New issue
Advanced search Search tips

Issue 621114 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Jul 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Use-of-uninitialized-value in v8::internal::LookupIterator::Delete

Project Member Reported by ClusterFuzz, Jun 17 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6621787966406656

Fuzzer: mbarbella_js_mutation
Job Type: linux_msan_d8
Platform Id: linux

Crash Type: Use-of-uninitialized-value
Crash Address: 
Crash State:
  v8::internal::LookupIterator::Delete
  v8::internal::JSReceiver::DeleteProperty
  v8::internal::DeleteProperty
  
Recommended Security Severity: Medium


Minimized Testcase (7.60 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96h4gia-atE1RXNmkdscxqBbC8luD54DOkpiVnUVPmvrEClZ_GwKrWDA1d1mBdvpUGB3nwSskkM7SCFm-eZb2aNzj8r4b4aJEOsbWd_Oo_enEXPm05sAXRbcZo-VuohmJTlnUFsJWrz45BqQZhKhhfQQVWjqQ

Filer: mmoroz

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 

Comment 1 by mmoroz@chromium.org, Jun 17 2016

Owner: verwa...@chromium.org
verwaest@, could you please take a look or suggest another owner?
Project Member

Comment 2 by ClusterFuzz, Jun 17 2016

Status: Assigned (was: Available)

Comment 3 by est...@chromium.org, Jun 17 2016

Labels: M-53
Project Member

Comment 4 by sheriffbot@chromium.org, Jun 18 2016

Labels: Security_Impact-Head
Project Member

Comment 5 by sheriffbot@chromium.org, Jun 18 2016

Labels: ReleaseBlock-Beta
This issue is a security regression. If you are not able to fix this quickly, please revert the change that introduced it.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 6 by sheriffbot@chromium.org, Jun 18 2016

Labels: Pri-1
Cc: -ishell@chromium.org -mstarzinger@chromium.org jarin@chromium.org
Owner: mstarzinger@chromium.org
Crashes as out/x64.debug/d8 --random-seed=-1023152996 --allow-natives-syntax  fuzz-03183.js 

Probably just heap corruption due to --turbo-escape (which doesn't ship yet afaik)

Comment 8 by gov...@chromium.org, Jun 23 2016

M53 is branching soon and will be promoted to Beta in July.Your bug is labelled as Beta ReleaseBlock, pls make sure to land the fix ASAP. Thank you. 

Comment 9 by jarin@chromium.org, Jun 24 2016

Labels: -ReleaseBlock-Beta -Security_Severity-Medium -Security_Impact-Head
This is not a security issue - we are not shipping escape analysis.

Comment 10 by jarin@chromium.org, Jun 24 2016

Labels: -Type-Bug-Security Type-Bug
Labels: -Pri-1 -M-53 Pri-2
Agree with comment #7 and #9. Same underlying problem as  issue 613923  and produces same assert in debug mode.
Project Member

Comment 12 by ClusterFuzz, Jul 5 2016

ClusterFuzz has detected this issue as fixed in range 403457:403659.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6621787966406656

Fuzzer: mbarbella_js_mutation
Job Type: linux_msan_d8
Platform Id: linux

Crash Type: Use-of-uninitialized-value
Crash Address: 
Crash State:
  v8::internal::LookupIterator::Delete
  v8::internal::JSReceiver::DeleteProperty
  v8::internal::DeleteProperty
  
Recommended Security Severity: Medium

Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_msan_d8&range=403457:403659

Minimized Testcase (7.60 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96h4gia-atE1RXNmkdscxqBbC8luD54DOkpiVnUVPmvrEClZ_GwKrWDA1d1mBdvpUGB3nwSskkM7SCFm-eZb2aNzj8r4b4aJEOsbWd_Oo_enEXPm05sAXRbcZo-VuohmJTlnUFsJWrz45BqQZhKhhfQQVWjqQ?testcase_id=6621787966406656

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 13 by ClusterFuzz, Jul 5 2016

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase is verified as fixed, closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 14 by sheriffbot@chromium.org, Jul 6 2016

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Project Member

Comment 15 by sheriffbot@chromium.org, Oct 12 2016

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment