Issue metadata
Sign in to add a comment
|
Bad-cast to cc::BeginFrameSource from invalid vptr |
||||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4815935561269248 Fuzzer: inferno_twister_custom_bundle Job Type: linux_cfi_chrome Platform Id: linux Crash Type: Bad-cast Crash Address: 0x000000000000 Crash State: Bad-cast to cc::BeginFrameSource from invalid vptr Recommended Security Severity: Medium Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97sIjKJw5sbHqpBiyZ6eLD9HzSFM3T6DfjdLueA4odIFFL-9hAhKUkLH2_I2xLXywPZyla5-ZpxlxGpZ5sNzz4rKhqKWBZEO3Jt0lAuHBmxWDIaDV79rgSnW4rjuIMHg0v2MPNyPd1rKbPFf0Gf7j5uWtRrjA?testcase_id=4815935561269248 Additional requirements: Requires Gestures Issue manually filed by: tanin See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Sep 1 2016
Making P1 based on current severity. Please feel free to update.
,
Sep 1 2016
This seems to be the culprit CL: https://chromium.googlesource.com/chromium/src/+/6f2861b9c957c7374a2a2c084c6cafba01b5e5d6 Applying label Security_Impact-Head based on that CL's recency.
,
Sep 1 2016
,
Sep 1 2016
Could it be the same as this https://chromium.googlesource.com/chromium/src/+/9848a61393772cc8a9aa8349c68f7d436c743369, which as reverted in https://codereview.chromium.org/2304483002/ ?
,
Sep 1 2016
,
Sep 1 2016
This issue is a security regression. If you are not able to fix this quickly, please revert the change that introduced it. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Sep 1 2016
,
Sep 1 2016
vakh: How did you determine this was danakj's CL? The stack trace really does look more like this is a dupe of issue 642803 , caused the CL that vmiura mentions in #5.
,
Sep 1 2016
I can't see 642803 but I was going to guess-assign this to enne@ for changing BFS types stuff :)
,
Sep 1 2016
I think it is your CL enne. It's in the fuzz regression range (my SetVisible one is not)
,
Dec 16 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Feb 26 2018
|
|||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||
Comment 1 by vakh@chromium.org
, Sep 1 2016Components: MUS
Owner: danakj@chromium.org