New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 661470 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Feb 2017
Cc:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Integer-overflow in blink::IntRect::maxY

Project Member Reported by ClusterFuzz, Nov 2 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4816575254495232

Fuzzer: inferno_twister
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  blink::IntRect::maxY
  blink::FrameView::updateRenderThrottlingStatus
  base::internal::RunMixin<base::Callback<void
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=429027:429061

Minimized Testcase (2.06 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96Fb7Gk-JhOW5HPHNVjX65C5rw_elig-PO-8Ci1G7vHbZvZJnhnFnEm-nJI3K3-9h3Ck7HgePE0eDnJxeRJpdtJomexlk_ku-uydbAhgKCpclPgoidLWXgajKUc6n3r-1drmBcU0XBfF7nw25da1FFshecapg?testcase_id=4816575254495232

Additional requirements: Requires HTTP

Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: msrchandra@chromium.org
Labels: Findit-for-crash
Owner: skyos...@chromium.org
Status: Assigned (was: Untriaged)
Suspecting the suspect from find it and assigning to the concern owner.
Suspected CLs	The result is a list of CLs that change the crashed files.

Author: skyostil
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/3c364c812da0312a104e976ca5838507efe3488e
Time: Tue Nov 01 17:56:08 2016
Lines 4459-4473, 4490-4492 of file FrameView.cpp which potentially caused crash are changed in this cl (frame #1, "blink::FrameView::updateRenderThrottlingStatus").

File IntersectionObserver.cpp is changed in this cl (and is part of stack frame #3, "blink::IntersectionObserver::deliver")
Minimum distance from crash line to modified line: 0. (file: FrameView.cpp, crashed on: 4490, modified: 4490).

Suspected Project: chromium

@skyostil --  Could you please look into the issue, pardon me if has nothing to do with your changes and if possible assign it to the concern owner.
Thank You.
Project Member

Comment 2 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 3 by ClusterFuzz, Feb 1 2017

ClusterFuzz has detected this issue as fixed in range 446721:447186.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4816575254495232

Fuzzer: inferno_twister
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  blink::IntRect::maxY
  blink::FrameView::updateRenderThrottlingStatus
  base::internal::RunMixin<base::Callback<void
  
Sanitizer: undefined (UBSAN)

Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=429027:429061
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=446721:447186

Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv96Fb7Gk-JhOW5HPHNVjX65C5rw_elig-PO-8Ci1G7vHbZvZJnhnFnEm-nJI3K3-9h3Ck7HgePE0eDnJxeRJpdtJomexlk_ku-uydbAhgKCpclPgoidLWXgajKUc6n3r-1drmBcU0XBfF7nw25da1FFshecapg?testcase_id=4816575254495232


Additional requirements: Requires HTTP

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 4 by ClusterFuzz, Feb 1 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 4816575254495232 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment