New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 670807 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Jan 2017
Cc:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 1
Type: Bug



Sign in to add a comment

Crash in blink::WebString::WebString

Project Member Reported by ClusterFuzz, Dec 2 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5644267520524288

Fuzzer: inferno_twister
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: UNKNOWN READ
Crash Address: 0x000000000270
Crash State:
  blink::WebString::WebString
  blink::WebURL::WebURL
  blink::WebDocument::url
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_chrome&range=434476:434480

Minimized Testcase (0.59 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv95bOsvzHsotdJ_d2DuWqTA2b-kYeiKo86_-5Gi0RT1QjZuDdGmR_4U5O3iLdOQqXs394IjmcuaUaL_Mz-Df6-BaBTAjypYWRlwcauI-sXnj2DMDLPG_HlE7uY7zjq4uvXMj-W4FUxb2d8PYuXnHr_wedOJjTg?testcase_id=5644267520524288
><script>
 window.gc(); 
function eventhandler7() {
 /*string_event*/ var var00013 = "webkitprerenderload";  //line 15
 /*DOMWindow*/ var var00215 = window;  //line 240
 /*long*/ var var00296 = var00215.setTimeout("eventhandler7()");  //line 328
 var00215.close();  //line 378
 /*DOMWindow*/ var var00357 = window;  //line 396
 /*string*/ var var00358 = "j&{9LqMW00c";  //line 397
 /*string*/ var var00359 = Array(31);  //line 398
 /*DOMWindow*/ var var00360 = var00357.open(var00358,var00359,var00013);  //line 399
}
</script>
&#xede6;&#xea18;M&#x8746;<iframe onload=eventhandler7() id=tCF2</iframe>


Additional requirements: Requires HTTP

Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: msrchandra@chromium.org
Labels: Test-Predator-Wrong-CLs
Owner: kinuko@chromium.org
Status: Assigned (was: Untriaged)
Unable to find the suspect using Find it and CL.
Using Code Search for the file, "WebString.cpp" assigning to the concern owner.
Suspecting the Commit#
https://chromium.googlesource.com/chromium/src/+/a0d5ac61931de6d57d2f7c2a619177986d4d5e0e

@kinuko -- Could you please look into the issue, kindly re-assign if this is not related to your change.

Thank You.
I don't believe my change could cause a crash like it.  I'll take a quick look and see if I can fix it or can find someone more appropriate to re-assign.
Project Member

Comment 3 by ClusterFuzz, Jan 7 2017

Status: WontFix (was: Assigned)
ClusterFuzz testcase 5644267520524288 is flaky and no longer reproduces, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment