Integer-overflow in blink::LayoutListItem::calcValue |
|||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6025990540361728 Fuzzer: ifratric-browserfuzzer-v3 Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: blink::LayoutListItem::calcValue updateValueNow value Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=434178:434216 Minimized Testcase (0.11 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv95X6_gpNR-e5J3mLuigQtjtKJhT8-5NYHJUhukDrKSzaQsZ92BzSvSKGQkVsoLi9MTRMwKNNofE4wT-mmRCODYK1eT79tg5a4nAElf121udF-rYGASVI_YHEEOGWVCt9FZjrZ_rSEKWwGkJrGym3Dx4qaPpYQ?testcase_id=6025990540361728 <ol start="2147483647"> <li> <dir> <li id="htmlvar00048" role="banner"VHw?LmI 8n|K></li> </li> </li> <li> Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Dec 19 2016
Find it and CL did not provide any possible suspect. Using Code Search for the file, "LayoutListItem.cpp" assigning to the concern owner. Suspecting Commit# https://chromium.googlesource.com/chromium/src/+/c896e79e5ba348d7ed87438cd3a19d0176f3036d @robhogan -- Could you please look into the issue, kindly re-assign if this is not related to your changes. Thank You.
,
Feb 22 2017
ClusterFuzz has detected this issue as fixed in range 451788:451857. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6025990540361728 Fuzzer: ifratric-browserfuzzer-v3 Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: blink::LayoutListItem::calcValue updateValueNow value Sanitizer: undefined (UBSAN) Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=434178:434216 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=451788:451857 Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv95X6_gpNR-e5J3mLuigQtjtKJhT8-5NYHJUhukDrKSzaQsZ92BzSvSKGQkVsoLi9MTRMwKNNofE4wT-mmRCODYK1eT79tg5a4nAElf121udF-rYGASVI_YHEEOGWVCt9FZjrZ_rSEKWwGkJrGym3Dx4qaPpYQ?testcase_id=6025990540361728 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Feb 22 2017
ClusterFuzz testcase 6025990540361728 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
|||
►
Sign in to add a comment |
|||
Comment 1 by tkent@chromium.org
, Dec 18 2016