Issue metadata
Sign in to add a comment
|
Use-after-poison in blink::V8AbstractEventListener::secondWeakCallback |
||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5437630690361344 Fuzzer: lcamtuf_cross_fuzz Job Type: windows_asan_chrome Platform Id: windows Crash Type: Use-after-poison READ 4 Crash Address: 0x0a3460c0 Crash State: blink::V8AbstractEventListener::secondWeakCallback v8::internal::GlobalHandles::PendingPhantomCallbacksSecondPassTask::RunInternal base::debug::TaskAnnotator::RunTask Recommended Security Severity: High Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_asan_chrome&range=385978:386243 Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97J23BDoxWAt1iSJZAXSEQ70mF_sxaRHDsrdkgkZUl_TEg8R5Wl8n3zGZIHRHIZXIFoZ0d6cIds8o9Ii1ma8c30nzY8P_AMFrl019ZkG_c0Ix45-w48pFv_9dowDAxODZseDSSduUJyhhtWKsVbLTprtBwNVwaRkd13qb37KS7406ObmUo Filer: mmoroz See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Apr 11 2016
,
Apr 11 2016
,
Apr 12 2016
Thanks Marty!
,
Jun 9 2016
ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5437630690361344 Fuzzer: lcamtuf_cross_fuzz Job Type: windows_asan_chrome Platform Id: windows Crash Type: Use-after-poison READ 4 Crash Address: 0x0a3460c0 Crash State: blink::V8AbstractEventListener::secondWeakCallback v8::internal::GlobalHandles::PendingPhantomCallbacksSecondPassTask::RunInternal base::debug::TaskAnnotator::RunTask Recommended Security Severity: High Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_asan_chrome&range=385978:386243 Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97J23BDoxWAt1iSJZAXSEQ70mF_sxaRHDsrdkgkZUl_TEg8R5Wl8n3zGZIHRHIZXIFoZ0d6cIds8o9Ii1ma8c30nzY8P_AMFrl019ZkG_c0Ix45-w48pFv_9dowDAxODZseDSSduUJyhhtWKsVbLTprtBwNVwaRkd13qb37KS7406ObmUo See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Aug 17 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 1 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
|
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by mmoroz@chromium.org
, Apr 11 2016