Heap-use-after-free in base::Timer::RunScheduledTask |
||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5954268731539456 Fuzzer: ochang_domfuzzer Job Type: linux_asan_content_shell_drt Platform Id: linux Crash Type: Heap-use-after-free READ 8 Crash Address: 0x61f0000284a0 Crash State: base::Timer::RunScheduledTask base::debug::TaskAnnotator::RunTask base::MessageLoop::RunTask Recommended Security Severity: High Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_content_shell_drt&range=396347:396435 Minimized Testcase (25.86 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94nK9IIZKQQOLQvY8tHZymKqi2eesTz858G20dvA0GBTLIWBQSTH_s58oZA8prhmedQzdgGfbDjpDEmNgWB3K1lMO2k0w1vtA3l8ujQQfvfjmebdh6LVa0cAmC6OVGNSK_G4GOUZpxfN139F2bYb-DhcZLJkmG2g0whhMW3TqAU8su7pEU?testcase_id=5954268731539456 Issue manually filed by: mmoroz See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Aug 24 2016
,
Aug 24 2016
,
Aug 24 2016
,
Aug 24 2016
Looks like this is a test only crash. Adding //content/shell/browser/layout_test/*bluetooth* owners.
,
Aug 24 2016
It is a test only crash. This is happening because the resources file is out of date so it's calling a test function that shouldn't be called. The fix would be to update the resources files.
,
Aug 24 2016
Updating type and labels to reflect #6
,
Dec 5 2016
ClusterFuzz testcase is flaky and no longer reproduces, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Mar 14 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
||||||||
►
Sign in to add a comment |
||||||||
Comment 1 by mmoroz@chromium.org
, Aug 24 2016Labels: Pri-1
Owner: tzik@chromium.org