Integer-overflow in blink::NinePieceImageGrid::NinePieceImageGrid |
||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5126889972957184 Fuzzer: inferno_twister Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: blink::NinePieceImageGrid::NinePieceImageGrid blink::NinePieceImagePainter::paint blink::BoxPainter::paintNinePieceImage Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=407167:409418 Minimized Testcase (0.42 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97GjR1Q-ntVROunjHbnNAiH5F44QJDbrRLa-3dbFvCx0GeGSKhc1Oc7m20ujmZXIGsglQRy60mC3tbN3KKFjyVLE9cT4RFIGm9y-s8o52VcZ6JeSk5ItWvZ_DfGkHJ1NDpeaEUMIcvH6xZIIQ3S5y9jD3ChyA?testcase_id=5126889972957184 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Feb 14 2017
ClusterFuzz has detected this issue as fixed in range 449941:449957. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5126889972957184 Fuzzer: inferno_twister Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: blink::NinePieceImageGrid::NinePieceImageGrid blink::NinePieceImagePainter::paint blink::BoxPainter::paintNinePieceImage Sanitizer: undefined (UBSAN) Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=407167:409418 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=449941:449957 Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97GjR1Q-ntVROunjHbnNAiH5F44QJDbrRLa-3dbFvCx0GeGSKhc1Oc7m20ujmZXIGsglQRy60mC3tbN3KKFjyVLE9cT4RFIGm9y-s8o52VcZ6JeSk5ItWvZ_DfGkHJ1NDpeaEUMIcvH6xZIIQ3S5y9jD3ChyA?testcase_id=5126889972957184 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Feb 14 2017
ClusterFuzz testcase 5126889972957184 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
||
►
Sign in to add a comment |
||
Comment 1 by msrchandra@chromium.org
, Dec 26 2016Components: Blink>Layout
Labels: Test-Predator-Correct-CLs
Owner: flackr@chromium.org
Status: Assigned (was: Untriaged)