000000e [ 0x80 ] 0x3000000f [ 0xff ] 0x30000010 [ 0xff ] 0x30000011 [ 0xff ] 0x30000012 [ 0xff ] 0x30000013 [ 0xff ] 0x30000014 [ 0xff ] 0x30000015 [ 0xff ] 0x30000016 [ 0xff ] 0x30000017 [ 0xff ] 0x30000018 [ 0xff ] 0x30000019 [ 0xff ] 0x3000001a [ 0xff ] 0x3000001b [ 0xff ] 0x3000001c [ 0xff ] 0x3000001d [ 0xff ] 0x3000001e [ 0xff ] 0x3000001f [ 0xff ] 0x30000020 [ 0xff ] 0x30000021 [ 0xff ] 0x30000022 [ 0xff ] 0x30000023 [ 0xff ] 0x30000024 [ 0xff ] 0x30000025 [ 0xff ] 0x30000026 [ 0xff ] 0x30000027 [ 0xff ] 0x30000028 [ 0xff ] 0x30000029 [ 0xff ] 0x3000002a [ 0xff ] 0x3000002b [ 0xff ] 0x3000002c [ 0xff ] 0x3000002d [ 0xff ] 0x3000002e [ 0xff ] 0x3000002f [ 0xff ] 0x30000030 [ 0xff ] 0x30000031 [ 0xff ] 0x30000032 [ 0x0 ] 0x30000a32 [ 0xff ] 0x30000a33 [ 0xff ] 0x30000a34 [ 0xff ] 0x30000a35 [ 0xff ] 0x30000a36 [ 0xff ] 0x30000a37 [ 0xff ] 0x30000a38 [ 0xff ] 0x30000a39 [ 0xff ] 0x30000a3a [ 0xff ] 0x30000a3b [ 0xff ] 0x30000a3c [ 0xff ] 0x30000a3d [ 0xff ] 0x30000a3e [ 0xff ] 0x30000a3f [ 0xff ] 0x30000a40 [ 0xff ] 0x30000a41 [ 0xff ] 0x30000a42 [ 0xff ] 0x30000a43 [ 0xff ] 0x30000a44 [ 0xff ] 0x30000a45 [ 0xff ] 0x30000a46 [ 0xff ] 0x30000a47 [ 0xff ] 0x30000a48 [ 0xff ] 0x30000a49 [ 0xff ] 0x30000a4a [ 0xff ] 0x30000a4b [ 0xff ] 0x30000a4c [ 0xff ] 0x30000a4d [ 0xff ] 0x30000a4e [ 0xff ] 0x30000a4f [ 0xff ] 0x30000a50 [ 0xff ] 0x30000a51 [ 0xff ] 0x30000a52 [ 0xff ] 0x30000a53 [ 0xff ] 0x30000a54 [ 0xff ] 0x30000a55 [ 0xff ] 0x30000a56 [ 0xff ] 0x30000a57 [ 0xff ] 0x30000a58 [ 0xff ] 0x30000a59 [ 0xff ] 0x30000a5a [ 0xff ] 0x30000a5b [ 0xff ] 0x30000a5c [ 0xff ] 0x30000a5d [ 0xff ] 0x30000a5e [ 0xff ] 0x30000a5f [ 0xff ] 0x30000a60 [ 0xff ] 0x30000a61 [ 0xff ] 0x30000a62 [ 0xff ] 0x30000a64 [ 0x3a ] 0x30000a65 [ 0xff ] 0x30000a66 [ 0xff ] 0x30000a67 [ 0xff ] 0x30000a68 [ 0xff ] 0x30000a69 [ 0xff ] 0x30000a6a [ 0xff ] 0x30000a6b [ 0xff ] 0x30000a6c [ 0xff ] 0x30000a6d [ 0xff ] 0x30000a6e [ 0xff ] 0x30000a6f [ 0xff ] 0x30000a70 [ 0xff ] 0x30000a71 [ 0xff ] 0x30000a72 [ 0xff ] 0x30000a73 [ 0xff ] 0x30000a74 [ 0xff ] 0x30000a75 [ 0xff ] 0x30000a76 [ 0xff ] 0x30000a77 [ 0xff ] 0x30000a78 [ 0xff ] 0x30000a79 [ 0xff ] 0x30000a7a [ 0xff ] 0x30000a7b [ 0xff ] 0x30000a7c [ 0xff ] 0x30000a7d [ 0xff ] 0x30000a7e [ 0xff ] 0x30000a7f [ 0xff ] 0x30000a80 [ 0xff ] 0x30000a81 [ 0xff ] 0x30000a82 [ 0xff ] 0x30000a83 [ 0xff ] 0x30000a84 [ 0xff ] 0x30000a85 [ 0xff ] 0x30000a86 [ 0xff ] 0x30000a87 [ 0xff ] 0x30000a88 [ 0xff ] 0x30000a89 [ 0xff ] 0x30000a8a [ 0xff ] 0x30000a8b [ 0xff ] 0x30000a8c [ 0xff ] 0x30000a8d [ 0xff ] 0x30000a8e [ 0xff ] 0x30000a8f [ 0xff ] 0x30000a90 [ 0xff ] 0x30000a91 [ 0xff ] 0x30000a92 [ 0xff ] 0x30000a93 [ 0xff ] 0x30000a94 [ 0xff ] 0x30000a95 [ 0xff ] 0x30000a96 [ 0x0 ] 0x30001b86 [ 0xff ] 0x30001b87 [ 0xff ] 0x30001b88 [ 0xff ] 0x30001b89 [ 0xff ] 0x30001b8a [ 0xff ] 0x30001b8b [ 0xff ] 0x30001b8c [ 0xff ] 0x30001b8d [ 0xff ] 0x30001b8e [ 0xff ] 0x30001b8f [ 0xff ] 0x30001b90 [ 0xff ] 0x30001b91 [ 0xff ] 0x30001b92 [ 0xff ] 0x30001b93 [ 0xff ] 0x30001b94 [ 0xff ] 0x30001b95 [ 0xff ] 0x30001b96 [ 0xff ] 0x30001b97 [ 0xff ] 0x30001b98 [ 0xff ] 0x30001b99 [ 0xff ] 0x30001b9a [ 0xff ] 0x30001b9b [ 0xff ] 0x30001b9c [ 0xff ] 0x30001b9d [ 0xff ] 0x30001b9e [ 0xff ] 0x30001b9f [ 0xff ] 0x30001ba0 [ 0xff ] 0x30001ba1 [ 0xff ] 0x30001ba2 [ 0xff ] 0x30001ba3 [ 0xff ] 0x30001ba4 [ 0xff ] 0x30001ba5 [ 0xff ] 0x30001ba6 [ 0xff ] 0x30001ba7 [ 0xff ] 0x30001ba8 [ 0xff ] 0x30001ba9 [ 0xff ] 0x30001baa [ 0xff ] 0x30001bab [ 0xff ] 0x30001bac [ 0xff ] 0x30001bad [ 0xff ] 0x30001bae [ 0xff ] 0x30001baf [ 0xff ] 0x30001bb0 [ 0xff ] 0x30001bb1 [ 0xff ] 0x30001bb2 [ 0xff ] 0x30001bb3 [ 0xff ] 0x30001bb4 [ 0xff ] 0x30001bb5 [ 0xff ] 0x30001bb6 [ 0xff ] 0x30001bb8 [ 0x0 ] 0x3000147e [ 0xff ] 0x3000147f [ 0xff ] 0x30001480 [ 0xff ] 0x30001481 [ 0xff ] 0x30001482 [ 0xff ] 0x30001483 [ 0xff ] 0x30001484 [ 0xff ] 0x30001485 [ 0xff ] 0x30001486 [ 0xff ] 0x30001487 [ 0xff ] 0x30001488 [ 0xff ] 0x30001489 [ 0xff ] 0x3000148a [ 0xff ] 0x3000148b [ 0xff ] 0x3000148c [ 0xff ] 0x3000148d [ 0xff ] 0x3000148e [ 0xff ] 0x3000148f [ 0xff ] 0x30001490 [ 0xff ] 0x30001491 [ 0xff ] 0x30001492 [ 0xff ] 0x30001493 [ 0xff ] 0x30001494 [ 0xff ] 0x30001495 [ 0xff ] 0x30001496 [ 0xff ] 0x30001497 [ 0xff ] 0x30001498 [ 0xff ] 0x30001499 [ 0xff ] 0x3000149a [ 0xff ] 0x3000149b [ 0xff ] 0x3000149c [ 0xff ] 0x3000149d [ 0xff ] 0x3000149e [ 0xff ] 0x3000149f [ 0xff ] 0x300014a0 [ 0xff ] 0x300014a1 [ 0xff ] 0x300014a2 [ 0xff ] 0x300014a3 [ 0xff ] 0x300014a4 [ 0xff ] 0x300014a5 [ 0xff ] 0x300014a6 [ 0xff ] 0x300014a7 [ 0xff ] 0x300014a8 [ 0xff ] 0x300014a9 [ 0xff ] 0x300014aa [ 0xff ] 0x300014ab [ 0xff ] 0x300014ac [ 0xff ] 0x300014ad [ 0xff ] 0x300014ae [ 0xff ] 0x300014b0 [ 0x0 ] 0x300204fe [ 0x0 ] 0x30000d4c [ 0xff ] 0x30000d4d [ 0xff ] 0x30000d4e [ 0xff ] 0x30000d4f [ 0xff ] 0x30000d50 [ 0xff ] 0x30000d51 [ 0xff ] 0x30000d52 [ 0xff ] 0x30000d53 [ 0xff ] 0x30000d54 [ 0xff ] 0x30000d55 [ 0xff ] 0x30000d56 [ 0xff ] 0x30000d57 [ 0xff ] 0x30000d58 [ 0xff ] 0x30000d59 [ 0xff ] 0x30000d5a [ 0xff ] 0x30000d5b [ 0xff ] 0x30000d5c [ 0xff ] 0x30000d5d [ 0xff ] 0x30000d5e [ 0xff ] 0x30000d5f [ 0xff ] 0x30000d60 [ 0xff ] 0x30000d61 [ 0xff ] 0x30000d62 [ 0xff ] 0x30000d63 [ 0xff ] 0x30000d64 [ 0xff ] 0x30000d65 [ 0xff ] 0x30000d66 [ 0xff ] 0x30000d67 [ 0xff ] 0x30000d68 [ 0xff ] 0x30000d69 [ 0xff ] 0x30000d6a [ 0xff ] 0x30000d6b [ 0xff ] 0x30000d6c [ 0xff ] 0x30000d6d [ 0xff ] 0x30000d6e [ 0xff ] 0x30000d6f [ 0xff ] 0x30000d70 [ 0x0 ] 0x30000d71 [ 0xff ] 0x30000d72 [ 0xff ] 0x30000d73 [ 0xff ] 0x30000d74 [ 0xff ] 0x30000d75 [ 0xff ] 0x30000d76 [ 0xff ] 0x30000d77 [ 0xff ] 0x30000d78 [ 0xff ] 0x30000d79 [ 0xff ] 0x30000d7a [ 0xff ] 0x30000d7b [ 0xff ] 0x30000d7c [ 0xff ] 0x30000d7d [ 0xff ] 0x30000daa [ 0xff ] 0x30000dab [ 0xff ] 0x30000dac [ 0xff ] 0x30000dad [ 0xff ] 0x30000dae [ 0xff ] 0x30000daf [ 0xff ] 0x30000db0 [ 0xff ] 0x30000db1 [ 0xff ] 0x30000db2 [ 0xff ] 0x30000db3 [ 0xff ] 0x30000db4 [ 0xff ] 0x30000db5 [ 0xff ] 0x30000db6 [ 0xff ] 0x30000db7 [ 0xff ] 0x30000db8 [ 0xff ] 0x30000db9 [ 0xff ] 0x30000dba [ 0xff ] 0x30000dbb [ 0xff ] 0x30000dbc [ 0xff ] 0x30000dbd [ 0xff ] 0x30000dbe [ 0xff ] 0x30000dbf [ 0xff ] 0x30000dc0 [ 0xff ] 0x30000dc1 [ 0xff ] 0x30000dc2 [ 0xff ] 0x30000dc3 [ 0xff ] 0x30000dc4 [ 0xff ] 0x30000dc5 [ 0xff ] 0x30000dc6 [ 0xff ] 0x30000dc7 [ 0xff ] 0x30000dc8 [ 0xff ] 0x30000dc9 [ 0xff ] 0x30000dca [ 0xff ] 0x30000dcb [ 0xff ] 0x30000dcc [ 0xff ] 0x30000dcd [ 0xff ] 0x30000dce [ 0xff ] 0x30000dcf [ 0xff ] 0x30000dd0 [ 0xff ] 0x30000dd1 [ 0xff ] 0x30000dd2 [ 0xff ] 0x30000dd3 [ 0xff ] 0x30000dd4 [ 0xff ] 0x30000dd5 [ 0xff ] 0x30000dd6 [ 0xff ] 0x30000dd7 [ 0xff ] 0x30000dd8 [ 0xff ] 0x30000dd9 [ 0xff ] 0x30000dda [ 0xff ] 0x30000ddc [ 0x2f ] 0x30000ddd [ 0xff ] 0x30000dde [ 0xff ] 0x30000ddf [ 0xff ] 0x30000de0 [ 0xff ] 0x30000de1 [ 0xff ] 0x30000de2 [ 0xff ] 0x30000de3 [ 0xff ] 0x30000de4 [ 0xff ] 0x30000de5 [ 0xff ] 0x30000de6 [ 0xff ] 0x30000de7 [ 0xff ] 0x30000de8 [ 0xff ] 0x30000de9 [ 0xff ] 0x30000dea [ 0xff ] 0x30000deb [ 0xff ] 0x30000dec [ 0xff ] 0x30000ded [ 0xff ] 0x30000dee [ 0xff ] 0x30000def [ 0xff ] 0x30000df0 [ 0xff ] 0x30000df1 [ 0xff ] 0x30000df2 [ 0xff ] 0x30000df3 [ 0xff ] 0x30000df4 [ 0xff ] 0x30000df5 [ 0xff ] 0x30000df6 [ 0xff ] 0x30000df7 [ 0xff ] 0x30000df8 [ 0xff ] 0x30000df9 [ 0xff ] 0x30000dfa [ 0xff ] 0x30000dfb [ 0xff ] 0x30000dfc [ 0xff ] 0x30000dfd [ 0xff ] 0x30000dfe [ 0xff ] 0x30000dff [ 0xff ] 0x30000e00 [ 0xff ] 0x30000e01 [ 0xff ] 0x30000e02 [ 0xff ] 0x30000e03 [ 0xff ] 0x30000e04 [ 0xff ] 0x30000e05 [ 0xff ] 0x30000e06 [ 0xff ] 0x30000e07 [ 0xff ] 0x30000e08 [ 0xff ] 0x30000e09 [ 0xff ] 0x30000e0a [ 0xff ] 0x30000e0b [ 0xff ] 0x30000e0c [ 0x0 ] 0x30000e0d [ 0xff ] 0x30000e0e [ 0x0 ] 0x30002634 [ 0x0 ] 0x30002635 [ 0xff ] 0x30002636 [ 0xff ] 0x30002637 [ 0xff ] 0x30002638 [ 0xff ] 0x30002639 [ 0xff ] 0x3000263a [ 0xff ] 0x3000263b [ 0xff ] 0x3000263c [ 0xff ] 0x3000263d [ 0xff ] 0x3000263e [ 0xff ] 0x3000263f [ 0xff ] 0x3003ef96 [ 0x0 ] 0x3001f7b2 [ 0x0 ] 0x3001f7e4 [ 0x0 ] 0x3001f7e5 [ 0xff ] 0x3001f7e6 [ 0x0 ] 0x3001f7e7 [ 0xff ] 0x3001f7e8 [ 0xff ] 0x3001f7e9 [ 0xff ] 0x3001f7ea [ 0xff ] 0x3001f7eb [ 0xff ] 0x3001f7ec [ 0xff ] 0x3001f7ed [ 0x0 ] 0x3001f7ee [ 0xff ] 0x3001f7ef [ 0xff ] [LIMITATION] number of seeds attempted exceed ... +[EMULATION] attempted sequence: ('ecall_opendb', 'ecall_execute_sql', 'ecall_closedb', 'ecall_execute_sql', 'ecall_opendb', 'ecall_closedb') + +real 52m58.083s +user 52m56.415s +sys 0m1.520s