New issue
Advanced search Search tips

Issue 570428 link

Starred by 0 users

Issue metadata

Status: Duplicate
Merged: issue 570427
Owner: ----
Closed: Dec 2015
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: ----
Type: Bug-Security



Sign in to add a comment

Heap-use-after-free in blink::TextFieldInputType::didSetValueByUserEdit

Project Member Reported by ClusterFuzz, Dec 16 2015

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6593516991414272

Uploader: ochang@google.com
Job Type: linux_asan_chrome_mp
Platform Id: linux

Crash Type: Heap-use-after-free READ 8
Crash Address: 0x60f000010cb0
Crash State:
  blink::TextFieldInputType::didSetValueByUserEdit
  blink::TextFieldInputType::subtreeHasChanged
  blink::HTMLInputElement::subtreeHasChanged
  

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv94vpIVFh8Lxrmtbdtqi4Hvsa_KauEYj1VkA0hwy6oQmsf9-ByQXD9avOMiWACeL_M8mEnltOpZyHKFoYN0lyrSxiNFfrRgNvkdmm2XJvEY9lDVeG0CMJEn4dNiPbyGkpE7ZWaTPRtd7EX6Zjt3_m3-P2i7jxg


Filer: ochang

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 

Comment 1 by och...@chromium.org, Dec 16 2015

Mergedinto: 570427
Status: Duplicate
Project Member

Comment 2 by sheriffbot@chromium.org, Mar 25 2016

Labels: -Restrict-View-SecurityTeam
This security bug has been closed for more than 14 weeks. Removing view restrictions.

For more details visit https://sites.google.com/a/chromium.org/dev/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 3 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 4 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment