Integer-overflow in blink::cornerRect |
|||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5026591823626240 Fuzzer: inferno_twister Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: blink::cornerRect blink::PaintLayerScrollableArea::resizerCornerRect touchResizerCornerRect Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=370022:370027 Minimized Testcase (0.33 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv95ME4GXsOLIKLgAU2B9Ka7qDZ-OvYuOmBWPxzVY0E8E-Bu_2NOcLtWcKl5OSWK75mO232dSSHeenqqGecWIVNLpgIJ2F47hpt7piLrqXZY4PgouKV41FNeouIXzbj79tMX5KxuCc1fiIZuXc8fLnPbbGPqmfA?testcase_id=5026591823626240 <style> .c34 { taste: salty; motion: path("M 52365 24 h 44 v -2543968708") 11086rad 99%;</style><script> var docElement = document.body ? document.body : document.documentElement; tCF75 = document.createElementNS("http://www.w3.org/1999/xhtml", "textarea"); tCF75.setAttribute("class", "c34"); docElement.appendChild(tCF75); </script> Additional requirements: Requires HTTP Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Nov 19 2016
From discussion with ISE and Blink eng, over/underflow in Paint rects such as the resizer should not be harmful. It is likely this part in cornerRect(): bounds.maxY() - verticalThickness - box.styleRef().borderBottomWidth(),
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jan 31 2017
ClusterFuzz has detected this issue as fixed in range 446721:447186. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5026591823626240 Fuzzer: inferno_twister Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: blink::cornerRect blink::PaintLayerScrollableArea::resizerCornerRect touchResizerCornerRect Sanitizer: undefined (UBSAN) Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=370022:370027 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=446721:447186 Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv95ME4GXsOLIKLgAU2B9Ka7qDZ-OvYuOmBWPxzVY0E8E-Bu_2NOcLtWcKl5OSWK75mO232dSSHeenqqGecWIVNLpgIJ2F47hpt7piLrqXZY4PgouKV41FNeouIXzbj79tMX5KxuCc1fiIZuXc8fLnPbbGPqmfA?testcase_id=5026591823626240 Additional requirements: Requires HTTP See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page. |
|||
►
Sign in to add a comment |
|||
Comment 1 by durga.behera@chromium.org
, Oct 25 2016Owner: wkorman@chromium.org
Status: Assigned (was: Untriaged)