Crash in content::BrowserPluginEmbedder::OnAttach |
|||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5818575340437504 Fuzzer: ipc_fuzzer_gen Job Type: linux_asan_chrome_ipc Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000000 Crash State: content::BrowserPluginEmbedder::OnAttach bool IPC::MessageT<BrowserPluginHostMsg_Attach_Meta, std::__1::tuple<int, Browse content::BrowserPluginEmbedder::OnMessageReceived Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_ipc&range=399984:400026 Minimized Testcase (0.10 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96EeZaBi33y7t_9K8uIcVvSKSEEqmR7y_PZ-mAb2mEiC9IDG051rFaA7-ZFjuUs4yemaRClX89jHCrHpbii3YT7ATYV0_OYTb7oDE-89QEupT6ocb7rN39-z0E8l2D_HpGeXxKpqYe6HcTDUORmMe48QFP7EQ?testcase_id=5818575340437504 Filer: thestig See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jul 18 2016
Suspected CLs No CL in the regression range changes the crashed files. The result is the blame information. Author: fsamuel Project: chromium Changelist: https://chromium.googlesource.com/chromium/src//+/986f59179731e7970d99d9e8d1a7de43719c73bc Time: Wed Aug 27 01:11:30 2014 The CL last changed line 168 of file browser_plugin_embedder.cc, which is stack frame 0. Author: tzik Project: chromium Changelist: https://chromium.googlesource.com/chromium/src//+/55e3e4d3c52bf99bd8a710e55b1dcccea5e3acc6 Time: Tue Mar 08 05:47:44 2016 The CL last changed line 40 of file ipc_message_templates.h, which is stack frame 1. Author: mdempsky Project: chromium Changelist: https://chromium.googlesource.com/chromium/src//+/8a5190449d48e06efa581390426dfa3bb6750f4c Time: Tue Feb 09 05:41:47 2016 The CL last changed line 51 of file ipc_message_templates.h, which is stack frame 2. Author: mdempsky Project: chromium Changelist: https://chromium.googlesource.com/chromium/src//+/8a5190449d48e06efa581390426dfa3bb6750f4c Time: Tue Feb 09 05:41:47 2016 The CL last changed line 121 of file ipc_message_templates.h, which is stack frame 3. Author: fsamuel@chromium.org Project: chromium Changelist: https://chromium.googlesource.com/chromium/src//+/c453807747fc1dfb6d6829fa431fbf7a913ad5bd Time: Mon Mar 18 02:17:55 2013 The CL last changed line 129 of file browser_plugin_embedder.cc, which is stack frame 4. Author: fsamuel Project: chromium Changelist: https://chromium.googlesource.com/chromium/src//+/833ee7ced817effed9202b9cfddf85b067cf0edf Time: Fri Feb 13 23:40:40 2015 The CL last changed line 3788 of file web_contents_impl.cc, which is stack frame 5. Author: fsamuel@chromium.org Project: chromium Changelist: https://chromium.googlesource.com/chromium/src//+/c453807747fc1dfb6d6829fa431fbf7a913ad5bd Time: Mon Mar 18 02:17:55 2013 The CL last changed line 714 of file web_contents_impl.cc, which is stack frame 6. Suspected Project: chromium Suspected Component: Internals>Core Possible suspect : https://chromium.googlesource.com/chromium/src//+/986f59179731e7970d99d9e8d1a7de43719c73bc Please reassign if this is not related to your change.
,
Jul 20 2016
,
Aug 10 2016
ClusterFuzz has detected this issue as fixed in range 410634:410757. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5818575340437504 Fuzzer: ipc_fuzzer_gen Job Type: linux_asan_chrome_ipc Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000000 Crash State: content::BrowserPluginEmbedder::OnAttach bool IPC::MessageT<BrowserPluginHostMsg_Attach_Meta, std::__1::tuple<int, Browse content::BrowserPluginEmbedder::OnMessageReceived Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_ipc&range=399984:400026 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_ipc&range=410634:410757 Minimized Testcase (0.10 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96EeZaBi33y7t_9K8uIcVvSKSEEqmR7y_PZ-mAb2mEiC9IDG051rFaA7-ZFjuUs4yemaRClX89jHCrHpbii3YT7ATYV0_OYTb7oDE-89QEupT6ocb7rN39-z0E8l2D_HpGeXxKpqYe6HcTDUORmMe48QFP7EQ?testcase_id=5818575340437504 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Aug 10 2016
ClusterFuzz testcase is verified as fixed, closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||
►
Sign in to add a comment |
|||||
Comment 1 by thestig@chromium.org
, Jul 16 2016