New issue
Advanced search Search tips

Issue 660776 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: Oct 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Crash in LoginHandler::AddObservers

Project Member Reported by ClusterFuzz, Oct 31 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5385078885842944

Fuzzer: inferno_webbot
Job Type: linux_asan_chrome_v8_arm
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x00000000
Crash State:
  LoginHandler::AddObservers
  base::internal::Invoker<base::internal::BindState<void
  base::debug::TaskAnnotator::RunTask
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=428630:428631

Minimized Testcase (0.10 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv965Em6ax6tWIxdBuJq13Pqysh7T11AgG5XDAmCNCQt6oAKjRTPT6fHo5f6SnKhgCpmxxlVBjXDLFEZZoVtiXrjMNYHbQ7X_EVCNTRqAu8juGXDb4AWDtb8HkM3NCTdW4xe0f8fFsE5GW-U0ZA0IrOVbODRM8A?testcase_id=5385078885842944
<html><script>
window.open("http://devmarkup.com");
window.location = "http://pitchandmatch.com";</script>


Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: nyerramilli@chromium.org
Labels: Findit-for-crash M-56
Owner: jochen@chromium.org
Status: Assigned (was: Untriaged)
Findit Results:
-----------------
Suspected CLs	The result is a list of CLs that change the crashed files.

Author: jochen
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/628d0df5c9e15eaac92ed084b6bb701248b03f8a
Time: Sun Oct 30 20:35:43 2016
Lines 341 of file login_handler.cc which potentially caused crash are changed in this cl (frame #2, "LoginHandler::AddObservers").
Minimum distance from crash line to modified line: 0. (file: login_handler.cc, crashed on: 339, modified: 339).

Suspected Project: chromium

based on Findit results, assigning to jochen@, could you please check the issue and help.

Comment 2 by jochen@chromium.org, Oct 31 2016

Cc: jochen@chromium.org
 Issue 660784  has been merged into this issue.
Project Member

Comment 3 by bugdroid1@chromium.org, Oct 31 2016

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/a1a345d3d77742531fb89e5a9c5aaf85d2a9c5d5

commit a1a345d3d77742531fb89e5a9c5aaf85d2a9c5d5
Author: jochen <jochen@chromium.org>
Date: Mon Oct 31 10:58:44 2016

Avoid nullptr deref when requesting http auth for non-webcontents requests

BUG= 660776 

Review-Url: https://codereview.chromium.org/2460323002
Cr-Commit-Position: refs/heads/master@{#428683}

[modify] https://crrev.com/a1a345d3d77742531fb89e5a9c5aaf85d2a9c5d5/chrome/browser/ui/login/login_handler.cc

Comment 4 by jochen@chromium.org, Oct 31 2016

Status: Fixed (was: Assigned)
Project Member

Comment 5 by ClusterFuzz, Nov 1 2016

ClusterFuzz has detected this issue as fixed in range 428675:428693.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5385078885842944

Fuzzer: inferno_webbot
Job Type: linux_asan_chrome_v8_arm
Platform Id: linux

Crash Type: UNKNOWN READ
Crash Address: 0x00000000
Crash State:
  LoginHandler::AddObservers
  base::internal::Invoker<base::internal::BindState<void
  base::debug::TaskAnnotator::RunTask
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=428630:428631
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=428675:428693

Minimized Testcase (0.10 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv965Em6ax6tWIxdBuJq13Pqysh7T11AgG5XDAmCNCQt6oAKjRTPT6fHo5f6SnKhgCpmxxlVBjXDLFEZZoVtiXrjMNYHbQ7X_EVCNTRqAu8juGXDb4AWDtb8HkM3NCTdW4xe0f8fFsE5GW-U0ZA0IrOVbODRM8A?testcase_id=5385078885842944
<html><script>
window.open("http://devmarkup.com");
window.location = "http://pitchandmatch.com";</script>


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 6 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment