New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 630524 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
OOO until 29th Jan
Closed: Aug 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 3
Type: Bug



Sign in to add a comment

Integer-overflow in blink::ComputedStyle::outlineOutsetExtent

Project Member Reported by ClusterFuzz, Jul 22 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6534040505286656

Fuzzer: inferno_twister
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  blink::ComputedStyle::outlineOutsetExtent
  blink::LayoutBox::computeVisualEffectOverflowOutsets
  blink::LayoutBox::addVisualEffectOverflow
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=370022:370027

Minimized Testcase (0.10 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv96W1AoWZ9CdgVgiBQav61d7BPIJFVS2Ad5k0xPxLUF59IfWdiQDqX5-QQjR3QgKBkAFayVePWOthLTSQkJhhqBLVmZewv1GN4o0-40X88qt5LJHmfRhcy8sL7k_T-_YlaFnxL9hlKJ8SgqldTCV3-ERQtFYbA?testcase_id=6534040505286656
<style>
* { animation-name: cfpulse91;0.431400); outline-offset: 2147483646px; outline-style: outset;


Additional requirements: Requires HTTP

Filer: brajkumar

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Labels: -Pri-1 Findit-for-crash Te-Logged Pri-2
Owner: wangxianzhu@chromium.org
Status: Assigned (was: Untriaged)
No CL in the regression range changes the crashed files. The result is the blame information.

Author: wangxianzhu
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src//+/1a879804714354bfc3ea468a9489e6871913deb8
Time: Sun Dec 06 20:45:25 2015
The CL last changed line 1912 of file LayoutBlockFlow.cpp, which is stack frame 4.

Suspected Project: chromium
Suspected Component: Blink>Layout
=================================
wangxianzhu@: Could you please look into this issue if it is related to your change, else please help us in assigning it to the right owner.

Thanks!
Components: Blink>CSS
Labels: -Stability-Crash -Pri-2 -Findit-for-crash -Stability-UndefinedBehaviorSanitizer Pri-3
Owner: ----
Status: Available (was: Assigned)
This is not a real crash and not important at all.

Comment 3 by meade@chromium.org, Aug 7 2016

Owner: meade@chromium.org
Owner: bugsnash@chromium.org
Status: Started (was: Available)
Status: Fixed (was: Started)
Project Member

Comment 7 by ClusterFuzz, Aug 11 2016

ClusterFuzz has detected this issue as fixed in range 410916:411073.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6534040505286656

Fuzzer: inferno_twister
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  blink::ComputedStyle::outlineOutsetExtent
  blink::LayoutBox::computeVisualEffectOverflowOutsets
  blink::LayoutBox::addVisualEffectOverflow
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=370022:370027
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=410916:411073

Minimized Testcase (0.10 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv96W1AoWZ9CdgVgiBQav61d7BPIJFVS2Ad5k0xPxLUF59IfWdiQDqX5-QQjR3QgKBkAFayVePWOthLTSQkJhhqBLVmZewv1GN4o0-40X88qt5LJHmfRhcy8sL7k_T-_YlaFnxL9hlKJ8SgqldTCV3-ERQtFYbA?testcase_id=6534040505286656
<style>
* { animation-name: cfpulse91;0.431400); outline-offset: 2147483646px; outline-style: outset;


Additional requirements: Requires HTTP

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 8 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment