Issue metadata
Sign in to add a comment
|
Bad-cast to v8::internal::AstNode from invalid vptr;wasm-js.cc:138:7 |
||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5397077835644928 Fuzzer: mbarbella_js_mutation Job Type: linux_ubsan_vptr_d8 Platform Id: linux Crash Type: Bad-cast Crash Address: 0x0000048b51b8 Crash State: Bad-cast to v8::internal::AstNode from invalid vptr wasm-js.cc:138:7 Recommended Security Severity: High Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_vptr_d8&range=383126:383185 Minimized Testcase (18.29 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94IvnVY4vzuBXULgigbKHFGw8fU-0w4O_v24HBhWEBaAplVq2E2KC5fbHo-jhcN8drf25ay4PgU_jVg47TA6L9kXfA3y48pgj0px0PECp8ozvk2ZwcHxVebl15s_eAcMTzJ59MCnZQ8lMP9D0eU9tXpHzUsctsf4yF2h-JpIs9OaEhnLaI Filer: mmoroz See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Apr 21 2016
,
Apr 21 2016
,
Apr 21 2016
titzer@, could you also please confirm that the Component is correct or fix it. I picked it based on some of bradnelson@'s other CLs.
,
Apr 22 2016
This medium+ severity security issue is a regression on trunk. Please fix this asap. If you are unable to look into this soon, please revert your change. - Your friendly ClusterFuzz
,
May 3 2016
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/98c231299564bbc200bff8b5acbf5ebe643918a2 commit 98c231299564bbc200bff8b5acbf5ebe643918a2 Author: titzer <titzer@chromium.org> Date: Tue May 03 11:14:01 2016 [wasm] Fix bug with empty input to Wasm.instantiateModuleFromAsm() R=ahaas@chromium.org,bradnelson@chromium.org BUG= chromium:605488 LOG=Y Review-Url: https://codereview.chromium.org/1940243002 Cr-Commit-Position: refs/heads/master@{#35974} [modify] https://crrev.com/98c231299564bbc200bff8b5acbf5ebe643918a2/src/wasm/wasm-js.cc [add] https://crrev.com/98c231299564bbc200bff8b5acbf5ebe643918a2/test/mjsunit/regress/regress-605488.js
,
May 3 2016
,
May 3 2016
,
Aug 9 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 1 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
|
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by mmoroz@chromium.org
, Apr 21 2016Owner: titzer@chromium.org