New issue
Advanced search Search tips

Issue 595657 link

Starred by 0 users

Issue metadata

Status: Fixed
Owner:
Closed: Mar 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: All
Pri: 1
Type: Bug



Sign in to add a comment

index <= know_captures in src/regexp/regexp-parser.cc

Project Member Reported by ClusterFuzz, Mar 17 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6519893553315840

Fuzzer: decoder_langfuzz
Job Type: linux_asan_d8_dbg
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  index <= know_captures in src/regexp/regexp-parser.cc
  
Regressed: V8: r32042:32043

Minimized Testcase (6.96 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94W6PAztOQLdQ1GEgvpZOgFQXzC3ld0UFGox5vJsJCE4UzKJsfrKE5vO4v1k0EpE7h0S3DRZYjvQg6vseZGCBF2DpQRabJWiwgJdnT3AanUh9ajp2-u47X-XgclEsXEMMzW2rQUFzW_F25bjrtBAZwbN9gvAw

Filer: hablich

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Owner: yangguo@chromium.org
Status: Assigned (was: Available)
Project Member

Comment 3 by ClusterFuzz, Mar 18 2016

ClusterFuzz has detected this issue as fixed in range 34893:34894.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6519893553315840

Fuzzer: decoder_langfuzz
Job Type: linux_asan_d8_dbg
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  index <= know_captures in src/regexp/regexp-parser.cc
  
Regressed: V8: r32042:32043
Fixed: V8: r34893:34894

Minimized Testcase (6.96 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94W6PAztOQLdQ1GEgvpZOgFQXzC3ld0UFGox5vJsJCE4UzKJsfrKE5vO4v1k0EpE7h0S3DRZYjvQg6vseZGCBF2DpQRabJWiwgJdnT3AanUh9ajp2-u47X-XgclEsXEMMzW2rQUFzW_F25bjrtBAZwbN9gvAw

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Cc: -ishell@chromium.org -mstarzinger@chromium.org hablich@chromium.org
Labels: Merge-Request-50 OS-Mac
Status: Fixed (was: Assigned)
This needs to be merged to M50.
Labels: -OS-Linux -OS-Mac OS-All

Comment 6 by tin...@google.com, Mar 19 2016

Labels: -Merge-Request-50 Merge-Approved-50 Hotlist-Merge-Approved
Your change meets the bar and is auto-approved for M50 (branch: 2661)
Project Member

Comment 7 by bugdroid1@chromium.org, Mar 21 2016

Labels: merge-merged-5.0
The following revision refers to this bug:
  https://chromium.googlesource.com/v8/v8.git/+/c98418cc4a07e4e3adadf030abb2a12afc8f8477

commit c98418cc4a07e4e3adadf030abb2a12afc8f8477
Author: Yang Guo <yangguo@chromium.org>
Date: Mon Mar 21 06:40:39 2016

Version 5.0.71.20 (cherry-pick)

Merged 1e2d0e113627dd9d123334ed8a62ef81697c9fe7

[regexp] catch stack overflow when parsing back references.

BUG= chromium:595657 
LOG=N
R=hablich@chromium.org
TBR=hablich@chromium.org

Review URL: https://codereview.chromium.org/1818883002 .

Cr-Commit-Position: refs/branch-heads/5.0@{#27}
Cr-Branched-From: ad16e6c2cbd2c6b0f2e8ff944ac245561c682ac2-refs/heads/5.0.71@{#1}
Cr-Branched-From: bd9df50d75125ee2ad37b3d92c8f50f0a8b5f030-refs/heads/master@{#34215}

[modify] https://crrev.com/c98418cc4a07e4e3adadf030abb2a12afc8f8477/include/v8-version.h
[modify] https://crrev.com/c98418cc4a07e4e3adadf030abb2a12afc8f8477/src/regexp/regexp-parser.cc
[add] https://crrev.com/c98418cc4a07e4e3adadf030abb2a12afc8f8477/test/mjsunit/regress/regress-crbug-595657.js

Comment 8 by gov...@chromium.org, Mar 21 2016

Per comment #7, this is already merged to M50. If all is done for M50, please remove "Merge-Approved-50" label. Thank you.
Labels: -Merge-Approved-50 -Hotlist-Merge-Approved
Project Member

Comment 10 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment