Issue metadata
Sign in to add a comment
|
Crash in v8::internal::String::ToCString |
||||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6301623937925120 Fuzzer: decoder_langfuzz Job Type: linux_asan_chrome_v8_d8 Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x00011fff8001 Crash State: v8::internal::String::ToCString v8::internal::String::ToCString v8::internal::wasm::AsmTyper::ImportLookup Sanitizer: address (ASAN) Recommended Security Severity: Medium Regressed: V8: r42212:42308 Minimized Testcase (10.65 Kb): https://cluster-fuzz.appspot.com/download/AMIfv973mfGONYw_8bj-JVJgUKr6s30MKo2FEZMnOImrE814-zmlM_RkpN4CpW-6PzlMFAGs4ICsCAWh_7O7Jx9wiKHI2XYi_9BBO-48LkCjglwYwLZ4bktXfUhRRiHZQKzU8IMEoZFh-UYrNXZw7L1HLa7KBCvJnV1KRcJv20sDnTwMYssFUHZeNU-hxziN84dOJbzJD-gZJkg2TMxQVQrZc1ZJNuQRpY5GQfn-lrKS1UNPzq-1fv3sbDSil-eFlczRJtJARl2TOjI8utnGnHjA2AIgRIf-FO-BDlnZSKyf4BtPsuBAKx5gCaKvE-dmlHu0KLMPvEQe-hdzqQVsmFexmWzTdyYbGjAXOonJF1haIFee7S6XAuo?testcase_id=6301623937925120 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jan 15 2017
This issue is a security regression. If you are not able to fix this quickly, please revert the change that introduced it. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jan 15 2017
,
Jan 16 2017
Some string related changes in the ranges. Jakob's was reverted in the same range though.
,
Jan 17 2017
Assigning to one of the v8 sheriffs to triage.
,
Jan 17 2017
Re-assigning to this week's CF sheriff.
,
Jan 17 2017
Repro revision range is not useful, but the crash is in AsmTyper. @bradnelson, can you please have a look?
,
Jan 17 2017
,
Jan 18 2017
,
Jan 19 2017
ClusterFuzz has detected this issue as fixed in range 42432:42456. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6301623937925120 Fuzzer: decoder_langfuzz Job Type: linux_asan_chrome_v8_d8 Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x00011fff8001 Crash State: v8::internal::String::ToCString v8::internal::String::ToCString v8::internal::wasm::AsmTyper::ImportLookup Sanitizer: address (ASAN) Recommended Security Severity: Medium Regressed: V8: 42212:42308 Fixed: V8: 42432:42456 Minimized Testcase (10.65 Kb): https://cluster-fuzz.appspot.com/download/AMIfv973mfGONYw_8bj-JVJgUKr6s30MKo2FEZMnOImrE814-zmlM_RkpN4CpW-6PzlMFAGs4ICsCAWh_7O7Jx9wiKHI2XYi_9BBO-48LkCjglwYwLZ4bktXfUhRRiHZQKzU8IMEoZFh-UYrNXZw7L1HLa7KBCvJnV1KRcJv20sDnTwMYssFUHZeNU-hxziN84dOJbzJD-gZJkg2TMxQVQrZc1ZJNuQRpY5GQfn-lrKS1UNPzq-1fv3sbDSil-eFlczRJtJARl2TOjI8utnGnHjA2AIgRIf-FO-BDlnZSKyf4BtPsuBAKx5gCaKvE-dmlHu0KLMPvEQe-hdzqQVsmFexmWzTdyYbGjAXOonJF1haIFee7S6XAuo?testcase_id=6301623937925120 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jan 27 2017
,
Apr 26 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||
Comment 1 by sheriffbot@chromium.org
, Jan 15 2017