Issue metadata
Sign in to add a comment
|
Use-of-uninitialized-value in blink::FloatingObject::unsafeClone |
||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4533190279823360 Fuzzer: inferno_layout_test_unmodified Job Type: linux_msan_chrome Platform Id: linux Crash Type: Use-of-uninitialized-value Crash Address: Crash State: blink::FloatingObject::unsafeClone blink::LayoutBlockFlow::moveAllChildrenIncludingFloatsTo blink::LayoutRubyBase::moveChildren Sanitizer: memory (MSAN) Recommended Security Severity: Medium Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_msan_chrome&range=444763:444813 Minimized Testcase (1.11 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96tbXVx0rO-FxC7faCfIwWu_uXekUkn3b3Jnvxz2PagRU0Dm3ekBdYpyzNVnZZ94DDUZgD87f0TlsFs2625np0inx-gwMqQJcjqrWYxqci1tBeKbFGs1qR5qcfVsXk1jWt_H4PKXQYwvAb6f1qxHW8H2gHrKSJIeBNCsw9_8SP5MUfe8Dt4CMRpwCQKSz-y5-SVpNr6GMGC7wGFGlTmRIhS6bJHFiSq_1Zu4t53KD5gHoi1im4_wRgDLLoaBautWDfOxchYqnWSZ2MjecopD7T3sCJui_0WUJqEIb8F60soUFEdel3mL8hTosZ1Kjaz-hthYgjbfgbitgx8l1Kqh6EKCDNNfoSGh0Yahhok6upLc7IpJIw?testcase_id=4533190279823360 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jan 20 2017
This issue is a security regression. If you are not able to fix this quickly, please revert the change that introduced it. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jan 20 2017
,
Jan 23 2017
A friendly reminder that M57 Beta launch is coming soon on February 2nd! Your bug is labelled as Beta ReleaseBlock, pls make sure to land the fix and get it merged into the release branch (2987) ASAP so it gets enough baking time in Dev (before Beta promotion). Thank you!
,
Jan 23 2017
robhogan: here's another one that looks like it might be related to https://codereview.chromium.org/2329863002 (or maybe possibly a dupe of issue 683104 ). Please take a look if you can. Thanks!
,
Jan 23 2017
,
Jan 26 2017
ClusterFuzz has detected this issue as fixed in range 446211:446229. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4533190279823360 Fuzzer: inferno_layout_test_unmodified Job Type: linux_msan_chrome Platform Id: linux Crash Type: Use-of-uninitialized-value Crash Address: Crash State: blink::FloatingObject::unsafeClone blink::LayoutBlockFlow::moveAllChildrenIncludingFloatsTo blink::LayoutRubyBase::moveChildren Sanitizer: memory (MSAN) Recommended Security Severity: Medium Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_msan_chrome&range=444763:444813 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_msan_chrome&range=446211:446229 Minimized Testcase (1.11 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96tbXVx0rO-FxC7faCfIwWu_uXekUkn3b3Jnvxz2PagRU0Dm3ekBdYpyzNVnZZ94DDUZgD87f0TlsFs2625np0inx-gwMqQJcjqrWYxqci1tBeKbFGs1qR5qcfVsXk1jWt_H4PKXQYwvAb6f1qxHW8H2gHrKSJIeBNCsw9_8SP5MUfe8Dt4CMRpwCQKSz-y5-SVpNr6GMGC7wGFGlTmRIhS6bJHFiSq_1Zu4t53KD5gHoi1im4_wRgDLLoaBautWDfOxchYqnWSZ2MjecopD7T3sCJui_0WUJqEIb8F60soUFEdel3mL8hTosZ1Kjaz-hthYgjbfgbitgx8l1Kqh6EKCDNNfoSGh0Yahhok6upLc7IpJIw?testcase_id=4533190279823360 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jan 27 2017
,
Jan 28 2017
ClusterFuzz has detected this issue as fixed in range 446318:446618. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4533190279823360 Fuzzer: inferno_layout_test_unmodified Job Type: linux_msan_chrome Platform Id: linux Crash Type: Use-of-uninitialized-value Crash Address: Crash State: blink::FloatingObject::unsafeClone blink::LayoutBlockFlow::moveAllChildrenIncludingFloatsTo blink::LayoutRubyBase::moveChildren Sanitizer: memory (MSAN) Recommended Security Severity: Medium Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_msan_chrome&range=444763:444813 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_msan_chrome&range=446318:446618 Minimized Testcase (1.11 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96tbXVx0rO-FxC7faCfIwWu_uXekUkn3b3Jnvxz2PagRU0Dm3ekBdYpyzNVnZZ94DDUZgD87f0TlsFs2625np0inx-gwMqQJcjqrWYxqci1tBeKbFGs1qR5qcfVsXk1jWt_H4PKXQYwvAb6f1qxHW8H2gHrKSJIeBNCsw9_8SP5MUfe8Dt4CMRpwCQKSz-y5-SVpNr6GMGC7wGFGlTmRIhS6bJHFiSq_1Zu4t53KD5gHoi1im4_wRgDLLoaBautWDfOxchYqnWSZ2MjecopD7T3sCJui_0WUJqEIb8F60soUFEdel3mL8hTosZ1Kjaz-hthYgjbfgbitgx8l1Kqh6EKCDNNfoSGh0Yahhok6upLc7IpJIw?testcase_id=4533190279823360 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
May 7 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by sheriffbot@chromium.org
, Jan 20 2017