Crash in memchr |
||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6588106146054144 Fuzzer: mbarbella_js_mutation Job Type: linux_asan_d8 Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x7fb66aca9f87 Crash State: memchr v8::internal::Invoke v8::internal::Execution::Call Recommended Security Severity: Medium Regressed: V8: r41759:41760 Minimized Testcase (0.06 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv94Eezav0X4HVPkHf1NCvfskjFrzpVfLG-AEtYnnV4QhR1LSpV3OY118yjP5J2NYK9nsIxEig2Xb3WObXYaSRySEmeUas94QbOZOfxKHmccrQaxd3Fjq_5hvhzxYmJPM9k2gkZ1OqF3YgG4ZGXn0NqRcuviSPA?testcase_id=6588106146054144 __v_10 = "test test test"; __v_10.indexOf("t", -1073741825); Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Dec 17 2016
This issue is a security regression. If you are not able to fix this quickly, please revert the change that introduced it. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Dec 17 2016
,
Dec 20 2016
Issue 675310 has been merged into this issue.
,
Dec 20 2016
cbruni: Could you take a look? The regression range points to https://chromium.googlesource.com/v8/v8/+/89f159b0420d643ecc78d43db0f7836d3c4aa932
,
Dec 20 2016
[builtins] Fix String.prototype.indexOf with negative positions BUG=chromium:674889 Review-Url: https://codereview.chromium.org/2593593002 Cr-Commit-Position: refs/heads/master@{#41858} Committed: https://chromium.googlesource.com/v8/v8/+/c1402cbde3a08f6d165a301c6f5596ca895ee0e7
,
Dec 21 2016
ClusterFuzz has detected this issue as fixed in range 41857:41858. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6588106146054144 Fuzzer: mbarbella_js_mutation Job Type: linux_asan_d8 Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x7fb66aca9f87 Crash State: memchr v8::internal::Invoke v8::internal::Execution::Call Recommended Security Severity: Medium Regressed: V8: r41759:41760 Fixed: V8: r41857:41858 Minimized Testcase (0.06 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv94Eezav0X4HVPkHf1NCvfskjFrzpVfLG-AEtYnnV4QhR1LSpV3OY118yjP5J2NYK9nsIxEig2Xb3WObXYaSRySEmeUas94QbOZOfxKHmccrQaxd3Fjq_5hvhzxYmJPM9k2gkZ1OqF3YgG4ZGXn0NqRcuviSPA?testcase_id=6588106146054144 __v_10 = "test test test"; __v_10.indexOf("t", -1073741825); See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Dec 21 2016
ClusterFuzz testcase 4939647349424128 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Dec 21 2016
,
Jan 27 2017
,
Mar 29 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
||||||||
►
Sign in to add a comment |
||||||||
Comment 1 by sheriffbot@chromium.org
, Dec 17 2016