New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 604666 link

Starred by 0 users

Issue metadata

Status: Duplicate
Owner:
Use other robhogan account instead.
Closed: Apr 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Security



Sign in to add a comment

Heap-use-after-free in blink::LayoutTableSection::computeOverflowFromCells

Project Member Reported by ClusterFuzz, Apr 19 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4832986549190656

Fuzzer: attekett_dom_fuzzer
Job Type: linux_asan_chrome_media
Platform Id: linux

Crash Type: Heap-use-after-free READ 4
Crash Address: 0x6110000295e8
Crash State:
  blink::LayoutTableSection::computeOverflowFromCells
  blink::LayoutTableSection::recalcChildOverflowAfterStyleChange
  blink::LayoutTable::recalcChildOverflowAfterStyleChange
  
Recommended Security Severity: High

Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_media&range=387601:387928

Minimized Testcase (1.38 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95NvUOyhHjRjfCNDsvyVfehabK_690gTYQJHPhQjRctoEraV4q_Js7bD0FvsvySPv4Po_FT1LiXg808wW7CsIaQF8yPXVBcORHiNzjY4LxzK5vZeBNsMHBp5g_Flefa1_nstM2jXkpOxhT-LAL6kY7jXAuffA

Filer: mmoroz

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 

Comment 1 by mmoroz@chromium.org, Apr 19 2016

Owner: e...@chromium.org
Project Member

Comment 2 by ClusterFuzz, Apr 19 2016

Labels: Pri-1
Status: Assigned (was: Available)
Project Member

Comment 3 by sheriffbot@chromium.org, Apr 19 2016

Labels: M-52
Components: Blink>Layout
Cc: e...@chromium.org mmoroz@chromium.org
 Issue 604667  has been merged into this issue.

Comment 6 by e...@chromium.org, Apr 19 2016

Owner: robhogan@chromium.org
This looks like a regression from r387862 I'm afraid robhogan.
https://codereview.chromium.org/1809643008

Would you mind taking a look?

Mergedinto: 604664
Status: Duplicate (was: Assigned)
This issue owns the 604664 to 604667 range!
Project Member

Comment 8 by sheriffbot@chromium.org, Apr 20 2016

Labels: -reward-topanel reward-ineligible
Project Member

Comment 9 by sheriffbot@chromium.org, Jul 28 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 10 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 11 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment