Issue metadata
Sign in to add a comment
|
Heap-use-after-free LayoutBoxModelObject::continuation() (NO STACK) |
||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5363490788737024 Fuzzer: ochang_domfuzzer Job Type: linux_tsan_chrome_mp Platform Id: linux Crash Type: Heap-use-after-free Crash Address: Crash State: NULL Recommended Security Severity: High Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv958vS4d73OA6yZByrwZtC-0qZZ8eJPyGmVh_pjsYoUYg7flsIbLawFMplaQYXhETRVbDGF5Bdu3DqEFN9o_8godq8IsA9lwNdkNn1sKAETlPfQbHOgxzk0wiL5YHS_2IuA92zQ8hTXqb8Pk5R6Tqz6qQGXd_Q Filer: mmoroz See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Apr 1 2016
,
Apr 2 2016
,
Apr 4 2016
eae@ to triage for layout-dev.
,
Apr 5 2016
ClusterFuzz has detected this issue as fixed in range 384988:385072. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5363490788737024 Fuzzer: ochang_domfuzzer Job Type: linux_tsan_chrome_mp Platform Id: linux Crash Type: Heap-use-after-free Crash Address: Crash State: NULL Recommended Security Severity: High Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_tsan_chrome_mp&range=384988:385072 Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv958vS4d73OA6yZByrwZtC-0qZZ8eJPyGmVh_pjsYoUYg7flsIbLawFMplaQYXhETRVbDGF5Bdu3DqEFN9o_8godq8IsA9lwNdkNn1sKAETlPfQbHOgxzk0wiL5YHS_2IuA92zQ8hTXqb8Pk5R6Tqz6qQGXd_Q See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Apr 5 2016
,
Apr 5 2016
ClusterFuzz has detected this issue as fixed in range 384988:385072. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5363490788737024 Fuzzer: ochang_domfuzzer Job Type: linux_tsan_chrome_mp Platform Id: linux Crash Type: Heap-use-after-free Crash Address: Crash State: NULL Recommended Security Severity: High Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_tsan_chrome_mp&range=384988:385072 Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv958vS4d73OA6yZByrwZtC-0qZZ8eJPyGmVh_pjsYoUYg7flsIbLawFMplaQYXhETRVbDGF5Bdu3DqEFN9o_8godq8IsA9lwNdkNn1sKAETlPfQbHOgxzk0wiL5YHS_2IuA92zQ8hTXqb8Pk5R6Tqz6qQGXd_Q See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Apr 6 2016
Adding Merge-Triage label for tracking purposes. Once your fix had sufficient bake time (on canary, dev as appropriate), please nominate your fix for merge by adding the Merge-Requested label. When your merge is approved by the release manager, please start merging with higher milestone label first. Make sure to re-request merge for every milestone in the label list. You can get branch information on omahaproxy.appspot.com. Your fix is very close to the branch point. After the branch happens, please make sure to check if your fix is in. - Your friendly ClusterFuzz
,
Apr 14 2016
,
May 9 2016
Did a fix land here off bug or is this a case of a flaky CF find / unrelated fix? I assume it's the latter, but want to double check.
,
May 9 2016
Unrelated fix.
,
May 24 2016
,
May 24 2016
,
Jul 13 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 1 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
|
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by mmoroz@chromium.org
, Apr 1 2016Components: Blink>Layout
Owner: dsinclair@chromium.org
Summary: Heap-use-after-free LayoutBoxModelObject::continuation() (NO STACK) (was: NO STACK)