Integer-overflow in blink::NinePieceImageGrid::NinePieceImageGrid |
||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5112375340695552 Fuzzer: inferno_twister Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: blink::NinePieceImageGrid::NinePieceImageGrid blink::NinePieceImagePainter::paint blink::BoxPainter::paintNinePieceImage Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=372506:372545 Minimized Testcase (0.27 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94AA3pmsAyMiMQSUI6awBcki3PQN7G98k3VtkXLiwYqnNwW-H0xyTkBxu2WdlPPr25P3mJJkBlphLYO9JXLJ9YAnHDsEhBR0rNj2oxWgC3-cMgCQyAQrlbvFjQRFH_TBPhhQg1bevhvSH9bPXkXvQEShUI9ZA?testcase_id=5112375340695552 Additional requirements: Requires HTTP Filer: mummareddy See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Aug 4 2016
Marking as available for the paint team. Leviw sadly no longer works on Chrome.
,
Aug 5 2016
Moving this nonessential bug to the next milestone. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 11 2016
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Dec 22 2016
ClusterFuzz testcase 5112375340695552 is flaky and no longer reproduces, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
||||||
►
Sign in to add a comment |
||||||
Comment 1 by mummare...@chromium.org
, Aug 3 2016Labels: Te-Logged M-53
Owner: le...@chromium.org
Status: Assigned (was: Untriaged)