Crash in refCachedImage |
||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5961328499097600 Fuzzer: inferno_layout_test_unmodified Job Type: linux_lsan_chrome_mp Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000028 Crash State: refCachedImage SkSurface::makeImageSnapshot createTransparentSkImage Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=440099:440242 Minimized Testcase (19.08 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97VkTscJ_yRcII1QaCLgehk7C_UT-KNd7YneqtEfpbJ5Uqe50K9h8ksJLua2VHyYilb6uMh_jbpMq15r-n5X6ke_7fQKe9aY4-8ZDn9s8-IHBmAXi3WqKbirDr5HNjHOzyM1SHM_Uld82TuyMsY6inK4QG8A9_ELYaq35y5augZ2Xi2lY0?testcase_id=5961328499097600 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Dec 22 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/f24759eb82410ae9383cc527bb6aecb7f72d2747 commit f24759eb82410ae9383cc527bb6aecb7f72d2747 Author: junov <junov@chromium.org> Date: Thu Dec 22 21:30:15 2016 Add missing null pointer check in HTMLCanvasElement.cpp Fixing an oversight from previous CL: https://codereview.chromium.org/2594093002/ BUG= 676585 TBR=xlai@chromium.org Review-Url: https://codereview.chromium.org/2598963004 Cr-Commit-Position: refs/heads/master@{#440509} [modify] https://crrev.com/f24759eb82410ae9383cc527bb6aecb7f72d2747/third_party/WebKit/Source/core/html/HTMLCanvasElement.cpp
,
Dec 24 2016
ClusterFuzz has detected this issue as fixed in range 440490:440591. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5961328499097600 Fuzzer: inferno_layout_test_unmodified Job Type: linux_lsan_chrome_mp Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000028 Crash State: refCachedImage SkSurface::makeImageSnapshot createTransparentSkImage Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=440099:440242 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=440490:440591 Minimized Testcase (19.08 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97VkTscJ_yRcII1QaCLgehk7C_UT-KNd7YneqtEfpbJ5Uqe50K9h8ksJLua2VHyYilb6uMh_jbpMq15r-n5X6ke_7fQKe9aY4-8ZDn9s8-IHBmAXi3WqKbirDr5HNjHOzyM1SHM_Uld82TuyMsY6inK4QG8A9_ELYaq35y5augZ2Xi2lY0?testcase_id=5961328499097600 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Dec 24 2016
ClusterFuzz testcase 5961328499097600 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
||
►
Sign in to add a comment |
||
Comment 1 by msrchandra@chromium.org
, Dec 22 2016Components: Blink>HTML
Labels: Test-Predator-Correct-CLs
Owner: junov@chromium.org
Status: Assigned (was: Untriaged)