Crash in blink::HTMLTextFormControlElement::setInnerEditorValue |
|||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4859060105248768 Fuzzer: inferno_twister Job Type: windows_syzyasan_content_shell Platform Id: windows Crash Type: UNKNOWN Crash Address: 0x00000027 Crash State: blink::HTMLTextFormControlElement::setInnerEditorValue blink::HTMLTextAreaElement::setValueCommon blink::HTMLTextAreaElement::childrenChanged Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_content_shell&range=402095:402107 Minimized Testcase (2.71 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96lQs3gWdZ1jsplIePx1jZXkHKNU3l7N4eJylhSlLut5WyrI7Kh9DM9q69esPbZ0RrXJjkce_Y8oZdiiLMbI3RSX27gvf8rL4IEP_IW7rUrrOu5R3auBm6o39nBPLic_v4Qmg_uxl2FJ13HEhJUU86RLHC-SQ?testcase_id=4859060105248768 Filer: mmohammad See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Nov 1 2016
The stacktrace doesn't even include V8; which is just calling out to blink here. There is also no V8 roll in the regression range.
,
Nov 9 2016
,
Nov 10 2016
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||
►
Sign in to add a comment |
|||||
Comment 1 by mmohammad@chromium.org
, Jun 27 2016Status: Assigned (was: Available)