Issue metadata
Sign in to add a comment
|
Crash in blink::Resource::responseReceived |
||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4928171838799872 Fuzzer: ochang_domfuzzer Job Type: linux_asan_chrome_v8_arm Platform Id: linux Crash Type: UNKNOWN Crash Address: 0x000004a4 Crash State: blink::Resource::responseReceived blink::ImageResource::responseReceived blink::ImageDocument::createDocumentStructure Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=380105:380830 Minimized Testcase (0.06 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv97EgRUc6Tm-4Su-o5VBc4twDHnSCMQJPtaqkds9xLmefB54t92mU-WKSrskl7RdlndTAvxXItjs9mzsLeXUpojvwjHBmUF8xczfGfuI8Gt16mnYbzYV0Jgb77ciU3JGwCgQsAetEhX0T7ZxsdNJ0E3wzmhHzA <iframe src="resources/mozilla.gif" sandbox="allowScripts"0)"> Filer: ajha See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Mar 14 2016
,
Mar 14 2016
Though I can't reproduce the crash, it looks m_imageElement->cachedImage()->responseReceived(loader()->response(), nullptr); fails because m_imageElement->cachedImage() returns null.
,
Mar 15 2016
,
Mar 17 2016
,
Mar 18 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/bf1150eba29bcb1f20ca5a98d1098ed778fc1c27 commit bf1150eba29bcb1f20ca5a98d1098ed778fc1c27 Author: yhirano <yhirano@chromium.org> Date: Fri Mar 18 05:13:04 2016 HTMLImageElement::cachedImage() may return null in ImageDocument construction This is a speculative fix for a crash. BUG= 594467 Review URL: https://codereview.chromium.org/1801543002 Cr-Commit-Position: refs/heads/master@{#381893} [modify] https://crrev.com/bf1150eba29bcb1f20ca5a98d1098ed778fc1c27/third_party/WebKit/Source/core/html/ImageDocument.cpp
,
Mar 18 2016
ClusterFuzz has detected this issue as fixed in range 381877:381899. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4928171838799872 Fuzzer: ochang_domfuzzer Job Type: linux_asan_chrome_v8_arm Platform Id: linux Crash Type: UNKNOWN Crash Address: 0x000004a4 Crash State: blink::Resource::responseReceived blink::ImageResource::responseReceived blink::ImageDocument::createDocumentStructure Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=380105:380830 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=381877:381899 Minimized Testcase (0.06 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv97EgRUc6Tm-4Su-o5VBc4twDHnSCMQJPtaqkds9xLmefB54t92mU-WKSrskl7RdlndTAvxXItjs9mzsLeXUpojvwjHBmUF8xczfGfuI8Gt16mnYbzYV0Jgb77ciU3JGwCgQsAetEhX0T7ZxsdNJ0E3wzmhHzA <iframe src="resources/mozilla.gif" sandbox="allowScripts"0)"> See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Mar 19 2016
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by ajha@chromium.org
, Mar 14 2016Owner: yhirano@chromium.org
Status: Assigned (was: Available)