New issue
Advanced search Search tips

Issue 658522 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Nov 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Integer-overflow in blink::IntPoint::move

Project Member Reported by ClusterFuzz, Oct 22 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5734123190878208

Fuzzer: inferno_twister
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  blink::IntPoint::move
  move
  blink::PaintLayerScrollableArea::resizerCornerRect
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=370022:370027

Minimized Testcase (0.38 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97ge34VJmzda3p9yusuMJLKkaK8CZ0Y_vriIFUUMIyUCqGcQkh2ph8DbABu-MUEoCk2GrjukXqC4kC6mkA7_T2rwFJTACT6_QpdHkwmTrzCen2BnKKhkRekg41Uuby271RAcKoNSds_kUHXrgnzmrss0ceELw?testcase_id=5734123190878208

Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Components: Blink>Scroll
Labels: Test-Predator-Wrong M-55
Owner: bokan@chromium.org
Status: Assigned (was: Untriaged)
Suspected CL is https://chromium.googlesource.com/chromium/src/+/10a29c5ef01177b72535c855713df141a9ef9ddc
bokan@, could you please take a look and help us to find correct owner if it is not related your changes.
Project Member

Comment 2 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 3 by bokan@chromium.org, Nov 28 2016

Status: WontFix (was: Assigned)
Test case contains overflowing int so this falls in the class of issues we don't care about, see  issue 634803 
Labels: Hotlist-Input-Dev

Sign in to add a comment