Issue metadata
Sign in to add a comment
|
Heap-buffer-overflow in MemoryWrite<unsigned |
||||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4960169379495936 Fuzzer: decoder_langfuzz Job Type: linux_asan_d8_v8_arm64_dbg Platform Id: linux Crash Type: Heap-buffer-overflow WRITE 8 Crash Address: 0x7f868e2517f8 Crash State: MemoryWrite<unsigned v8::internal::Simulator::LoadStoreHelper v8::internal::Simulator::ExecuteInstruction Recommended Security Severity: High Regressed: V8: r35689:35690 Minimized Testcase (8.59 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94FVZjQeC_0e0NApaNAw1GOmr5AOawlFP-b8gbLd7gvurpX4f5hRk7F_pxgsOfcqO8ppFLeRGw62ArURodnkFBZ6S8OY3beW2tkiuypBMfu7R2qvvLlPw8It2GH2eUxxMEUrxw96LdYenjZrAxEF8qNlvxqtQ?testcase_id=4960169379495936 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Oct 18 2016
,
Oct 18 2016
That code is merge of arm64 branch and is very old. Assigning to clusterfuzz sheriff for triaging.
,
Oct 18 2016
,
Oct 18 2016
,
Oct 18 2016
,
Oct 18 2016
,
Oct 19 2016
,
Nov 1 2016
ClusterFuzz has detected this issue as fixed in range 40662:40663. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4960169379495936 Fuzzer: decoder_langfuzz Job Type: linux_asan_d8_v8_arm64_dbg Platform Id: linux Crash Type: Heap-buffer-overflow WRITE 8 Crash Address: 0x7f868e2517f8 Crash State: MemoryWrite<unsigned v8::internal::Simulator::LoadStoreHelper v8::internal::Simulator::ExecuteInstruction Recommended Security Severity: High Regressed: V8: r35689:35690 Fixed: V8: r40662:40663 Minimized Testcase (8.59 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94FVZjQeC_0e0NApaNAw1GOmr5AOawlFP-b8gbLd7gvurpX4f5hRk7F_pxgsOfcqO8ppFLeRGw62ArURodnkFBZ6S8OY3beW2tkiuypBMfu7R2qvvLlPw8It2GH2eUxxMEUrxw96LdYenjZrAxEF8qNlvxqtQ?testcase_id=4960169379495936 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jan 24 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||
Comment 1 by mmoroz@chromium.org
, Oct 18 2016Labels: Pri-1
Owner: u...@chromium.org
Status: Available (was: Untriaged)