New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 595656 link

Starred by 0 users

Issue metadata

Status: Fixed
Owner:
Closed: Mar 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Security



Sign in to add a comment

Crash in v8::internal::InnerPointerToCodeCache::GcSafeFindCodeForInnerPointer

Project Member Reported by ClusterFuzz, Mar 17 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5403499919048704

Fuzzer: decoder_langfuzz
Job Type: linux_asan_d8_dbg
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x7fff7ea00030
Crash State:
  v8::internal::InnerPointerToCodeCache::GcSafeFindCodeForInnerPointer
  v8::internal::InnerPointerToCodeCache::GetCacheEntry
  v8::internal::StackFrame::ComputeType
  
Regressed: V8: r34731:34732

Minimized Testcase (6.24 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96jKhOUIwG2x-H_GpJD9SJccZ--XQxptO0q_s7KiG1_2e35NghPHPjAgofvCv7ve9a2fo8kPAH-Xp9Z8fP1vnvAMgBi9kSAW-1D9dEj3pjTQ089h2LYHuHWYT4WbVV6kEdKWPX62GKIcLOoNTXl4PiqiVqr8w

Filer: hablich

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Owner: adamk@chromium.org
Status: Assigned (was: Available)
A flag removal resulting in a security problem? That is strange.
Project Member

Comment 2 by ClusterFuzz, Mar 17 2016

Labels: Pri-1

Comment 3 by adamk@chromium.org, Mar 17 2016

Fairly certain this is not due to anything specific about the toString change; if the blamelist is correct, it's because that patch slightly changed heap layout.

Meanwhile, I'm having trouble actually running this reproduction: the fuzzer_with_launcher_script.zip claims to not be a valid zipfile.
Project Member

Comment 4 by ClusterFuzz, Mar 17 2016

ClusterFuzz has detected this issue as fixed in range 34867:34868.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5403499919048704

Fuzzer: decoder_langfuzz
Job Type: linux_asan_d8_dbg
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x7fff7ea00030
Crash State:
  v8::internal::InnerPointerToCodeCache::GcSafeFindCodeForInnerPointer
  v8::internal::InnerPointerToCodeCache::GetCacheEntry
  v8::internal::StackFrame::ComputeType
  
Regressed: V8: r34731:34732
Fixed: V8: r34867:34868

Minimized Testcase (6.24 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96jKhOUIwG2x-H_GpJD9SJccZ--XQxptO0q_s7KiG1_2e35NghPHPjAgofvCv7ve9a2fo8kPAH-Xp9Z8fP1vnvAMgBi9kSAW-1D9dEj3pjTQ089h2LYHuHWYT4WbVV6kEdKWPX62GKIcLOoNTXl4PiqiVqr8w

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Comment 5 by adamk@chromium.org, Mar 17 2016

Status: Fixed (was: Assigned)
Closing per #4
Project Member

Comment 6 by ClusterFuzz, Mar 18 2016

Labels: -Restrict-View-SecurityTeam Merge-Triage Restrict-View-SecurityNotify
Adding Merge-Triage label for tracking purposes.

Once your fix had sufficient bake time (on canary, dev as appropriate), please nominate your fix for merge by adding the Merge-Requested label.

When your merge is approved by the release manager, please start merging with higher milestone label first. Make sure to re-request merge for every milestone in the label list. You can get branch information on omahaproxy.appspot.com.

- Your friendly ClusterFuzz
Labels: -Merge-Triage
This was introduced only to ToT so no merge needed. Am I missing something?
Cc: timwillis@chromium.org
Labels: Security_Impact-Head M-51
#7: No, you're not missing anything. If there's no "Security_Impact" label, we assume that the impact is more significant than ToT (defence in depth!). Added the label and the milestone, so this should be good to go.
Project Member

Comment 9 by sheriffbot@chromium.org, Jun 24 2016

Labels: -Restrict-View-SecurityNotify
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: -reward-topanel reward-unpaid reward-3500
Congrats - $3,500 for this report. We'll add this to next week's payment run.
Labels: reward_to-decoder.oh_at_googlemail.com
Labels: -reward-unpaid reward-inprocess
Project Member

Comment 13 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 14 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment