New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 683069 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 683104
Owner:
Last visit > 30 days ago
Closed: Jan 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Security



Sign in to add a comment

Heap-use-after-free in blink::LayoutBlockFlow::moveAllChildrenIncludingFloatsTo

Project Member Reported by ClusterFuzz, Jan 20 2017

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5218368828473344

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_asan_chrome_v8_arm
Platform Id: linux

Crash Type: Heap-use-after-free READ 4
Crash Address: 0xb6f2a0b4
Crash State:
  blink::LayoutBlockFlow::moveAllChildrenIncludingFloatsTo
  blink::LayoutRubyBase::moveBlockChildren
  blink::LayoutRubyBase::moveChildren
  
Sanitizer: address (ASAN)

Recommended Security Severity: High

Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=444763:444844

Minimized Testcase (1.28 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95AR7tgdqMjWCIposoKsTDaXpdeu3UJV7V0Vxeea1WKPI5h8DD2g6yoLYtTNsSkpun1wpTy0Z5YDFxjbXLJqsG9030udAjTdAmow0Wy3qBK0bD1u1Say8hXHOcJNr3W3GodJSM0fPA3P6K7JrR1JmhKQK6L7VLnYh_ojJn3Wfrpk_K4_sxB2fG7jg2ImqRbRDExuUGbeaaMTrerB3PcFEv3yvsBwTSistjmZlbwm1Ho_PGk-JRVbjTqskHce0gHf6Nz4uJzkdQO89Pc8yL5zvU2F-aPKte63fLneuVPpJF8VMaoj2ByvXdWaV9V2JN1LncID-4_wDmtHzuDymFNwYbKkhhC5gwboFKV2ijn8QdSxW01Zpo?testcase_id=5218368828473344

Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Project Member

Comment 1 by sheriffbot@chromium.org, Jan 20 2017

Labels: M-57
Project Member

Comment 2 by sheriffbot@chromium.org, Jan 20 2017

Labels: ReleaseBlock-Beta
This issue is a security regression. If you are not able to fix this quickly, please revert the change that introduced it.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 3 by sheriffbot@chromium.org, Jan 20 2017

Labels: Pri-1

Comment 4 by gov...@chromium.org, Jan 23 2017


A friendly reminder that M57 Beta launch is coming soon on February 2nd! Your bug is labelled as Beta ReleaseBlock, pls make sure to land the fix and get it merged into the release branch (2987) ASAP so it gets enough baking time in Dev (before Beta promotion). Thank you!
Components: Blink>Layout
Owner: robho...@gmail.com
Status: Assigned (was: Untriaged)
robhogan@: It seems you tried to fix this in  Issue 681423 . That one got detected as fixed, but this one got subsequently found.

Comment 6 by robho...@gmail.com, Jan 23 2017

Cc: robhogan@chromium.org
Mergedinto: 683104
Status: Duplicate (was: Assigned)
Project Member

Comment 8 by ClusterFuzz, Jan 26 2017

ClusterFuzz has detected this issue as fixed in range 446211:446229.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5218368828473344

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_asan_chrome_v8_arm
Platform Id: linux

Crash Type: Heap-use-after-free READ 4
Crash Address: 0xb6f2a0b4
Crash State:
  blink::LayoutBlockFlow::moveAllChildrenIncludingFloatsTo
  blink::LayoutRubyBase::moveBlockChildren
  blink::LayoutRubyBase::moveChildren
  
Sanitizer: address (ASAN)

Recommended Security Severity: High

Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=444763:444844
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=446211:446229

Minimized Testcase (1.28 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95AR7tgdqMjWCIposoKsTDaXpdeu3UJV7V0Vxeea1WKPI5h8DD2g6yoLYtTNsSkpun1wpTy0Z5YDFxjbXLJqsG9030udAjTdAmow0Wy3qBK0bD1u1Say8hXHOcJNr3W3GodJSM0fPA3P6K7JrR1JmhKQK6L7VLnYh_ojJn3Wfrpk_K4_sxB2fG7jg2ImqRbRDExuUGbeaaMTrerB3PcFEv3yvsBwTSistjmZlbwm1Ho_PGk-JRVbjTqskHce0gHf6Nz4uJzkdQO89Pc8yL5zvU2F-aPKte63fLneuVPpJF8VMaoj2ByvXdWaV9V2JN1LncID-4_wDmtHzuDymFNwYbKkhhC5gwboFKV2ijn8QdSxW01Zpo?testcase_id=5218368828473344

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Labels: -ReleaseBlock-Beta
Project Member

Comment 10 by ClusterFuzz, Jan 28 2017

ClusterFuzz has detected this issue as fixed in range 446318:446618.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5218368828473344

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_asan_chrome_v8_arm
Platform Id: linux

Crash Type: Heap-use-after-free READ 4
Crash Address: 0xb6f2a0b4
Crash State:
  blink::LayoutBlockFlow::moveAllChildrenIncludingFloatsTo
  blink::LayoutRubyBase::moveBlockChildren
  blink::LayoutRubyBase::moveChildren
  
Sanitizer: address (ASAN)

Recommended Security Severity: High

Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=444763:444844
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=446318:446618

Minimized Testcase (1.28 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95AR7tgdqMjWCIposoKsTDaXpdeu3UJV7V0Vxeea1WKPI5h8DD2g6yoLYtTNsSkpun1wpTy0Z5YDFxjbXLJqsG9030udAjTdAmow0Wy3qBK0bD1u1Say8hXHOcJNr3W3GodJSM0fPA3P6K7JrR1JmhKQK6L7VLnYh_ojJn3Wfrpk_K4_sxB2fG7jg2ImqRbRDExuUGbeaaMTrerB3PcFEv3yvsBwTSistjmZlbwm1Ho_PGk-JRVbjTqskHce0gHf6Nz4uJzkdQO89Pc8yL5zvU2F-aPKte63fLneuVPpJF8VMaoj2ByvXdWaV9V2JN1LncID-4_wDmtHzuDymFNwYbKkhhC5gwboFKV2ijn8QdSxW01Zpo?testcase_id=5218368828473344

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 11 by sheriffbot@chromium.org, May 7 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment