New issue
Advanced search Search tips

Issue 599866 link

Starred by 0 users

Issue metadata

Status: Fixed
Owner:
Closed: Apr 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Security



Sign in to add a comment

Heap-use-after-free LayoutBoxModelObject::continuation() (NO STACK)

Project Member Reported by ClusterFuzz, Apr 1 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5363490788737024

Fuzzer: ochang_domfuzzer
Job Type: linux_tsan_chrome_mp
Platform Id: linux

Crash Type: Heap-use-after-free
Crash Address: 
Crash State:
  NULL
Recommended Security Severity: High


Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv958vS4d73OA6yZByrwZtC-0qZZ8eJPyGmVh_pjsYoUYg7flsIbLawFMplaQYXhETRVbDGF5Bdu3DqEFN9o_8godq8IsA9lwNdkNn1sKAETlPfQbHOgxzk0wiL5YHS_2IuA92zQ8hTXqb8Pk5R6Tqz6qQGXd_Q


Filer: mmoroz

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: mmoroz@chromium.org och...@chromium.org
Components: Blink>Layout
Owner: dsinclair@chromium.org
Summary: Heap-use-after-free LayoutBoxModelObject::continuation() (NO STACK) (was: NO STACK)
dsinclair@, could you please take a look and help to find an owner for this?
Project Member

Comment 2 by ClusterFuzz, Apr 1 2016

Labels: Pri-1
Status: Assigned (was: Available)
Project Member

Comment 3 by sheriffbot@chromium.org, Apr 2 2016

Labels: M-49
Owner: e...@chromium.org
eae@ to triage for layout-dev.
Project Member

Comment 5 by ClusterFuzz, Apr 5 2016

ClusterFuzz has detected this issue as fixed in range 384988:385072.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5363490788737024

Fuzzer: ochang_domfuzzer
Job Type: linux_tsan_chrome_mp
Platform Id: linux

Crash Type: Heap-use-after-free
Crash Address: 
Crash State:
  NULL
Recommended Security Severity: High

Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_tsan_chrome_mp&range=384988:385072

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv958vS4d73OA6yZByrwZtC-0qZZ8eJPyGmVh_pjsYoUYg7flsIbLawFMplaQYXhETRVbDGF5Bdu3DqEFN9o_8godq8IsA9lwNdkNn1sKAETlPfQbHOgxzk0wiL5YHS_2IuA92zQ8hTXqb8Pk5R6Tqz6qQGXd_Q


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Comment 6 by e...@chromium.org, Apr 5 2016

Status: Fixed (was: Assigned)
Project Member

Comment 7 by ClusterFuzz, Apr 5 2016

ClusterFuzz has detected this issue as fixed in range 384988:385072.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5363490788737024

Fuzzer: ochang_domfuzzer
Job Type: linux_tsan_chrome_mp
Platform Id: linux

Crash Type: Heap-use-after-free
Crash Address: 
Crash State:
  NULL
Recommended Security Severity: High

Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_tsan_chrome_mp&range=384988:385072

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv958vS4d73OA6yZByrwZtC-0qZZ8eJPyGmVh_pjsYoUYg7flsIbLawFMplaQYXhETRVbDGF5Bdu3DqEFN9o_8godq8IsA9lwNdkNn1sKAETlPfQbHOgxzk0wiL5YHS_2IuA92zQ8hTXqb8Pk5R6Tqz6qQGXd_Q


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 8 by ClusterFuzz, Apr 6 2016

Labels: -Restrict-View-SecurityTeam Merge-Triage M-51 M-50 Restrict-View-SecurityNotify
Adding Merge-Triage label for tracking purposes.

Once your fix had sufficient bake time (on canary, dev as appropriate), please nominate your fix for merge by adding the Merge-Requested label.

When your merge is approved by the release manager, please start merging with higher milestone label first. Make sure to re-request merge for every milestone in the label list. You can get branch information on omahaproxy.appspot.com.

Your fix is very close to the branch point. After the branch happens, please make sure to check if your fix is in.

- Your friendly ClusterFuzz
Project Member

Comment 9 by sheriffbot@chromium.org, Apr 14 2016

Labels: -M-49
Did a fix land here off bug or is this a case of a flaky CF find / unrelated fix? I assume it's the latter, but want to double check.

Comment 11 by e...@chromium.org, May 9 2016

Unrelated fix. 
Labels: -Merge-Triage merge-na
Labels: Release-NA
Project Member

Comment 14 by sheriffbot@chromium.org, Jul 13 2016

Labels: -Restrict-View-SecurityNotify
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 15 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 16 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment