New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 603925 link

Starred by 0 users

Issue metadata

Status: WontFix
Owner: ----
Closed: May 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Security



Sign in to add a comment

Heap-buffer-overflow in content::ResourceDispatcher::OnMessageReceived

Project Member Reported by ClusterFuzz, Apr 15 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6600113463492608

Fuzzer: inferno_flicker
Job Type: linux_asan_chrome_chromeos
Platform Id: linux

Crash Type: Heap-buffer-overflow READ 8
Crash Address: 0x603000011be0
Crash State:
  content::ResourceDispatcher::OnMessageReceived
  content::DispatchMessageTask::run
  base::internal::Invoker<base::IndexSequence<0ul>, base::internal::BindState<base
  
Recommended Security Severity: Medium

Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_chromeos&range=372832:372879

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97YwLs8jznNLRFcosbOIJrib14PebfjUEyJNaN6WhTpAGvZzUSlG0A5oNdhgwBBpqbW7P64p84Jhw6c5vjCiijys8bAsbUDVEwE3C7RQeeId85DRSYW4zd2JY3h58rBu4iGdLLNzQlDzc59p-S1Qbsrfwg4Bb5ukT5BhfhiLQuo3xlCBzI


Filer: mmoroz

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 

Comment 1 by mmoroz@chromium.org, Apr 15 2016

Cc: alexclarke@chromium.org
Labels: Pri-2
Owner: skyos...@chromium.org
skyostil@, do you mind to take a look or suggest another owner?

Comment 2 by tsepez@chromium.org, Apr 15 2016

Components: Content>Core
Labels: M-50
Project Member

Comment 3 by ClusterFuzz, Apr 15 2016

Labels: -Pri-2 Pri-1
Status: Assigned (was: Available)
Project Member

Comment 4 by sheriffbot@chromium.org, Apr 16 2016

Labels: -Security_Impact-Beta Security_Impact-Stable
Project Member

Comment 5 by sheriffbot@chromium.org, Apr 30 2016

skyostil: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers?

If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one?

If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Cc: skyos...@chromium.org
Owner: ----
Status: Available (was: Assigned)
Sorry, I'm not sure how this ended up on my plate? I don't really work on ResourceDispatcher that often.

Comment 7 by f...@chromium.org, May 6 2016

Cc: -skyos...@chromium.org
Owner: mek@chromium.org
Status: Assigned (was: Available)
My guess is that the bug is with something doing IPC, not necessarily an actual change to ResourceDispatcher. mek@, could you investigate whether it's https://chromium.googlesource.com/chromium/src/+/68eb197178f87cc8c25187c685080e69f4156262 (it's in the revision range)?

Comment 8 by mek@chromium.org, May 9 2016

Cc: mek@chromium.org
Owner: ----
Status: Available (was: Assigned)
It seems extremely unlikely that my change had anything to do with this, as none of the code in that CL would ever run unless an actual service worker is installed (which is not the case in the clusterfuzz test).
Also I can't reproduce the crash at ToT (and don't seem to be able to build an ASAN build as of 3 months ago which seems to be when clusterfuzz found the bug, so I don't even know if the bug is still valid.

Comment 9 by mmoroz@chromium.org, May 10 2016

Cc: mbarbe...@chromium.org
Status: WontFix (was: Available)
Hm, ClusterFuzz also has "Reproducible: No" flag now.

Thanks everyone.
Project Member

Comment 10 by sheriffbot@chromium.org, Aug 16 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 11 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 12 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment