Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4508344833540096 Fuzzer: foozzie_js_mutation Job Type: foozzie_ignition_staging Platform Id: linux Crash Type: V8 correctness failure Crash Address: Crash State: suppression: internal_error Sanitizer: address (ASAN) Minimized Testcase (0.11 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv97nOgBAE2hJLuCXEWoEV_uk9-2zCgFQT1qQK_OCgMHNaTDKeBMT3ICrI0dIo7RjsENla-WFFD7AzTrDhjg8hadugOwguOQV9fiVRZPAEfH9UiMP5bFE_XV7opdIhebv7Vq6bc-cgzFjdsAJLLDeDcOw7_9kTdRy2C17h1raom7I1muNYYuHLy6BFELs8qopiy9rKmlukTNbD-phA5JkeVxyD0bFJphoT303t-CVTC99my9LSGhOkUKmtN0CyFcjg0dT6oqmU7BrUSHMJ4wzZQ7cQ5agckAJSzgjID4gRriVNK-UJR0b7DvfLPZJvgJ1qaWDbC0DDTgEi1pV-ZKJg3bGfa76v3_fHKn5hleyuwmkcQx6ZSI?testcase_id=4508344833540096 try { __v_1 = "a"; for (var __v_0 = 0; __v_0 < 28; __v_0++) { __v_1 += __v_1; } } catch(e) {; } print(__v_1); Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
Comment 1 by machenb...@chromium.org
, Jan 24 2017