Crash in blink::InlineBox::operator |
||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5658792203386880 Fuzzer: bj_broddelwerk Job Type: windows_asan_content_shell Platform Id: windows Crash Type: UNKNOWN READ Crash Address: 0x00000b9c Crash State: blink::InlineBox::operator blink::MidpointState<blink::InlineIterator>::addMidpoint blink::BreakingContext::handleText Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_asan_content_shell&range=405740:410785 Minimized Testcase (1.25 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96ceYnxkMzPNSFoVaZ94mIxhk5SUmvVO_N6GqTMCgH2IYWKmo2lKHoErWRwKR7qCrnom6z9jX8br1pJLca483vqz5E6LeGR6Vk3UTXxi_JlMXXsFRqTnurLe9XINWJZryVpg77QX5dNrRBJbUZs_Eg0I5y3UA?testcase_id=5658792203386880 Issue manually filed by: nyerramilli See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Aug 10 2016
,
Oct 4 2016
Suspected CLs The result is a list of CLs that change the crashed files. Author: Xianzhu Wang Project: chromium Changelist: https://chromium.googlesource.com/chromium/src/+/f6c6259fca56e59fdb6d420f6d809d2c6c8cbdca Time: Thu Jul 21 18:55:40 2016 File InlineBox.cpp is changed in this cl (and is part of stack frame #6, "blink::InlineBox::operator new") Minimum distance from crash line to modified line: 10. (file: InlineBox.cpp, crashed on: 81, modified: 71). Suspected Project: chromium Suspected Component: Blink>Layout Please reassign if this is not related to your change.
,
Oct 7 2016
The test crashes during asan_malloc, so this seems not a problem of the caller. It's either an OOM or a problem of asan itself.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
||||
►
Sign in to add a comment |
||||
Comment 1 by nyerramilli@chromium.org
, Aug 10 2016Components: Tools>Test>FindIt>NoResult
Labels: M-54 findit-wrong Te-Logged
Owner: glebl@chromium.org
Status: Assigned (was: Untriaged)