New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 629280 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Last visit > 30 days ago
Closed: Jul 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 1
Type: Bug



Sign in to add a comment

Crash in blink::protocol::String16::String16

Project Member Reported by ClusterFuzz, Jul 18 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5973030224527360

Fuzzer: inferno_twister
Job Type: mac_asan_content_shell
Platform Id: mac

Crash Type: UNKNOWN READ
Crash Address: 0x000000000000
Crash State:
  blink::protocol::String16::String16
  blink::protocol::toValue
  blink::protocol::Runtime::RemoteObject::serialize
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_content_shell&range=403906:404161

Minimized Testcase (532.24 Kb): https://cluster-fuzz.appspot.com/download/AMIfv952w7BR7eRc61QK7eGsc41wt1y4ZC9BQtwV6hVAzwrVc2yhPwIyjh9a0J1gR_7KVkvLj9AQ4JZvUVu6hg6PG6OHAYHFvoPBUc8xdXhzq8L90tWB0YGNlr7StMXTDOw5Fdez-gj18Hfm57BI8PjzmjCUsDG_xx2xZf9Ajj9YOnDKcClWZDI?testcase_id=5973030224527360

Filer: mummareddy

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Labels: M-54 Te-Logged
Owner: pfeldman@chromium.org
Status: Assigned (was: Available)
From findit tool:

Author: pfeldman
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/7d5643a67249ecead4ec57c5575f7907a89d7025
Time: Sat Mar 12 00:26:07 2016
The CL last changed line 10 of file String16WTF.cpp, which is stack frame 4.

Author: pfeldman
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/7d5643a67249ecead4ec57c5575f7907a89d7025
Time: Sat Mar 12 00:26:07 2016
The CL last changed line 10 of file String16WTF.cpp, which is stack frame 5.

Author: pfeldman
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/06595f0c4376466cfdd21d2c7f6fc91d9c1142a6
Time: Tue Mar 08 22:16:06 2016
The CL last changed line 120 of file Values.h, which is stack frame 6.

Owner: dgozman@chromium.org
Cc: dgozman@chromium.org
Owner: kozyatinskiy@chromium.org
Project Member

Comment 4 by ClusterFuzz, Jul 19 2016

ClusterFuzz has detected this issue as fixed in range 406033:406232.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5973030224527360

Fuzzer: inferno_twister
Job Type: mac_asan_content_shell
Platform Id: mac

Crash Type: UNKNOWN READ
Crash Address: 0x000000000000
Crash State:
  blink::protocol::String16::String16
  blink::protocol::toValue
  blink::protocol::Runtime::RemoteObject::serialize
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_content_shell&range=403906:404161
Fixed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_content_shell&range=406033:406232

Minimized Testcase (532.24 Kb): https://cluster-fuzz.appspot.com/download/AMIfv952w7BR7eRc61QK7eGsc41wt1y4ZC9BQtwV6hVAzwrVc2yhPwIyjh9a0J1gR_7KVkvLj9AQ4JZvUVu6hg6PG6OHAYHFvoPBUc8xdXhzq8L90tWB0YGNlr7StMXTDOw5Fdez-gj18Hfm57BI8PjzmjCUsDG_xx2xZf9Ajj9YOnDKcClWZDI?testcase_id=5973030224527360

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 5 by ClusterFuzz, Jul 19 2016

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase is verified as fixed, closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 6 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment