Issue metadata
Sign in to add a comment
|
Heap-use-after-free in blink::LayoutBlockFlow::moveAllChildrenIncludingFloatsTo |
||||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5218368828473344 Fuzzer: inferno_layout_test_unmodified Job Type: linux_asan_chrome_v8_arm Platform Id: linux Crash Type: Heap-use-after-free READ 4 Crash Address: 0xb6f2a0b4 Crash State: blink::LayoutBlockFlow::moveAllChildrenIncludingFloatsTo blink::LayoutRubyBase::moveBlockChildren blink::LayoutRubyBase::moveChildren Sanitizer: address (ASAN) Recommended Security Severity: High Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=444763:444844 Minimized Testcase (1.28 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95AR7tgdqMjWCIposoKsTDaXpdeu3UJV7V0Vxeea1WKPI5h8DD2g6yoLYtTNsSkpun1wpTy0Z5YDFxjbXLJqsG9030udAjTdAmow0Wy3qBK0bD1u1Say8hXHOcJNr3W3GodJSM0fPA3P6K7JrR1JmhKQK6L7VLnYh_ojJn3Wfrpk_K4_sxB2fG7jg2ImqRbRDExuUGbeaaMTrerB3PcFEv3yvsBwTSistjmZlbwm1Ho_PGk-JRVbjTqskHce0gHf6Nz4uJzkdQO89Pc8yL5zvU2F-aPKte63fLneuVPpJF8VMaoj2ByvXdWaV9V2JN1LncID-4_wDmtHzuDymFNwYbKkhhC5gwboFKV2ijn8QdSxW01Zpo?testcase_id=5218368828473344 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jan 20 2017
This issue is a security regression. If you are not able to fix this quickly, please revert the change that introduced it. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jan 20 2017
,
Jan 23 2017
A friendly reminder that M57 Beta launch is coming soon on February 2nd! Your bug is labelled as Beta ReleaseBlock, pls make sure to land the fix and get it merged into the release branch (2987) ASAP so it gets enough baking time in Dev (before Beta promotion). Thank you!
,
Jan 23 2017
robhogan@: It seems you tried to fix this in Issue 681423 . That one got detected as fixed, but this one got subsequently found.
,
Jan 23 2017
,
Jan 23 2017
,
Jan 26 2017
ClusterFuzz has detected this issue as fixed in range 446211:446229. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5218368828473344 Fuzzer: inferno_layout_test_unmodified Job Type: linux_asan_chrome_v8_arm Platform Id: linux Crash Type: Heap-use-after-free READ 4 Crash Address: 0xb6f2a0b4 Crash State: blink::LayoutBlockFlow::moveAllChildrenIncludingFloatsTo blink::LayoutRubyBase::moveBlockChildren blink::LayoutRubyBase::moveChildren Sanitizer: address (ASAN) Recommended Security Severity: High Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=444763:444844 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=446211:446229 Minimized Testcase (1.28 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95AR7tgdqMjWCIposoKsTDaXpdeu3UJV7V0Vxeea1WKPI5h8DD2g6yoLYtTNsSkpun1wpTy0Z5YDFxjbXLJqsG9030udAjTdAmow0Wy3qBK0bD1u1Say8hXHOcJNr3W3GodJSM0fPA3P6K7JrR1JmhKQK6L7VLnYh_ojJn3Wfrpk_K4_sxB2fG7jg2ImqRbRDExuUGbeaaMTrerB3PcFEv3yvsBwTSistjmZlbwm1Ho_PGk-JRVbjTqskHce0gHf6Nz4uJzkdQO89Pc8yL5zvU2F-aPKte63fLneuVPpJF8VMaoj2ByvXdWaV9V2JN1LncID-4_wDmtHzuDymFNwYbKkhhC5gwboFKV2ijn8QdSxW01Zpo?testcase_id=5218368828473344 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jan 27 2017
,
Jan 28 2017
ClusterFuzz has detected this issue as fixed in range 446318:446618. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5218368828473344 Fuzzer: inferno_layout_test_unmodified Job Type: linux_asan_chrome_v8_arm Platform Id: linux Crash Type: Heap-use-after-free READ 4 Crash Address: 0xb6f2a0b4 Crash State: blink::LayoutBlockFlow::moveAllChildrenIncludingFloatsTo blink::LayoutRubyBase::moveBlockChildren blink::LayoutRubyBase::moveChildren Sanitizer: address (ASAN) Recommended Security Severity: High Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=444763:444844 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=446318:446618 Minimized Testcase (1.28 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95AR7tgdqMjWCIposoKsTDaXpdeu3UJV7V0Vxeea1WKPI5h8DD2g6yoLYtTNsSkpun1wpTy0Z5YDFxjbXLJqsG9030udAjTdAmow0Wy3qBK0bD1u1Say8hXHOcJNr3W3GodJSM0fPA3P6K7JrR1JmhKQK6L7VLnYh_ojJn3Wfrpk_K4_sxB2fG7jg2ImqRbRDExuUGbeaaMTrerB3PcFEv3yvsBwTSistjmZlbwm1Ho_PGk-JRVbjTqskHce0gHf6Nz4uJzkdQO89Pc8yL5zvU2F-aPKte63fLneuVPpJF8VMaoj2ByvXdWaV9V2JN1LncID-4_wDmtHzuDymFNwYbKkhhC5gwboFKV2ijn8QdSxW01Zpo?testcase_id=5218368828473344 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
May 7 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||
Comment 1 by sheriffbot@chromium.org
, Jan 20 2017