New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 643829 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 643194
Owner:
Closed: Sep 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 1
Type: Bug



Sign in to add a comment

Crash in blink::ComputedStyle::setVariable

Project Member Reported by ClusterFuzz, Sep 2 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5595502794244096

Fuzzer: attekett_dom_fuzzer
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: UNKNOWN READ
Crash Address: 0x000000000008
Crash State:
  blink::ComputedStyle::setVariable
  blink::StyleBuilderFunctions::applyValueCSSPropertyVariable
  blink::StyleBuilder::applyProperty
  

Minimized Testcase (0.15 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv97hxfYLiXqR6pIo7O4ku12AIEMBWuUkBRrBOPZZlf8Wf7h_0GLgnKCIz9JgWVv4F4ENytFAp2B4P4PE0JMa9OVQhf8DD8A02_26dLNXlTkL-iH8xGaeDtUsiwPfBNNkJM8gQXSEihORuWaVwnlfL74BubqWvg?testcase_id=5595502794244096
<div id="header"</div>
<script> 
var test8=document.getElementById("header")


test8.style['--panel-ui-button-background-position']='18122em 427px';
</script>


Issue manually filed by: mummareddy

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Components: Blink>CSS
Labels: findit-wrong Te-Logged M-53
Owner: sashab@chromium.org
Status: Assigned (was: Untriaged)
From find it tool:

Author: sashab
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/66e5ca50795b1031657be8116f8ba9094e547ac3
Time: Thu Jun 02 10:13:43 2016
The CL last changed line 819 of file StyleBuilderCustom.cpp, which is stack frame 6.
Mergedinto: 643194
Owner: timloh@chromium.org
Status: Duplicate (was: Assigned)
Probably a dupe of 643194 going by the minimised test.
Project Member

Comment 3 by ClusterFuzz, Sep 6 2016

ClusterFuzz has detected this issue as fixed in range 416466:416526.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5595502794244096

Fuzzer: attekett_dom_fuzzer
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: UNKNOWN READ
Crash Address: 0x000000000008
Crash State:
  blink::ComputedStyle::setVariable
  blink::StyleBuilderFunctions::applyValueCSSPropertyVariable
  blink::StyleBuilder::applyProperty
  
Fixed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_chrome&range=416466:416526

Minimized Testcase (0.15 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv97hxfYLiXqR6pIo7O4ku12AIEMBWuUkBRrBOPZZlf8Wf7h_0GLgnKCIz9JgWVv4F4ENytFAp2B4P4PE0JMa9OVQhf8DD8A02_26dLNXlTkL-iH8xGaeDtUsiwPfBNNkJM8gQXSEihORuWaVwnlfL74BubqWvg?testcase_id=5595502794244096
<div id="header"</div>
<script> 
var test8=document.getElementById("header")


test8.style['--panel-ui-button-background-position']='18122em 427px';
</script>


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 4 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment