Crash in blink::WebAXObject::showContextMenu |
||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5953419772952576 Fuzzer: inferno_twister Job Type: linux_asan_content_shell_drt Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000010 Crash State: blink::WebAXObject::showContextMenu gin::internal::Dispatcher<void v8::internal::FunctionCallbackArguments::Call Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_content_shell_drt&range=406657:406809 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_content_shell_drt&range=407408:407421 Minimized Testcase (4.64 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95GUv3iSO0R17TIiw2hQlrYru1BaclSWNK_whHMIsNjlAPK4mzHI_58kcCgTf7HEAOqr6RAz6R-4pY7RKvzvkOLs7uaC5tgCJ6ay7cOPy9Q1fqVW6BguTLjIBAnuizo8I5tVE7R5dMSU7DRzKh5Q_fRIAM-1g?testcase_id=5953419772952576 Filer: mmohammad See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jul 27 2016
Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6359173638127616 Fuzzer: inferno_twister Job Type: linux_asan_content_shell_drt Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000010 Crash State: blink::WebAXObject::showContextMenu gin::internal::Dispatcher<void v8::internal::FunctionCallbackArguments::Call Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_content_shell_drt&range=330379:330413 Minimized Testcase (0.11 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv95-ZkdzFbjhSDRwCB8MkxBIIZi-Fb0gskNM6OALsLX8705t8G-3Ax2pltJoxItIiwaTkpZFmgQiPFcaNccGkZbu3_dFs8hJ59Wm022bd-ycJSV8VQo5JVLOUhXy7iyf3OPD1DJmNUmfqJ3bvxJubHvs1_uVeg?testcase_id=6359173638127616 <script> combobox = accessibilityController.focusedElement; combobox.showMenu(); </script> Filer: mmohammad See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Aug 2 2016
,
Aug 4 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/b219d03ce85fc738a0bd8054395af4f03ad02544 commit b219d03ce85fc738a0bd8054395af4f03ad02544 Author: dmazzoni <dmazzoni@chromium.org> Date: Thu Aug 04 17:12:07 2016 Fix crash in WebAXObject::showContextMenu It was crashing if given the document node because it's not an element and it has no parent. BUG= 631807 Review-Url: https://codereview.chromium.org/2207633003 Cr-Commit-Position: refs/heads/master@{#409817} [add] https://crrev.com/b219d03ce85fc738a0bd8054395af4f03ad02544/third_party/WebKit/LayoutTests/accessibility/show-context-menu-crash.html [modify] https://crrev.com/b219d03ce85fc738a0bd8054395af4f03ad02544/third_party/WebKit/Source/web/WebAXObject.cpp
,
Aug 4 2016
,
Aug 5 2016
ClusterFuzz has detected this issue as fixed in range 409589:409863. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6359173638127616 Fuzzer: inferno_twister Job Type: linux_asan_content_shell_drt Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000010 Crash State: blink::WebAXObject::showContextMenu gin::internal::Dispatcher<void v8::internal::FunctionCallbackArguments::Call Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_content_shell_drt&range=330379:330413 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_content_shell_drt&range=409589:409863 Minimized Testcase (0.11 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv95-ZkdzFbjhSDRwCB8MkxBIIZi-Fb0gskNM6OALsLX8705t8G-3Ax2pltJoxItIiwaTkpZFmgQiPFcaNccGkZbu3_dFs8hJ59Wm022bd-ycJSV8VQo5JVLOUhXy7iyf3OPD1DJmNUmfqJ3bvxJubHvs1_uVeg?testcase_id=6359173638127616 <script> combobox = accessibilityController.focusedElement; combobox.showMenu(); </script> See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
||||
►
Sign in to add a comment |
||||
Comment 1 by mmohammad@chromium.org
, Jul 26 2016Owner: dmazz...@chromium.org
Status: Assigned (was: Untriaged)