Crash in v8::internal::Object::SetPropertyInternal |
|||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4951520479281152 Fuzzer: inferno_twister_custom_bundle Job Type: windows_syzyasan_chrome Platform Id: windows Crash Type: UNKNOWN Crash Address: 0x00000014 Crash State: v8::internal::Object::SetPropertyInternal v8::internal::Object::SetProperty v8::internal::Runtime::SetObjectProperty Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_chrome&range=404473:404552 Minimized Testcase (2.45 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97pyQOZFOD6CyzkeX3ePDqVF6zIaPsyGG79lPGjJyscoWmcn-S0HMHyLBk4pjIl3GfI2EJO8MIz2BtU_QfGrEOaxzfF0ufyRzZRdYAAL7CyX8Jlz1kQsP6jtaAacxRqmzTRc5iotBxUc3iMkGc2IMAEBYBnnA?testcase_id=4951520479281152 Filer: ajha See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jul 13 2016
Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5836563468779520 Fuzzer: inferno_twister Job Type: mac_asan_content_shell Platform Id: mac Crash Type: UNKNOWN READ Crash Address: 0x0007ffffffff Crash State: v8::internal::Object::SetPropertyInternal v8::internal::Object::SetProperty v8::internal::StoreIC::Store Recommended Security Severity: Medium Regressed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_content_shell&range=401149:401251 Minimized Testcase (2.38 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95ywcF5DaMETFQ7Yf15Qc32V-Lipobc7qKxAjdLLTEaXwQbwGqQwEf3DSr5spYe8_cuB5wd0swN6vDC3VIQ54Qfk3OEWY3aq-c67ddI96a8XV60gUYFnuKTYT2nSTvauGQipfikk-RH24K0idHnhhUHv2-ugw?testcase_id=5836563468779520 Filer: mmoroz See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jul 13 2016
Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6246493954768896 Fuzzer: inferno_twister Job Type: windows_syzyasan_chrome Platform Id: windows Crash Type: UNKNOWN Crash Address: 0x00000006 Crash State: v8::internal::Object::SetPropertyInternal v8::internal::Object::SetProperty v8::internal::StoreIC::Store Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_chrome&range=404473:404552 Minimized Testcase (2.08 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96KXnM9iniwOBNIHpUWQ1C9OznS-BEEppN1Lqtp3X7iVcceEZMtV-m0ACQzt0CN_d9He_s-vZUeBLdvNWuIjnHxzG3eG-tbVvrUlK7s1q-Vkhae6wvW2FN8PXVq0V5u42uJbLCLNdGavzdz98h09Ztx8Z8KiA?testcase_id=6246493954768896 Filer: rnimmagadda See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jul 20 2016
Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4867856596729856 Fuzzer: inferno_twister_custom_bundle Job Type: linux_asan_chrome_mp Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000000 Crash State: v8::internal::Object::SetPropertyInternal v8::internal::Object::SetProperty v8::internal::Runtime::SetObjectProperty Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_mp&range=401117:401251 Minimized Testcase (2.71 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94FeSkWazFWiExM2UH8zjKKBvWky2dgZ4rEfD3oJVcnIIVI1XuJ1EVhbHo911ZUTzY6HBk1rPuW8qs1U_NRM6g9T3YOedSkqz3SvifA2OpFZMkmlVqdSJj8XUY_tPYAiWD8IIFe0OAjTLqJnpwtyCRXRxpsVw?testcase_id=4867856596729856 Filer: brajkumar See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jul 25 2016
,
Jul 27 2016
ClusterFuzz has detected this issue as fixed in range 407480:407721. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4867856596729856 Fuzzer: inferno_twister_custom_bundle Job Type: linux_asan_chrome_mp Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000000 Crash State: v8::internal::Object::SetPropertyInternal v8::internal::Object::SetProperty v8::internal::Runtime::SetObjectProperty Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_mp&range=401117:401251 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_mp&range=407480:407721 Minimized Testcase (2.71 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94FeSkWazFWiExM2UH8zjKKBvWky2dgZ4rEfD3oJVcnIIVI1XuJ1EVhbHo911ZUTzY6HBk1rPuW8qs1U_NRM6g9T3YOedSkqz3SvifA2OpFZMkmlVqdSJj8XUY_tPYAiWD8IIFe0OAjTLqJnpwtyCRXRxpsVw?testcase_id=4867856596729856 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||
►
Sign in to add a comment |
|||
Comment 1 by ajha@chromium.org
, Jul 13 2016Components: Blink>JavaScript
Labels: Te-Logged