New issue
Advanced search Search tips

Issue 624935 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Nov 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Crash in blink::TimerBase::TimerBase

Project Member Reported by ClusterFuzz, Jun 30 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6054051351625728

Fuzzer: afl_renderer_fuzzer
Job Type: afl_chrome_asan
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000000
Crash State:
  blink::TimerBase::TimerBase
  blink::ResourceFetcher::ResourceFetcher
  blink::ResourceFetcher::create
  

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv96JIBpK91G3NvDsT8hJj8fUpWJF2jgB2DK5T9OEYzatKurt4apGZEobZuJYkZaUWX2j8aXs0R8wEF4NjLTCpNAGjJa3Yix7ZHAZTwSvyk2rRNnEjw_ssTEpsnTYjRAuXP96GYukDmfB1FJCsNnx3IMoiDbVkw?testcase_id=6054051351625728


Filer: mmohammad

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Owner: japhet@chromium.org
Status: Assigned (was: Available)
Suspected CL could be
https://chromium.googlesource.com/chromium/src/+/99d88a6fd4fed13ef44a24800f2bf79da69abc7e%5E%21/third_party/WebKit/Source/core/fetch/ResourceFetcher.cpp

Last updated by japhet @ weeks ago , please have a look and reassign if needed.

Thank you.
Cc: hirosh...@chromium.org
Project Member

Comment 3 by ClusterFuzz, Jul 14 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5929631802982400

Fuzzer: afl_renderer_fuzzer
Job Type: afl_chrome_asan
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x000000000000
Crash State:
  blink::TimerBase::TimerBase
  blink::ResourceFetcher::ResourceFetcher
  blink::ResourceFetcher::create
  

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97iE8ve9MASSzl-nTf1QQCVIbBJKFT0WUXmqvUxOwajglmTRbRplPh1LFehT4LwP8XTCde5a2dWdDJM6RH34lWEUp93H-P15Bc-pRjkrZ6CyxEVQyYEx_iuvUyU_0h_xTJPj32FaUcjTtVs5H0T3y9DG4FEYw?testcase_id=5929631802982400


Filer: mmohammad

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

Comment 4 by japhet@chromium.org, Sep 30 2016

Labels: -ClusterFuzz Clusterfuzz
I think I ran this test correctly locally, but I wasn't able to reproduce the crash.

Given the nature of it, I'm strongly suspicious that it's a test harness problem rather than a production bug.

Comment 5 by japhet@chromium.org, Nov 21 2016

Status: WontFix (was: Assigned)
Ok, clusterfuzz couldn't repro either. Closing.
Project Member

Comment 6 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment