Issue metadata
Sign in to add a comment
|
Crash in v8::internal::Heap::Contains |
||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5138662667059200 Fuzzer: attekett_dom_fuzzer Job Type: linux_asan_chrome_media Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000000 Crash State: v8::internal::Heap::Contains v8::internal::VerifyPointersVisitor::VisitPointers v8::internal::StandardFrame::IterateCompiledFrame Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_media&range=421045:421108 Minimized Testcase (0.35 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv96rGxMIUdTSfij3rcNodSyhFsdnBxFBtZ9vEKc92Fadru5MN3pZmZF0g5RiOYWKrPClI5Cc0hniiPF4g7oSwqZhtPxJMC1Rk76AZvpI5ENyURYhrOJ50scjjoeYzEvpfP6verU2krnawCc4SVfpeYPk6fMSmg?testcase_id=5138662667059200 <script> document.write('<st' + 'yle type="text/css">\n' + '#main { display: none; }\n' + '</st' + 'yle>'); </script> <form id="frmSwfRedirect" action="/tr/#/home"> <script> if(DetectFlashVer()){document.forms["frmSwfRedirect"];} </script><script> document.forms["frmSwfRedirect"].submit(); </script> Issue manually filed by: brajkumar See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Sep 28 2016
Assigning to this weeks memory sheriff (https://g3doc.corp.google.com/company/teams/v8/sheriffing.md).
,
Sep 28 2016
ClusterFuzz has detected this issue as fixed in range 421108:421147. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5138662667059200 Fuzzer: attekett_dom_fuzzer Job Type: linux_asan_chrome_media Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000000 Crash State: v8::internal::Heap::Contains v8::internal::VerifyPointersVisitor::VisitPointers v8::internal::StandardFrame::IterateCompiledFrame Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_media&range=421045:421108 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_media&range=421108:421147 Minimized Testcase (0.35 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv96rGxMIUdTSfij3rcNodSyhFsdnBxFBtZ9vEKc92Fadru5MN3pZmZF0g5RiOYWKrPClI5Cc0hniiPF4g7oSwqZhtPxJMC1Rk76AZvpI5ENyURYhrOJ50scjjoeYzEvpfP6verU2krnawCc4SVfpeYPk6fMSmg?testcase_id=5138662667059200 <script> document.write('<st' + 'yle type="text/css">\n' + '#main { display: none; }\n' + '</st' + 'yle>'); </script> <form id="frmSwfRedirect" action="/tr/#/home"> <script> if(DetectFlashVer()){document.forms["frmSwfRedirect"];} </script><script> document.forms["frmSwfRedirect"].submit(); </script> See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Sep 28 2016
ClusterFuzz testcase is verified as fixed, closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by brajkumar@chromium.org
, Sep 28 2016Labels: -Type-Bug Findit-for-crash M-55 Te-Logged Type-Bug-Regression
Owner: mlippautz@chromium.org
Status: Assigned (was: Untriaged)