Issue metadata
Sign in to add a comment
|
Crash in v8::internal::FixedArray::get |
||||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5713010216927232 Fuzzer: decoder_langfuzz Job Type: linux_asan_d8 Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x001ebfff8003 Crash State: v8::internal::FixedArray::get v8::internal::HashTableBase::Capacity v8::internal::NameDictionaryBase<v8::internal::NameDictionary, v8::internal::Nam Recommended Security Severity: Medium Regressed: V8: r41208:41209 Minimized Testcase (7.42 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96BmnUupvigfGi8HwxMLd1R0aymSvhvBMKttjgXU1pn0RWJ9MLqAvpys3YSK2VScnI_pqME_VX_ocMVie4C8PYnP8jW50ckiXzTfFjFIvs1rgsVPqF7DJ98WOQCxu9aW7kzdF6EHiOdLVG0Axp4FosOp-ZIBA?testcase_id=5713010216927232 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Nov 24 2016
,
Nov 25 2016
When I run this on Debug I get the following DCHECK OpParameter<FrameStateInfo>(dummy_state).bailout_id().IsNone() in js-typed-lower, so duping with issue 668654
,
Nov 25 2016
,
Nov 30 2016
ClusterFuzz has detected this issue as fixed in range 41355:41356. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5713010216927232 Fuzzer: decoder_langfuzz Job Type: linux_asan_d8 Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x001ebfff8003 Crash State: v8::internal::FixedArray::get v8::internal::HashTableBase::Capacity v8::internal::NameDictionaryBase<v8::internal::NameDictionary, v8::internal::Nam Recommended Security Severity: Medium Regressed: V8: r41208:41209 Fixed: V8: r41355:41356 Minimized Testcase (7.42 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96BmnUupvigfGi8HwxMLd1R0aymSvhvBMKttjgXU1pn0RWJ9MLqAvpys3YSK2VScnI_pqME_VX_ocMVie4C8PYnP8jW50ckiXzTfFjFIvs1rgsVPqF7DJ98WOQCxu9aW7kzdF6EHiOdLVG0Axp4FosOp-ZIBA?testcase_id=5713010216927232 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Mar 3 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||
Comment 1 by dominickn@chromium.org
, Nov 24 2016Status: Assigned (was: Untriaged)