Issue metadata
Sign in to add a comment
|
Use-after-poison in v8::internal::RegExpParser::GetCapture |
||||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4534753427980288 Fuzzer: decoder_langfuzz Job Type: linux_asan_d8 Platform Id: linux Crash Type: Use-after-poison READ 8 Crash Address: 0x62500018dc60 Crash State: v8::internal::RegExpParser::GetCapture v8::internal::RegExpParser::ParseDisjunction v8::internal::RegExpParser::ParsePattern Recommended Security Severity: High Regressed: V8: r32119:32120 Minimized Testcase (6.96 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94o8gBDYc8ALNadpCvGqBpU7QZtYmXf6ejK1Wga8RYGvR6WvIh3_YiL__kT9xYkpB0ZsUhQrR4yis7zdA-4AreIYHA_fvgJetqvfhJQEATbkdeWu-R6RB_wK7uOhpYM278tyPmihRJT29OjEz6jumjBke-JUA Filer: hablich See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Mar 19 2016
,
Mar 19 2016
ClusterFuzz has detected this issue as fixed in range 34893:34894. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4534753427980288 Fuzzer: decoder_langfuzz Job Type: linux_asan_d8 Platform Id: linux Crash Type: Use-after-poison READ 8 Crash Address: 0x62500018dc60 Crash State: v8::internal::RegExpParser::GetCapture v8::internal::RegExpParser::ParseDisjunction v8::internal::RegExpParser::ParsePattern Recommended Security Severity: High Regressed: V8: r32119:32120 Fixed: V8: r34893:34894 Minimized Testcase (6.96 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94o8gBDYc8ALNadpCvGqBpU7QZtYmXf6ejK1Wga8RYGvR6WvIh3_YiL__kT9xYkpB0ZsUhQrR4yis7zdA-4AreIYHA_fvgJetqvfhJQEATbkdeWu-R6RB_wK7uOhpYM278tyPmihRJT29OjEz6jumjBke-JUA See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Mar 21 2016
Clusterfuzz says this was a regression. Adjusting labels.
,
Mar 22 2016
,
Mar 22 2016
This medium+ severity security issue is a regression on trunk. Please fix this asap. If you are unable to look into this soon, please revert your change. - Your friendly ClusterFuzz
,
Mar 24 2016
,
Mar 24 2016
,
Mar 24 2016
,
Jun 30 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jun 30 2016
Updating Status - this is a dupe of Issue 594953 . As it's a dupe, it's not eligible for a reward. @decoder - I've also added you to the duped bug so that you can see it.
,
Jun 30 2016
Thanks Tim :)
,
Oct 1 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
|
|||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||
Comment 1 by hablich@chromium.org
, Mar 18 2016Owner: verwa...@chromium.org
Status: Assigned (was: Available)