New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 590648 link

Starred by 0 users

Issue metadata

Status: Fixed
Owner:
Last visit > 30 days ago
Closed: Mar 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Direct-leak in blink::JPEGImageEncoderState::create

Project Member Reported by ClusterFuzz, Feb 29 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4937871317794816

Fuzzer: inferno_twister
Job Type: linux_lsan_chrome_mp
Platform Id: linux

Crash Type: Direct-leak
Crash Address: 
Crash State:
  blink::JPEGImageEncoderState::create
  blink::JPEGImageEncoder::encode
  blink::ImageDataBuffer::encodeImage
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=378023:378103

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97xHyUYc09yJH_9nBQIm51mIPiN2SKxgb2r4BmNsIqiXSJbKgVagttF26gVMfVd0rUA8TLa-HUEXxEMwDr46tty9snaIC24B5YgrZUSgOgjD0eavEBljPFDV_rsoc6Rp_2k1gkVlBoDx3g4irfKSa6ZrdbxAaHReNmO9Sl-cC-rntYimxo


Additional requirements: Requires Gestures

Additional requirements: Requires HTTP

Filer: ranjitkan

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: ranjitkan@chromium.org
Components: Blink>HTML>Image
Labels: findit-for-crash M-50 TE-Logged
Owner: xlai@chromium.org
Status: Assigned (was: Available)
Author: xlai
Component: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/8eb8fa6b1082bcee64d5bc98ed8d1004378c0331
Time: Thu Feb 18 18:46:22 2016
The CL last changed line 139 of file JPEGImageEncoder.cpp, which is stack frame 1.

@xlai: request you to please take a look into it.

Thanks.!

Comment 2 by tkent@chromium.org, Feb 29 2016

Components: -Blink>HTML>Image Blink>Image
Project Member

Comment 3 by ClusterFuzz, Mar 2 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4937871317794816

Fuzzer: inferno_twister
Job Type: linux_lsan_chrome_mp
Platform Id: linux

Crash Type: Direct-leak
Crash Address: 
Crash State:
  blink::JPEGImageEncoderState::create
  blink::JPEGImageEncoder::encode
  blink::ImageDataBuffer::encodeImage
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=378023:378103

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97xHyUYc09yJH_9nBQIm51mIPiN2SKxgb2r4BmNsIqiXSJbKgVagttF26gVMfVd0rUA8TLa-HUEXxEMwDr46tty9snaIC24B5YgrZUSgOgjD0eavEBljPFDV_rsoc6Rp_2k1gkVlBoDx3g4irfKSa6ZrdbxAaHReNmO9Sl-cC-rntYimxo


Additional requirements: Requires Gestures

Additional requirements: Requires HTTP

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Comment 5 by noel@chromium.org, Mar 14 2016

Status: Fixed (was: Assigned)
Project Member

Comment 7 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment