New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 627441 link

Starred by 1 user

Issue metadata

Status: Duplicate
Owner:
Closed: Jul 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 1
Type: Bug-Security



Sign in to add a comment

Corrupt-block in sk_free_releaseproc

Project Member Reported by ClusterFuzz, Jul 12 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4862819640279040

Fuzzer: bj_broddelwerk
Job Type: windows_syzyasan_chrome
Platform Id: windows

Crash Type: Corrupt-block
Crash Address: 0x7fff8030
Crash State:
  sk_free_releaseproc
  content::ServiceWorkerDispatcher::WillStopCurrentWorkerThread
  SkBitmap::~SkBitmap
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_chrome&range=404161:404191

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv95wbPsRLEtBw62y7fQLzdluYobLUoAByMzNmOi41ZQOSWzQUjqNShN4tObi_UN9WxqyB9KuMJzeSFh28nx4bG7qtEJ_Qz7JSVRnl_SNsT_UJI2UKVwJ0Hb6iHCNffa3j-hJe46mvv1poVIVhLCygiWZ1e2Zs9gEWO-k-0ZadT-Wxo1WUgY?testcase_id=4862819640279040


Filer: mmoroz

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 

Comment 1 by mmoroz@chromium.org, Jul 12 2016

Components: Internals>Skia
Owner: reed@chromium.org
Looks similar to  bug 623991  and  bug 624820 , but since stacktraces are different, I file it separately for now.
Project Member

Comment 2 by sheriffbot@chromium.org, Jul 12 2016

Labels: M-53
Project Member

Comment 3 by sheriffbot@chromium.org, Jul 12 2016

Labels: ReleaseBlock-Beta
This issue is a security regression. If you are not able to fix this quickly, please revert the change that introduced it.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 4 by sheriffbot@chromium.org, Jul 12 2016

Labels: Pri-1
Project Member

Comment 5 by sheriffbot@chromium.org, Jul 12 2016

Status: Assigned (was: Available)

Comment 6 by reed@chromium.org, Jul 12 2016

Cc: reed@chromium.org
Owner: reed@google.com

Comment 7 by gov...@chromium.org, Jul 14 2016

M53 beta launch is coming soon.Your bug is labelled as Beta ReleaseBlock, pls make sure to land the fix before 6:00 PM PST, Monday (07/18/16). Thank you.
Project Member

Comment 8 by ClusterFuzz, Jul 18 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5473675424038912

Fuzzer: inferno_layout_test_unmodified
Job Type: windows_syzyasan_chrome
Platform Id: windows

Crash Type: Corrupt-block
Crash Address: 0x7fffd030
Crash State:
  sk_free_releaseproc
  ui::AXNode::Destroy
  SkBitmap::~SkBitmap
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_chrome&range=405844:405858

Minimized Testcase (12.98 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97cVVO6suAjtSiA55KQ-cpCOOEwrtq4KUZyg1k4GKh6s_re8-O8Z-LYmVBBUh5A1Yif1pRmRUMTmIFVhpeKt2_W5trlCSlBpuwmhs2Qb1SrEvAA7KRvgLiuVtjhTDRT6-3bBdSBE7oUC0I0JxPTP_10ovug0w?testcase_id=5473675424038912

Filer: mmoroz

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

Comment 9 by gov...@chromium.org, Jul 19 2016

M53 beta launch is next week.Your bug is labelled as Beta ReleaseBlock, pls make sure to land the fix before 6:00 PM PST, Friday (07/22/16). Thank you.
Project Member

Comment 10 by sheriffbot@chromium.org, Jul 21 2016

Labels: -Security_Impact-Head Security_Impact-Beta
Project Member

Comment 11 by sheriffbot@chromium.org, Jul 21 2016

Labels: -ReleaseBlock-Beta ReleaseBlock-Stable
Mergedinto: 627455
Status: Duplicate (was: Assigned)
Labels: -ReleaseBlock-Stable
Project Member

Comment 14 by sheriffbot@chromium.org, Dec 6 2016

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment