IsNumber() in src/objects-inl.h |
|||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4523510092791808 Fuzzer: mbarbella_js_mutation Job Type: linux_asan_d8_dbg Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: IsNumber() in src/objects-inl.h Regressed: V8: r34744:34745 Minimized Testcase (0.16 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv94IoF29VLzmt8FrP69f1EUjstAO87zO8fCiCA4zg0qRtgFEUZ3rxiLV7Kn_lrmBm3j2TObuWZVBg6yguQdv9SZ6P5Finohr6rjSZxB3si9ntXp5x6TccrYh5Q9PIUtMErDznxkznVx4Qu-_OVJJVAfS6vEpiw var __v_17 = {}; try { } catch(e) {; } (function () { __v_7 = __v_17; __v_7.__proto__[10000000] = 1; })(); var __v_8 = "return " + Array(12010) + "__v_8"; Filer: hablich See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Mar 18 2016
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/c6f9883d53b05b882d41dc887385636d6c7d29fe commit c6f9883d53b05b882d41dc887385636d6c7d29fe Author: verwaest <verwaest@chromium.org> Date: Fri Mar 18 14:36:07 2016 Remove oob elements collected from the prototype chain by trimming in GetArrayKeys BUG= chromium:594953 LOG=n Review URL: https://codereview.chromium.org/1817443003 Cr-Commit-Position: refs/heads/master@{#34893} [modify] https://crrev.com/c6f9883d53b05b882d41dc887385636d6c7d29fe/src/js/array.js [modify] https://crrev.com/c6f9883d53b05b882d41dc887385636d6c7d29fe/src/runtime/runtime-array.cc [add] https://crrev.com/c6f9883d53b05b882d41dc887385636d6c7d29fe/test/mjsunit/regress/get-array-keys-oob.js
,
Mar 18 2016
ClusterFuzz has detected this issue as fixed in range 34892:34893. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4523510092791808 Fuzzer: mbarbella_js_mutation Job Type: linux_asan_d8_dbg Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: IsNumber() in src/objects-inl.h Regressed: V8: r34744:34745 Fixed: V8: r34892:34893 Minimized Testcase (0.16 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv94IoF29VLzmt8FrP69f1EUjstAO87zO8fCiCA4zg0qRtgFEUZ3rxiLV7Kn_lrmBm3j2TObuWZVBg6yguQdv9SZ6P5Finohr6rjSZxB3si9ntXp5x6TccrYh5Q9PIUtMErDznxkznVx4Qu-_OVJJVAfS6vEpiw var __v_17 = {}; try { } catch(e) {; } (function () { __v_7 = __v_17; __v_7.__proto__[10000000] = 1; })(); var __v_8 = "return " + Array(12010) + "__v_8"; See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Mar 24 2016
Issue 596056 has been merged into this issue.
,
Apr 27 2016
,
Jun 30 2016
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||
►
Sign in to add a comment |
|||
Comment 1 by habl...@google.com
, Mar 15 2016Status: Assigned (was: Available)