Issue metadata
Sign in to add a comment
|
Use-of-uninitialized-value in base::Pickle::WriteData |
||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4661361992269824 Fuzzer: inferno_twister Job Type: linux_msan_chrome Platform Id: linux Crash Type: Use-of-uninitialized-value Crash Address: Crash State: base::Pickle::WriteData IPC::ParamTraits<cc::FilterOperation>::Write IPC::ParamTraits<cc::FilterOperations>::Write Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_msan_chrome&range=384988:385072 Minimized Testcase (0.18 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv97fkDFdb5NaYTf5xpZ2AMEey50qGo81KlKd402rv-iVVlZQjnsP8z4v-o4ZGTYH9E6hsKuzbj99zO6Jr9yovFHQbur7fmmQUdsDiUFDWavSQQ1J_Sx3jjlpwyKzGm9BSoNztKXS3jg2X_E5uAlmxDwwuNNr1Q <svg> <filter id=non-integer-tile> <feColorMatrix height=0><style>img { transform: translatez(0) <img src=resources/reference.png style="-webkit-filter: url(#non-integer-tile);"> Additional requirements: Requires HTTP Filer: mmoroz See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Apr 5 2016
,
Apr 6 2016
ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4661361992269824 Fuzzer: inferno_twister Job Type: linux_msan_chrome Platform Id: linux Crash Type: Use-of-uninitialized-value Crash Address: Crash State: base::Pickle::WriteData IPC::ParamTraits<cc::FilterOperation>::Write IPC::ParamTraits<cc::FilterOperations>::Write Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_msan_chrome&range=384988:385072 Minimized Testcase (0.18 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv97fkDFdb5NaYTf5xpZ2AMEey50qGo81KlKd402rv-iVVlZQjnsP8z4v-o4ZGTYH9E6hsKuzbj99zO6Jr9yovFHQbur7fmmQUdsDiUFDWavSQQ1J_Sx3jjlpwyKzGm9BSoNztKXS3jg2X_E5uAlmxDwwuNNr1Q <svg> <filter id=non-integer-tile> <feColorMatrix height=0><style>img { transform: translatez(0) <img src=resources/reference.png style="-webkit-filter: url(#non-integer-tile);"> Additional requirements: Requires HTTP See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Apr 14 2016
,
Apr 25 2016
,
Apr 26 2016
,
Apr 26 2016
mkosiba: Uh oh! This issue still open and hasn't been updated in the last 21 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
May 3 2016
,
May 9 2016
A friendly reminder that M51 Stable is launching soon! Your bug is labelled as Stable ReleaseBlock, pls make sure to land the fix and get it merged into the release branch by May 17. All changes MUST be merged into the release branch by 5pm on May 20 to make into the desktop Stable final build cut. Thanks!
,
May 11 2016
mkosiba: Uh oh! This issue still open and hasn't been updated in the last 36 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
May 12 2016
We're getting closer to M51 Stable launch. Please update the bug with the current status.
,
May 16 2016
M51 Stable is launching very soon! Your bug is labelled as Stable ReleaseBlock, pls make sure to land the fix and get it merged ASAP. All changes MUST be merged into the release branch by 5pm on May 20 to make into the desktop Stable final build cut. Thank you!
,
May 18 2016
Any update on this bug? Please note that we're getting very close to M51 stable launch.
,
May 20 2016
Triggered redo of clusterfuzz testing to see if flaky and if a fix is required here.
,
May 20 2016
ClusterFuzz has detected this issue as fixed in range 386671:386714. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4661361992269824 Fuzzer: inferno_twister Job Type: linux_msan_chrome Platform Id: linux Crash Type: Use-of-uninitialized-value Crash Address: Crash State: base::Pickle::WriteData IPC::ParamTraits<cc::FilterOperation>::Write IPC::ParamTraits<cc::FilterOperations>::Write Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_msan_chrome&range=384988:385072 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_msan_chrome&range=386671:386714 Minimized Testcase (0.18 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv97fkDFdb5NaYTf5xpZ2AMEey50qGo81KlKd402rv-iVVlZQjnsP8z4v-o4ZGTYH9E6hsKuzbj99zO6Jr9yovFHQbur7fmmQUdsDiUFDWavSQQ1J_Sx3jjlpwyKzGm9BSoNztKXS3jg2X_E5uAlmxDwwuNNr1Q <svg> <filter id=non-integer-tile> <feColorMatrix height=0><style>img { transform: translatez(0) <img src=resources/reference.png style="-webkit-filter: url(#non-integer-tile);"> Additional requirements: Requires HTTP See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
May 20 2016
Assuming unrelated fix, marking Release-NA and Merge-NA.
,
May 20 2016
,
Aug 26 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 1 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
|
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by mmoroz@chromium.org
, Apr 5 2016Components: Content>Core
Labels: M-51 Pri-3
Owner: mkosiba@chromium.org