New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 627351 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner:
Closed: Jul 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Security



Sign in to add a comment

Bad-cast to blink::WebGLObject from invalid vptr;blink::WebGLProgram::deleteObjectImpl;blink::WebGLSharedObject::detachContextGroup

Project Member Reported by ClusterFuzz, Jul 12 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5949856401326080

Fuzzer: inferno_twister_custom_bundle
Job Type: linux_ubsan_vptr_content_shell_drt
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x25990f494638
Crash State:
  Bad-cast to blink::WebGLObject from invalid vptr
  blink::WebGLProgram::deleteObjectImpl
  blink::WebGLSharedObject::detachContextGroup
  
Recommended Security Severity: High

Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_vptr_content_shell_drt&range=404473:404506

Minimized Testcase (50.09 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96iGsON7UH4VX13H-myTKYwJjmvpd9XP2FkKy0H8-OzYXmztH01cPAwt-UoHwM91YR9jE4zwlk3qLjKfbnWvszlI45pVIWvJoxdSeYRwbVT8Ou3LZHZoUOXvPANoqg4IXFpxZhlzSBPFfUy3WfLM-79aXU_cdXT2slKaa1SXK8XAIZPc8Q?testcase_id=5949856401326080

Filer: ochang

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Project Member

Comment 1 by sheriffbot@chromium.org, Jul 12 2016

Labels: M-52
Project Member

Comment 2 by sheriffbot@chromium.org, Jul 12 2016

Labels: ReleaseBlock-Stable
Project Member

Comment 3 by sheriffbot@chromium.org, Jul 12 2016

Labels: Pri-1

Comment 4 by ta...@google.com, Jul 13 2016

Components: Blink>WebGL
Owner: infe...@chromium.org
Status: Assigned (was: Available)
inferno@, could you take a look at this? It's similar to 	https://bugs.chromium.org/p/chromium/issues/detail?id=619377 (#619377)

Comment 5 by gov...@chromium.org, Jul 14 2016

Cc: awhalley@chromium.org
A friendly reminder that M52 Stable is launching soon! Your bug is labelled as Stable ReleaseBlock, pls make sure to land the fix and get it merged into the release branch by July 15, 5:00 PM PS in order to make into the desktop Stable final build cut. Thank you!


Comment 6 by aarya@google.com, Jul 15 2016

Cc: kbr@chromium.org
Status: WontFix (was: Assigned)
Can't reproduce this locally, this looks like a vm only issue. Closing.
Labels: -ReleaseBlock-Stable
Project Member

Comment 8 by ClusterFuzz, Jul 16 2016

ClusterFuzz has detected this issue as fixed in range 405563:405613.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5949856401326080

Fuzzer: inferno_twister_custom_bundle
Job Type: linux_ubsan_vptr_content_shell_drt
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x25990f494638
Crash State:
  Bad-cast to blink::WebGLObject from invalid vptr
  blink::WebGLProgram::deleteObjectImpl
  blink::WebGLSharedObject::detachContextGroup
  
Recommended Security Severity: High

Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_vptr_content_shell_drt&range=404473:404506
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_vptr_content_shell_drt&range=405563:405613

Minimized Testcase (50.09 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96iGsON7UH4VX13H-myTKYwJjmvpd9XP2FkKy0H8-OzYXmztH01cPAwt-UoHwM91YR9jE4zwlk3qLjKfbnWvszlI45pVIWvJoxdSeYRwbVT8Ou3LZHZoUOXvPANoqg4IXFpxZhlzSBPFfUy3WfLM-79aXU_cdXT2slKaa1SXK8XAIZPc8Q?testcase_id=5949856401326080

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 9 by sheriffbot@chromium.org, Oct 22 2016

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment