New issue
Advanced search Search tips

Issue 605488 link

Starred by 0 users

Issue metadata

Status: Fixed
Owner:
Closed: May 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Security



Sign in to add a comment

Bad-cast to v8::internal::AstNode from invalid vptr;wasm-js.cc:138:7

Project Member Reported by ClusterFuzz, Apr 21 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5397077835644928

Fuzzer: mbarbella_js_mutation
Job Type: linux_ubsan_vptr_d8
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x0000048b51b8
Crash State:
  Bad-cast to v8::internal::AstNode from invalid vptr
  wasm-js.cc:138:7
  
Recommended Security Severity: High

Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_vptr_d8&range=383126:383185

Minimized Testcase (18.29 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94IvnVY4vzuBXULgigbKHFGw8fU-0w4O_v24HBhWEBaAplVq2E2KC5fbHo-jhcN8drf25ay4PgU_jVg47TA6L9kXfA3y48pgj0px0PECp8ozvk2ZwcHxVebl15s_eAcMTzJ59MCnZQ8lMP9D0eU9tXpHzUsctsf4yF2h-JpIs9OaEhnLaI

Filer: mmoroz

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 

Comment 1 by mmoroz@chromium.org, Apr 21 2016

Labels: Pri-1
Owner: titzer@chromium.org
titzer@, could you please take a look or suggest another owner?
Project Member

Comment 2 by ClusterFuzz, Apr 21 2016

Status: Assigned (was: Available)
Project Member

Comment 3 by sheriffbot@chromium.org, Apr 21 2016

Labels: M-52

Comment 4 by vakh@chromium.org, Apr 21 2016

Components: Blink>JavaScript>Compiler
titzer@, could you also please confirm that the Component is correct or fix it. I picked it based on some of bradnelson@'s other CLs.
Project Member

Comment 5 by ClusterFuzz, Apr 22 2016

Labels: ReleaseBlock-Beta
This medium+ severity security issue is a regression on trunk.

Please fix this asap. If you are unable to look into this soon, please revert your change.

- Your friendly ClusterFuzz
Project Member

Comment 6 by bugdroid1@chromium.org, May 3 2016

Status: Fixed (was: Assigned)
Project Member

Comment 8 by ClusterFuzz, May 3 2016

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify Merge-NA
Project Member

Comment 9 by sheriffbot@chromium.org, Aug 9 2016

Labels: -Restrict-View-SecurityNotify
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 10 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 11 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment