New issue
Advanced search Search tips

Issue 638159 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Sep 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug-Security



Sign in to add a comment

Use-of-uninitialized-value in test_runner::MockWebSpeechRecognizer::PostRunTaskFromQueue

Project Member Reported by ClusterFuzz, Aug 16 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5001882793934848

Fuzzer: ochang_domfuzzer
Job Type: linux_msan_content_shell_drt
Platform Id: linux

Crash Type: Use-of-uninitialized-value
Crash Address: 
Crash State:
  test_runner::MockWebSpeechRecognizer::PostRunTaskFromQueue
  base::internal::Invoker<base::internal::BindState<void
  base::debug::TaskAnnotator::RunTask
  
Recommended Security Severity: Medium

Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_msan_content_shell_drt&range=399688:399707

Minimized Testcase (0.30 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97eJHXxVnwmFengtvFl1H_mN2KrUKFQcq33pOHkXPCdUMoDplSKDpZxdhtbrfeDgl7O4NA3C4pkSG17anWAwjJj6sFOQtUIt08VuCrc7KfoWq1CTLGeEa65wUQ9_c3kdwe0PZ307oUjRfYMG4thlq3PKO4-Rg?testcase_id=5001882793934848

Issue manually filed by: mmoroz

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 

Comment 1 by mmoroz@chromium.org, Aug 16 2016

Owner: lfg@chromium.org
lfg@, could you please take a look or suggest another owner, since you've recently touched some stuff in the stacktrace: https://chromium.googlesource.com/chromium/src//+/05e4137fc06ab5b10b30ecd053f49190cfbf3b5d
Project Member

Comment 2 by sheriffbot@chromium.org, Aug 16 2016

Labels: M-53
Project Member

Comment 3 by sheriffbot@chromium.org, Aug 16 2016

Labels: ReleaseBlock-Stable
Project Member

Comment 4 by sheriffbot@chromium.org, Aug 16 2016

Labels: Pri-1
Project Member

Comment 5 by sheriffbot@chromium.org, Aug 16 2016

Status: Assigned (was: Untriaged)
Components: Internals>Sandbox>SiteIsolation

Comment 7 by gov...@chromium.org, Aug 17 2016

Cc: awhalley@chromium.org
M53 Stable launch is coming VERY soon.Your bug is labelled as Stable ReleaseBlock, pls make sure to land the fix asap so it gets chance to bake in beta before stable promotion later this month. Thank you.

Comment 8 by gov...@chromium.org, Aug 18 2016

Please try to resolve this ASAP as we're very close to M53 Stable promotion. Please request a merge to M53 branch 2785 once change is landed/baked/verified in Canary. Thank you.

Comment 9 by gov...@chromium.org, Aug 18 2016

Cc: infe...@chromium.org
A friendly reminder that M53 Stable is launching VERY soon! Your bug is labelled as Stable ReleaseBlock, pls make sure to land the fix and get it merged into the release branch ASAP (before 5:00 PM PT, Tuesday) so we can take it for this week LAST Beta release for Desktop. Thank you!

Note: Merge has to happen by Friday, August 26th, 5:00 PM PST in order to make into the desktop Stable final build cut. 

Comment 11 by lfg@chromium.org, Aug 22 2016

Labels: -ReleaseBlock-Stable
This code only runs on tests, removing releaseblock.
Labels: -Security_Impact-Beta Security_Impact-None

Comment 13 by lfg@chromium.org, Aug 22 2016

Labels: -Pri-1 Pri-2
Project Member

Comment 14 by ClusterFuzz, Sep 14 2016

ClusterFuzz has detected this issue as fixed in range 418377:418438.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5001882793934848

Fuzzer: ochang_domfuzzer
Job Type: linux_msan_content_shell_drt
Platform Id: linux

Crash Type: Use-of-uninitialized-value
Crash Address: 
Crash State:
  test_runner::MockWebSpeechRecognizer::PostRunTaskFromQueue
  base::internal::Invoker<base::internal::BindState<void
  base::debug::TaskAnnotator::RunTask
  
Recommended Security Severity: Medium

Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_msan_content_shell_drt&range=399688:399707
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_msan_content_shell_drt&range=418377:418438

Minimized Testcase (0.30 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97eJHXxVnwmFengtvFl1H_mN2KrUKFQcq33pOHkXPCdUMoDplSKDpZxdhtbrfeDgl7O4NA3C4pkSG17anWAwjJj6sFOQtUIt08VuCrc7KfoWq1CTLGeEa65wUQ9_c3kdwe0PZ307oUjRfYMG4thlq3PKO4-Rg?testcase_id=5001882793934848

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 15 by ClusterFuzz, Sep 14 2016

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase is verified as fixed, closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 16 by sheriffbot@chromium.org, Sep 14 2016

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Project Member

Comment 17 by sheriffbot@chromium.org, Dec 21 2016

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment