New issue
Advanced search Search tips

Issue 599634 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 590071
Owner:
Closed: Apr 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Security



Sign in to add a comment

Crash in v8::internal::MaybeHandle<v8::internal::Object> v8::internal::HandleApiCallHelpe

Project Member Reported by ClusterFuzz, Mar 31 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5293918089904128

Fuzzer: inferno_twister
Job Type: linux_asan_chrome_media
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x00017fff7fff
Crash State:
  v8::internal::MaybeHandle<v8::internal::Object> v8::internal::HandleApiCallHelpe
  v8::internal::Builtins::InvokeApiFunction
  v8::internal::Object::GetPropertyWithAccessor
  
Recommended Security Severity: Medium

Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_media&range=375259:376263

Minimized Testcase (3.14 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94jYVEBklnwcf6yWSehsSz_m6Gldh6qSncAPlcKrLousQltdS-E0lbaTkME2CxE9-odRL8kn5vbosyEhVhEzEAuLVBi-MlqKGgvdIJFxN48CFfflFmqbvOBLEfL1mlg4sjcMCz2E86Y5YiDxhXS-pEVigUWMQ

Filer: inferno

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: jarin@chromium.org hablich@chromium.org
Owner: mstarzinger@chromium.org
Status: Assigned (was: Available)
Author: mstarzinger
Component: chromium-v8
Changelist: https://chromium.googlesource.com/v8/v8.git/+/305a36e0d41f22d79b60daea70050e58f960bd8e
Time: Wed Feb 17 10:30:10 2016
Lines 4102 of file builtins.cc which potentially caused crash are changed in this cl (frame #5, "v8::internal::Builtins::InvokeApiFunction").

Lines 1093 of file objects.cc which potentially caused crash are changed in this cl (frame #6, "v8::internal::Object::GetPropertyWithAccessor").
Minimum distance from crash line to modified line: 0. (file: builtins.cc, crashed on: 4102, modified: 4102).

Suspected Component: chromium-v8
Suspected Cr- Label: Cr-Blink-JavaScrip
Project Member

Comment 2 by ClusterFuzz, Mar 31 2016

Labels: Pri-1
Components: Blink>JavaScript
Labels: M-50
Project Member

Comment 4 by ClusterFuzz, Apr 7 2016

ClusterFuzz has detected this issue as fixed in range 385386:385441.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5293918089904128

Fuzzer: inferno_twister
Job Type: linux_asan_chrome_media
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x00017fff7fff
Crash State:
  v8::internal::MaybeHandle<v8::internal::Object> v8::internal::HandleApiCallHelpe
  v8::internal::Builtins::InvokeApiFunction
  v8::internal::Object::GetPropertyWithAccessor
  
Recommended Security Severity: Medium

Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_media&range=375259:376263
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_media&range=385386:385441

Minimized Testcase (3.14 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94jYVEBklnwcf6yWSehsSz_m6Gldh6qSncAPlcKrLousQltdS-E0lbaTkME2CxE9-odRL8kn5vbosyEhVhEzEAuLVBi-MlqKGgvdIJFxN48CFfflFmqbvOBLEfL1mlg4sjcMCz2E86Y5YiDxhXS-pEVigUWMQ

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 5 by sheriffbot@chromium.org, Apr 14 2016

Labels: -Security_Impact-Beta Security_Impact-Stable
Project Member

Comment 6 by sheriffbot@chromium.org, Apr 21 2016

mstarzinger: Uh oh! This issue still open and hasn't been updated in the last 20 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers?

If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one?

If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Mergedinto: 590071
Status: Duplicate (was: Assigned)
Has been fixed already.
Project Member

Comment 8 by sheriffbot@chromium.org, Jul 29 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 9 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 10 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment