Null crash in blink::SimpleFontData::isTextOrientationFallbackOf |
|||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5295890990628864 Fuzzer: attekett_dom_fuzzer Job Type: linux_asan_chrome_v8_arm Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x00000494 Crash State: blink::SimpleFontData::isTextOrientationFallbackOf blink::ShapeResult::fallbackFonts blink::CachingWordShaper::width Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=379622:379959 Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv96DocJWIMd7bxKorQkQsrW3726E6GiN3lNnkVUMQtt6GCcr8oUphswbitOuRQIplt5XtoI5LTmnDVtpS0Yt9la5F7GuXoc-gSETHFUR3M_j60Qs14940H6L99s7ABm5qoAhc-00QXpIWi5bg9DsxmIydtbZCw?testcase_id=5295890990628864 Filer: nyerramilli See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jul 22 2016
I've re-done the regressed, blame, and fixed tasks for this on clusterfuzz. I don't think my patch is related. It looks like m_fontData is null but it's not clear how. A null deref should probably be P2 instead of P1. Opening this up to Blink>Fonts. Note: you'll need to run a local server for this to repro: python -m SimpleHTTPServer, then hit localhost:8000/fuzz-104.html
,
Jul 25 2016
,
Jul 25 2016
,
Jul 25 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/63402c5b51408d48710846f739fe07b2d1b19d1e commit 63402c5b51408d48710846f739fe07b2d1b19d1e Author: eae <eae@chromium.org> Date: Mon Jul 25 23:36:39 2016 Add null-check to ShapeResult::fallbackFonts Add a null check for m_runs[i]->m_fontData in ShapeResult::fallbackFonts to ensure that isTextOrientationFallbackOf is only called when it's set. TBR=pdr@chromium.org BUG= 629005 Review-Url: https://codereview.chromium.org/2177163003 Cr-Commit-Position: refs/heads/master@{#407633} [modify] https://crrev.com/63402c5b51408d48710846f739fe07b2d1b19d1e/third_party/WebKit/Source/platform/fonts/shaping/ShapeResult.cpp
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||
►
Sign in to add a comment |
|||||
Comment 1 by nyerramilli@chromium.org
, Jul 18 2016Components: Tools>Test>FindIt>CorrectResult
Labels: findit-for-crash Te-Logged M-52
Owner: pdr@chromium.org
Status: Assigned (was: Available)