New issue
Advanced search Search tips

Issue 624820 link

Starred by 1 user

Issue metadata

Status: Duplicate
Owner:
Closed: Jul 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 1
Type: Bug-Security



Sign in to add a comment

Corrupt-block in sk_free_releaseproc

Project Member Reported by ClusterFuzz, Jun 30 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5547850801086464

Fuzzer: bj_broddelwerk
Job Type: windows_syzyasan_chrome
Platform Id: windows

Crash Type: Corrupt-block
Crash Address: 0x7fff2030
Crash State:
  sk_free_releaseproc
  CXML_DataBufAcc::Release
  SkBitmap::~SkBitmap
  

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv96YZR90TvdYw7w0otGGwEMRYUwIA9_vMq2BQ5SIpnEMZmlO0Qje12oQJipTJ_Gjl-h0nLCjkGONlKZqEYx08jMKizNbDiJ-kNzOBW3YhM3ntXNwOohfWd7OvuMrKmrDthGpDGuTtqL7X922RM9ksTB1o9bkPhFZJx3dwOgbVRYR1RbHsRM?testcase_id=5547850801086464


Filer: mbarbella

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 

Comment 1 by palmer@chromium.org, Jun 30 2016

Components: Internals>Skia
Labels: Security_Impact-Stable M-53
Owner: reed@chromium.org
Status: Assigned (was: Available)
Project Member

Comment 2 by sheriffbot@chromium.org, Jul 1 2016

Labels: Pri-1
Project Member

Comment 3 by ClusterFuzz, Jul 13 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5701644872581120

Fuzzer: inferno_layout_test_unmodified
Job Type: windows_syzyasan_chrome
Platform Id: windows

Crash Type: Corrupt-block
Crash Address: 0x7fff1030
Crash State:
  sk_free_releaseproc
  CXML_DataBufAcc::Release
  SkBitmap::~SkBitmap
  

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv950lK3dG4zKN2tSQETK-mu7K_ZuNPc_PSLuIIezLnDYIwU88bA4_jNW2cxnGbFaLg3zjwJLJXXOePGCaZ7Q22ieHFU7P7yaQ-NVV1ji7olROw7N34KBo7taeCCFhaOMFqctLVrTuHQO2MEY0ibArojMVlf5NQ?testcase_id=5701644872581120


Filer: mmoroz

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
Project Member

Comment 4 by sheriffbot@chromium.org, Jul 15 2016

reed: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers?

If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one?

If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 5 by reed@chromium.org, Jul 15 2016

Owner: reed@google.com
Labels: -ClusterFuzz Clusterfuzz
Mergedinto: 627455
Status: Duplicate (was: Assigned)
Project Member

Comment 7 by sheriffbot@chromium.org, Dec 6 2016

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment