Issue metadata
Sign in to add a comment
|
Use-of-uninitialized-value in base::time_internal::SaturatedSub |
||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5738618436190208 Fuzzer: inferno_layout_test_unmodified Job Type: linux_msan_chrome Platform Id: linux Crash Type: Use-of-uninitialized-value Crash Address: Crash State: base::time_internal::SaturatedSub cc::Scheduler::BeginImplFrameWithDeadline base::debug::TaskAnnotator::RunTask Recommended Security Severity: Medium Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_msan_chrome&range=417755:417794 Minimized Testcase (0.08 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv97WzEixG-bklMa3qn6wJKc--k2iQ7Ax-MOPM-Cov1FKKCKP7Hfw7dHZTMaPDUcF-xD75GKoiClZawg-8KyUqtVv6oDpmgAVaSMfa6fKhWFHOCwmFEt4-VD69KO6OAFpyzOfl8EC3saAMml83ig0HfBYV5avKw?testcase_id=5738618436190208 <form target="_blank" method="post"> <script> document.forms[0].submit(); </script> Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Sep 11 2016
This issue is a security regression. If you are not able to fix this quickly, please revert the change that introduced it. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Sep 11 2016
,
Sep 12 2016
sunnyps@ I wonder if this CL could be related -> https://codereview.chromium.org/2323063004
,
Sep 12 2016
oh it seems this CL has already been reverted in https://codereview.chromium.org/2336493002/ but I'll leave the bug open so hopefully it can be fixed in the reland.
,
Sep 13 2016
ClusterFuzz has detected this issue as fixed in range 417889:417901. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5738618436190208 Fuzzer: inferno_layout_test_unmodified Job Type: linux_msan_chrome Platform Id: linux Crash Type: Use-of-uninitialized-value Crash Address: Crash State: base::time_internal::SaturatedSub cc::Scheduler::BeginImplFrameWithDeadline base::debug::TaskAnnotator::RunTask Recommended Security Severity: Medium Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_msan_chrome&range=417755:417794 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_msan_chrome&range=417889:417901 Minimized Testcase (0.08 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv97WzEixG-bklMa3qn6wJKc--k2iQ7Ax-MOPM-Cov1FKKCKP7Hfw7dHZTMaPDUcF-xD75GKoiClZawg-8KyUqtVv6oDpmgAVaSMfa6fKhWFHOCwmFEt4-VD69KO6OAFpyzOfl8EC3saAMml83ig0HfBYV5avKw?testcase_id=5738618436190208 <form target="_blank" method="post"> <script> document.forms[0].submit(); </script> See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Sep 13 2016
ClusterFuzz testcase is verified as fixed, closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Sep 13 2016
,
Oct 25 2016
,
Dec 20 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by sheriffbot@chromium.org
, Sep 11 2016