Issue metadata
Sign in to add a comment
|
Integer-overflow in blink::LayoutTableSection::distributeRemainingExtraLogicalHeight |
||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5706449110171648 Fuzzer: inferno_twister Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: blink::LayoutTableSection::distributeRemainingExtraLogicalHeight blink::LayoutTableSection::distributeExtraLogicalHeightToRows blink::LayoutTable::distributeExtraLogicalHeight Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=370022:370027 Minimized Testcase (5.86 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96ON6gLwyJsRDTzDtYaqFZTyGY7yBsim2QYqnTXOyurR5T4BfcwoYHlwcT9n7ksfCMczXkwVm7j0TjSYeaKx4pkZWqNXjG4OEksXVwH0woO04qvBp6DF65UMVMpZoFeNOcoW6IbpUBgeX2c4P8AKW_nBZa0MQ?testcase_id=5706449110171648 Issue manually filed by: ranjitkan See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Oct 24 2016
I am unfortunately not working on Chrome anymore. Reassigning to eae@ for triaging.
,
Oct 24 2016
,
Oct 24 2016
Based on discussion with security team and other TLs we've decided not to fix int overflows that aren't considered security issues unless they appear in the wild.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jul 14 2017
ClusterFuzz testcase 5706449110171648 is still reproducing on tip-of-tree build (trunk). If this testcase was not reproducible locally or unworkable, ignore this notification and we will file another bug soon with hopefully a better and workable testcase. Otherwise, if this is not intended to be fixed (e.g. this is an intentional crash), please add ClusterFuzz-Ignore label to prevent future bug filing with similar crash stacktrace. |
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by ranjitkan@chromium.org
, Oct 3 2016Components: Tools>Test>FindIt>CorrectResult
Labels: -Pri-1 -Type-Bug Findit-for-crash M-55 Te-Logged Pri-2 Type-Bug-Regression
Owner: jchaffraix@chromium.org
Status: Assigned (was: Untriaged)