New issue
Advanced search Search tips

Issue 613906 link

Starred by 0 users

Issue metadata

Status: Duplicate
Merged: issue 613907
Owner:
Closed: Jun 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Security



Sign in to add a comment

Use-of-uninitialized-value in blink::LayoutBox::markForPaginationRelayoutIfNeeded

Project Member Reported by ClusterFuzz, May 23 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5725601440989184

Fuzzer: inferno_twister
Job Type: linux_msan_chrome
Platform Id: linux

Crash Type: Use-of-uninitialized-value
Crash Address: 
Crash State:
  blink::LayoutBox::markForPaginationRelayoutIfNeeded
  blink::LayoutTableSection::layout
  blink::FrameView::performLayout
  
Recommended Security Severity: Medium

Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_msan_chrome&range=394251:394739

Minimized Testcase (0.33 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94AG02xAcH9G2BmKQKOUZgNpcNhfkonu7fmsm1ACwqUu4AHBM1bLGXA1Vbs35kjJAF626IfXWC5UCwwGg49qJXpaIE0oNf6447zcSRm-wiwjKVQCI31D081HMtMYM-Eq1pH3PQu-s5ovH8xXlNrjbsgYfNNdA

Filer: inferno

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Project Member

Comment 1 by sheriffbot@chromium.org, May 23 2016

Labels: Pri-1

Comment 2 by est...@chromium.org, May 23 2016

Components: Blink>Layout
Owner: e...@chromium.org
eae@, could you please take a look at this? It looks like it might be related to issue 402056?

Comment 3 by e...@chromium.org, May 23 2016

Owner: dgro...@chromium.org
Do you have enough bandwidth to look into this security bug David?

See https://www.chromium.org/developers/testing/addresssanitizer for instructions for an asan build (which is needed to reproduce) it.

If not, please assign back to me.

Project Member

Comment 4 by ClusterFuzz, May 24 2016

Status: Assigned (was: Available)

Comment 5 by est...@chromium.org, May 25 2016

dgrogan@, we're doing a security fix-it this week; any chance you could look into it this week if you haven't already? Thanks!
Cc: est...@chromium.org
I plan to start on it this week but probably won't finish.

Comment 7 by mea...@chromium.org, May 27 2016

Labels: M-53
Project Member

Comment 8 by sheriffbot@chromium.org, May 28 2016

Labels: ReleaseBlock-Beta
This issue is a security regression. If you are not able to fix this quickly, please revert the change that introduced it.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Cc: -est...@chromium.org
Status: Started (was: Assigned)
Mergedinto: 613907
Status: Duplicate (was: Started)
Project Member

Comment 11 by ClusterFuzz, Jun 3 2016

ClusterFuzz has detected this issue as fixed in range 397421:397444.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5725601440989184

Fuzzer: inferno_twister
Job Type: linux_msan_chrome
Platform Id: linux

Crash Type: Use-of-uninitialized-value
Crash Address: 
Crash State:
  blink::LayoutBox::markForPaginationRelayoutIfNeeded
  blink::LayoutTableSection::layout
  blink::FrameView::performLayout
  
Recommended Security Severity: Medium

Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_msan_chrome&range=394251:394739
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_msan_chrome&range=397421:397444

Minimized Testcase (0.33 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94AG02xAcH9G2BmKQKOUZgNpcNhfkonu7fmsm1ACwqUu4AHBM1bLGXA1Vbs35kjJAF626IfXWC5UCwwGg49qJXpaIE0oNf6447zcSRm-wiwjKVQCI31D081HMtMYM-Eq1pH3PQu-s5ovH8xXlNrjbsgYfNNdA

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 12 by sheriffbot@chromium.org, Sep 9 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 13 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 14 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment