size == 1 << static_cast<int>( binop->right()->AsLiteral()->raw_value()->AsNumbe |
||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4840172631097344 Fuzzer: mbarbella_js_mutation Job Type: linux_asan_d8_ignition_turbo_dbg Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: size == 1 << static_cast<int>( binop->right()->AsLiteral()->raw_value()->AsNumbe Sanitizer: address (ASAN) Regressed: V8: 41514:41515 Minimized Testcase (0.61 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96PKkySMjzO9VUL4eDghL-Ui02D-HLFVNxFXAMagPgfUBfF7qxKQkjirqOngv-bqAPcbraS2iiCek0ap6m2bwZhMbbqUEvuJDZekUVHX2GRo6Y7Fhe1B3vy1BuenB_0V78TdDsZDOqCwLGu8Sfj8DYy0A0tcendq90F-RcmHDNGCnXqrUu7Re16Tia9xncLRnrYnUTQIi8GzUgaD0o07l-8OjMdQ9szu8wzgMLi8887h4qqdQInO9WDqv57sUMOpJkqcZDfacAUknU79HGP0cHOlL2cwRKEvxsQOq1tRdcEO-5zbaOVZnyLPVoT9D8MjQkQINo9MSQMhwQ9qfjKdUWeOe7Jt7DQsRuMtx9XuFjDulGske8?testcase_id=4840172631097344 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
May 30 2017
Should no longer happen with the new validator. I triggered a redo on ClusterFuzz.
,
Jun 8 2017
No longer applies to new validator. |
||
►
Sign in to add a comment |
||
Comment 1 by mstarzinger@chromium.org
, Jan 23 2017Status: Assigned (was: Untriaged)