New issue
Advanced search Search tips

Issue 650224 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 649935
Owner: ----
Closed: Sep 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 1
Type: Bug-Security



Sign in to add a comment

Heap-buffer-overflow in v8::internal::ScavengeVisitor::VisitPointer

Project Member Reported by ClusterFuzz, Sep 26 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5494803100073984

Fuzzer: inferno_layout_test_unmodified
Job Type: windows_syzyasan_chrome
Platform Id: windows

Crash Type: Heap-buffer-overflow READ 1
Crash Address: 0x26700004
Crash State:
  v8::internal::ScavengeVisitor::VisitPointer
  v8::internal::StandardFrame::IterateCompiledFrame
  v8::internal::Isolate::Iterate
  
Recommended Security Severity: Medium

Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_chrome&range=420857:420859

Minimized Testcase (1.66 Kb): https://cluster-fuzz.appspot.com/download/AMIfv952lAB-pe8l6O0cEjCASpgVLZUfOpT34dv4PVJZO93iMPlkHYGOELrc9QGSHyXcFmgE9L2h94fnXQJcyRKexzMl-kVzjq0QloRL8mLmqkJdF1XP3oMI-jbL3WqtSwvjKCoixislf27opJgHTAHhe9ZFn5qdrA?testcase_id=5494803100073984

Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Project Member

Comment 1 by sheriffbot@chromium.org, Sep 26 2016

Labels: M-55
Project Member

Comment 2 by sheriffbot@chromium.org, Sep 26 2016

Labels: ReleaseBlock-Beta
This issue is a security regression. If you are not able to fix this quickly, please revert the change that introduced it.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 3 by sheriffbot@chromium.org, Sep 26 2016

Labels: Pri-1
Components: Blink>JavaScript
Mergedinto: 649935
Status: Duplicate (was: Untriaged)
Project Member

Comment 6 by sheriffbot@chromium.org, Jan 4 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment