Issue metadata
Sign in to add a comment
|
Use-after-poison in blink::MediaStreamSource::setReadyState |
||||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5112613872074752 Fuzzer: phoglund_webrtc_peerconnection Job Type: linux_asan_chrome_v8_arm Platform Id: linux Crash Type: Use-after-poison READ 4 Crash Address: 0x4d705840 Crash State: blink::MediaStreamSource::setReadyState blink::WebMediaStreamSource::setReadyState content::MediaStreamVideoSource::SetReadyState Recommended Security Severity: High Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=355576:355963 Minimized Testcase (2.36 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96RGFe7JpeDiWPPjdrHMgbAcFS59aMqzFm2ADX3uTwd3JQWrzmCxweuGskb9AELbloZeJkoEWksR5DDmSKZuTqqPIJ7pXs7akKIf9dcg6HWrBI5qJ60YmExseFY3fmcxP4CGgS7Wx8BCvZzv6jkdMeve-lstw Additional requirements: Requires HTTP Filer: mmoroz See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Apr 11 2016
,
Apr 11 2016
,
Apr 12 2016
Guidou - would you mind taking a look and fix? The regression range does not seem right so please add the appropriate mstone if a fix needs a merge.
,
Apr 12 2016
ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5112613872074752 Fuzzer: phoglund_webrtc_peerconnection Job Type: linux_asan_chrome_v8_arm Platform Id: linux Crash Type: Use-after-poison READ 4 Crash Address: 0x4d705840 Crash State: blink::MediaStreamSource::setReadyState blink::WebMediaStreamSource::setReadyState content::MediaStreamVideoSource::SetReadyState Recommended Security Severity: High Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=355576:355963 Minimized Testcase (2.36 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96RGFe7JpeDiWPPjdrHMgbAcFS59aMqzFm2ADX3uTwd3JQWrzmCxweuGskb9AELbloZeJkoEWksR5DDmSKZuTqqPIJ7pXs7akKIf9dcg6HWrBI5qJ60YmExseFY3fmcxP4CGgS7Wx8BCvZzv6jkdMeve-lstw Additional requirements: Requires HTTP See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Apr 12 2016
Looks similar to bug 602273
,
Apr 12 2016
Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5003207343865856 Fuzzer: phoglund_webrtc_peerconnection Job Type: linux_asan_chrome_v8_arm Platform Id: linux Crash Type: Use-after-poison READ 4 Crash Address: 0x9e9456e8 Crash State: blink::MediaStreamSource::setReadyState blink::WebMediaStreamSource::setReadyState content::MediaStreamVideoSource::SetReadyState Recommended Security Severity: High Minimized Testcase (2.72 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94673Q_fmsJcMPO78u0f-PJfALz8e82LBz-cA_0STCsl7uhmbqB8z3q3XKPghGXDWMK_fa9KvRb-WQZ4fmcxjzREJlUIPCYvxWEg61gJOPh0w6WxT7BCbk29CTPsmhVUMlWVakeSrCclD0TMWF8OJRos6OYxg Additional requirements: Requires HTTP Filer: mmoroz See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Apr 12 2016
,
Apr 12 2016
,
Apr 12 2016
,
Apr 12 2016
,
Apr 14 2016
ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5003207343865856 Fuzzer: phoglund_webrtc_peerconnection Job Type: linux_asan_chrome_v8_arm Platform Id: linux Crash Type: Use-after-poison READ 4 Crash Address: 0x9e9456e8 Crash State: blink::MediaStreamSource::setReadyState blink::WebMediaStreamSource::setReadyState content::MediaStreamVideoSource::SetReadyState Recommended Security Severity: High Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=329193:329642 Minimized Testcase (2.72 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94673Q_fmsJcMPO78u0f-PJfALz8e82LBz-cA_0STCsl7uhmbqB8z3q3XKPghGXDWMK_fa9KvRb-WQZ4fmcxjzREJlUIPCYvxWEg61gJOPh0w6WxT7BCbk29CTPsmhVUMlWVakeSrCclD0TMWF8OJRos6OYxg Additional requirements: Requires HTTP See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jul 23 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 1 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
|
|||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||
Comment 1 by mmoroz@chromium.org
, Apr 11 2016Owner: perkj@chromium.org