New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 675321 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Use other robhogan account instead.
Closed: Feb 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Integer-overflow in blink::LayoutListItem::calcValue

Project Member Reported by ClusterFuzz, Dec 17 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6025990540361728

Fuzzer: ifratric-browserfuzzer-v3
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  blink::LayoutListItem::calcValue
  updateValueNow
  value
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=434178:434216

Minimized Testcase (0.11 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv95X6_gpNR-e5J3mLuigQtjtKJhT8-5NYHJUhukDrKSzaQsZ92BzSvSKGQkVsoLi9MTRMwKNNofE4wT-mmRCODYK1eT79tg5a4nAElf121udF-rYGASVI_YHEEOGWVCt9FZjrZ_rSEKWwGkJrGym3Dx4qaPpYQ?testcase_id=6025990540361728
<ol start="2147483647">
<li>
<dir>
<li id="htmlvar00048" role="banner"VHw?LmI 8n|K&gt;</li>
</li>
</li>
<li>


Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 

Comment 1 by tkent@chromium.org, Dec 18 2016

Components: Blink>Layout
Cc: msrchandra@chromium.org
Labels: Test-Predator-Wrong-CLs
Owner: robhogan@chromium.org
Status: Assigned (was: Untriaged)
Find it and CL did not provide any possible suspect.
Using Code Search for the file, "LayoutListItem.cpp" assigning to the concern owner.
Suspecting Commit#
https://chromium.googlesource.com/chromium/src/+/c896e79e5ba348d7ed87438cd3a19d0176f3036d

@robhogan -- Could you please look into the issue, kindly re-assign if this is not related to your changes.
Thank You.
Project Member

Comment 3 by ClusterFuzz, Feb 22 2017

ClusterFuzz has detected this issue as fixed in range 451788:451857.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6025990540361728

Fuzzer: ifratric-browserfuzzer-v3
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  blink::LayoutListItem::calcValue
  updateValueNow
  value
  
Sanitizer: undefined (UBSAN)

Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=434178:434216
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=451788:451857

Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv95X6_gpNR-e5J3mLuigQtjtKJhT8-5NYHJUhukDrKSzaQsZ92BzSvSKGQkVsoLi9MTRMwKNNofE4wT-mmRCODYK1eT79tg5a4nAElf121udF-rYGASVI_YHEEOGWVCt9FZjrZ_rSEKWwGkJrGym3Dx4qaPpYQ?testcase_id=6025990540361728


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 4 by ClusterFuzz, Feb 22 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 6025990540361728 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment