Crash in blink::Node::isDescendantOf |
|
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6265244906422272 Fuzzer: miaubiz_svg_fuzzer Job Type: linux_asan_chrome_mp Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000010 Crash State: blink::Node::isDescendantOf blink::CompositeEditCommand::cloneParagraphUnderNewElement blink::CompositeEditCommand::moveParagraphWithClones Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_mp&range=268656:269696 Minimized Testcase (1.62 Kb): https://cluster-fuzz.appspot.com/download/AMIfv940ByCl7WQxKAA7ygh37XNkmUmglpQUw-pu-bI3PizF3yx6c9w5AyILgdYWvDDAf6yMCPgWr__mX4feOOE71lsoEPRHZXTZMuqWp6b8UwGa7vmk3Gs_W5AOLZekp6O1gI4IptUOTLfqdcDqWLqtCh-O-NTLgg?testcase_id=6265244906422272 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Mar 9 2017
ClusterFuzz has detected this issue as fixed in range 455091:455394. Detailed report: https://clusterfuzz.com/testcase?key=6265244906422272 Fuzzer: miaubiz_svg_fuzzer Job Type: linux_asan_chrome_mp Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000010 Crash State: blink::Node::isDescendantOf blink::CompositeEditCommand::cloneParagraphUnderNewElement blink::CompositeEditCommand::moveParagraphWithClones Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=linux_asan_chrome_mp&range=268656:269696 Fixed: https://clusterfuzz.com/revisions?job=linux_asan_chrome_mp&range=455091:455394 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv940ByCl7WQxKAA7ygh37XNkmUmglpQUw-pu-bI3PizF3yx6c9w5AyILgdYWvDDAf6yMCPgWr__mX4feOOE71lsoEPRHZXTZMuqWp6b8UwGa7vmk3Gs_W5AOLZekp6O1gI4IptUOTLfqdcDqWLqtCh-O-NTLgg?testcase_id=6265244906422272 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page. |
|
►
Sign in to add a comment |
|
Comment 1 by durga.behera@chromium.org
, Dec 12 2016Status: Duplicate (was: Untriaged)