Issue metadata
Sign in to add a comment
|
Heap-use-after-free in printing::PrintWebViewHelper::OnMessageReceived |
||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5754609055563776 Fuzzer: cdiehl_peach Job Type: linux_asan_chrome_media Platform Id: linux Crash Type: Heap-use-after-free READ 4 Crash Address: 0x61100001b7dc Crash State: printing::PrintWebViewHelper::OnMessageReceived content::RenderFrameImpl::OnMessageReceived content::ChildThreadImpl::OnMessageReceived Recommended Security Severity: Medium Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_media&range=434678:434769 Minimized Testcase (953.89 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94F1azWt_SdrRZJ4bx0hPi8cmk-13Gl4MWJltieZ7oVD7lci13RzJJ8rMGLadq4yxRUvXpSfJ0l2HRRjAg6y779Mc63DoRk-yE7A7bM-4GphogTaJOYGnigvzajuOsoDrX48HT88d6SXugqp_dPYlHQMO5V89mztxrrza9mSem8JkO-D7Y?testcase_id=5754609055563776 Additional requirements: Requires Gestures Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Nov 29 2016
,
Nov 30 2016
Looks like we need to do another follow up after fixing bug 666616 in r434734.
,
Nov 30 2016
,
Nov 30 2016
This issue is a security regression. If you are not able to fix this quickly, please revert the change that introduced it. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Nov 30 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/149f2a418b32edc71ce700e75084fccf2ce6eb2a commit 149f2a418b32edc71ce700e75084fccf2ce6eb2a Author: thestig <thestig@chromium.org> Date: Wed Nov 30 17:52:57 2016 One more check for PrintWebViewHelper validity. This check should have been in r434734. BUG= 669534 Review-Url: https://codereview.chromium.org/2537973003 Cr-Commit-Position: refs/heads/master@{#435323} [modify] https://crrev.com/149f2a418b32edc71ce700e75084fccf2ce6eb2a/components/printing/renderer/print_web_view_helper.cc
,
Dec 1 2016
ClusterFuzz has detected this issue as fixed in range 435314:435416. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5754609055563776 Fuzzer: cdiehl_peach Job Type: linux_asan_chrome_media Platform Id: linux Crash Type: Heap-use-after-free READ 4 Crash Address: 0x61100001b7dc Crash State: printing::PrintWebViewHelper::OnMessageReceived content::RenderFrameImpl::OnMessageReceived content::ChildThreadImpl::OnMessageReceived Recommended Security Severity: Medium Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_media&range=434678:434769 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_media&range=435314:435416 Minimized Testcase (953.89 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94F1azWt_SdrRZJ4bx0hPi8cmk-13Gl4MWJltieZ7oVD7lci13RzJJ8rMGLadq4yxRUvXpSfJ0l2HRRjAg6y779Mc63DoRk-yE7A7bM-4GphogTaJOYGnigvzajuOsoDrX48HT88d6SXugqp_dPYlHQMO5V89mztxrrza9mSem8JkO-D7Y?testcase_id=5754609055563776 Additional requirements: Requires Gestures See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Dec 1 2016
ClusterFuzz testcase is verified as fixed, closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Dec 1 2016
,
Dec 1 2016
Now that ClusterFuzz has verified the fix, requesting merge into M56.
,
Dec 1 2016
Your change meets the bar and is auto-approved for M56 (branch: 2924)
,
Dec 1 2016
I'll take care of the merge.
,
Dec 1 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/a6e404a5004dc4ac3c9860371f824ba13bcaf5f7 commit a6e404a5004dc4ac3c9860371f824ba13bcaf5f7 Author: Nasko Oskov <nasko@chromium.org> Date: Thu Dec 01 18:07:52 2016 One more check for PrintWebViewHelper validity. This check should have been in r434734. BUG= 669534 Review-Url: https://codereview.chromium.org/2537973003 Cr-Commit-Position: refs/heads/master@{#435323} (cherry picked from commit 149f2a418b32edc71ce700e75084fccf2ce6eb2a) Review URL: https://codereview.chromium.org/2545853002 . Cr-Commit-Position: refs/branch-heads/2924@{#251} Cr-Branched-From: 3a87aecc31cd1ffe751dd72c04e5a96a1fc8108a-refs/heads/master@{#433059} [modify] https://crrev.com/a6e404a5004dc4ac3c9860371f824ba13bcaf5f7/components/printing/renderer/print_web_view_helper.cc
,
Dec 12 2016
,
Dec 12 2016
Congratulations! The panel has awarded $1,500 for this bug.
,
Dec 12 2016
Re #15: This was found by clusterfuzz. Wrong bug?
,
Dec 12 2016
This was found by Peach. Looks legit to me. ;-)
,
Dec 12 2016
Re #17: Ah, fair enough, didn't see that :)
,
Dec 12 2016
Yep - this is running under the Chrome Fuzzer Program (g.co/ChromeBugRewards)
,
Dec 12 2016
,
Dec 14 2016
,
Mar 9 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by och...@chromium.org
, Nov 29 2016Status: Assigned (was: Untriaged)