Issue metadata
Sign in to add a comment
|
Heap-use-after-free in v8::internal::Scope::is_function_scope |
||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5756337842814976 Fuzzer: decoder_langfuzz Job Type: linux_asan_d8 Platform Id: linux Crash Type: Heap-use-after-free READ 1 Crash Address: 0x625000043990 Crash State: v8::internal::Scope::is_function_scope v8::internal::Scope::MaxNestedContextChainLength v8::internal::interpreter::BytecodeGenerator::BytecodeGenerator Sanitizer: address (ASAN) Recommended Security Severity: High Regressed: V8: r42243:42244 Minimized Testcase (6.19 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96I5jkjLK34yRumSkuQV5xWeGswGVSyl5G755vbFLufwsRUebIG1yYWi3Imq7aAgahtRRxrfjTqto5LbVKMc8HQdYEvy4J_cJI4I0TWGbprGK1scmWLFEM9YvDZMqWkULlbDgeI99RMtLkipoZtCIm36XojOlqgqZL9e5Pfj2gFsaIDtRDNEn_z2fl2JpjoZEVRxELSaLBBE62HVCHBKa-c32QG1wasASxrfJIO-jl3Sl6WvJebbnJ1ZIiTyhWw54-IUKm85DLoPyz3Srb1WIztXGfFCc4Ti2zC6Z0o1y5nPUg8DQMWinCab9xIu-8RjNBVoceW2013fr0DnPna5XDk7REQPN2CIFlZlZJ9eW99cKjhNQ_aZRg7mJ5OCM0aV1snJxIAaMHogR9vAHW6Fh5ahxy5hQ?testcase_id=5756337842814976 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jan 12 2017
ClusterFuzz testcase 5756337842814976 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Jan 12 2017
,
Jan 23 2017
,
Apr 20 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jul 28
|
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by ClusterFuzz
, Jan 12 2017