Heap-use-after-free in base::ObserverListBase<aura::client::CaptureClientObserver>::begin |
|||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6141051216855040 Fuzzer: inferno_layout_test_unmodified Job Type: windows_syzyasan_content_shell Platform Id: windows Crash Type: Heap-use-after-free READ 4 Crash Address: 0x2d3b13ff Crash State: base::ObserverListBase<aura::client::CaptureClientObserver>::begin device::MockBluetoothGattNotifySession::DoNotify base::internal::Invoker<base::internal::BindState<void Memory Tool: SYZYASAN Recommended Security Severity: High Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_syzyasan_content_shell&range=441510:441524 Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv96Zjs9LSmdonbdKlrJDM7kjCeG3r7NgnloRsKXV9zeXccVR2eOTRbtPU629ArPd7gV2d3Xcf0sHaMtVlzfzqX4PlV5yyUhxRF8E-miEHB8MiV32erHVmkgc_ZF933bkL2OL6v-Yde4YSaDLY4l39MBzwB7-_HglWq5BRncc8EwdcTixu3a-Fm-MbsvLEb168WESxIAWxnPlL3G_Z4VrlRr4l4NmSD3mYX9TU8XgqVXcdK4RTJI6WdFSzAM760cAELYhNiesYSZSkQm4CZ1vCfudqGrbku5A7GsRdNkeS-cBVK_A1JDP-E-3Wc8BqkU8fJ_NPzOlDWo69vyntDHfQHHbou15VxS1ftm8H_wLfDxe929iNV6NjahcRmdmiPmDtg8vmWA4ny1bFIhGUdtLaAMyX3fXnw?testcase_id=6141051216855040 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jan 22 2017
This issue is a security regression. If you are not able to fix this quickly, please revert the change that introduced it. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jan 22 2017
,
Jan 23 2017
A friendly reminder that M57 Beta launch is coming soon on February 2nd! Your bug is labelled as Beta ReleaseBlock, pls make sure to land the fix and get it merged into the release branch (2987) ASAP so it gets enough baking time in Dev (before Beta promotion). Thank you!
,
Jan 23 2017
scheib, do you think you could help find an owner for this security bug? It looks like the crash is in test-only code but it would be good if someone more knowledgeable about this code could confirm that's the case. Thanks!
,
Jan 23 2017
,
Jan 24 2017
I suspect this is Issue 668558 again. But I can't seem to find what resources are being used for the test. More specifically where is third_party/WebKit/LayoutTest/resources?
,
Jan 24 2017
The resources are enclosed
,
Jan 24 2017
Thanks aarya! As suspected the resources being used are from June 2016. These resources contain a test only function that deletes an object being used during testing. We've removed this function since, but fuzzers keep using it for some reason. Issue 668558 was supposed to address this but I guess there are some instances left over. aarya could you help us out with cleaning the necessary fuzzers again? Because this is a test only issue removing ReleaseBlock label.
,
Jan 24 2017
,
Jan 25 2017
,
Jan 26 2017
,
Feb 22 2017
,
Feb 22 2017
Issue 694353 has been merged into this issue.
,
Mar 16 2017
,
Mar 16 2017
,
Apr 20 2017
ClusterFuzz has detected this issue as fixed in range 465765:465806. Detailed report: https://clusterfuzz.com/testcase?key=6141051216855040 Fuzzer: inferno_layout_test_unmodified Job Type: windows_syzyasan_content_shell Platform Id: windows Crash Type: Heap-use-after-free READ 4 Crash Address: 0x2d3b13ff Crash State: base::ObserverListBase<aura::client::CaptureClientObserver>::begin device::MockBluetoothGattNotifySession::DoNotify base::internal::Invoker<base::internal::BindState<void Memory Tool: SYZYASAN Recommended Security Severity: High Regressed: https://clusterfuzz.com/revisions?job=windows_syzyasan_content_shell&range=441510:441524 Fixed: https://clusterfuzz.com/revisions?job=windows_syzyasan_content_shell&range=465765:465806 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv96Zjs9LSmdonbdKlrJDM7kjCeG3r7NgnloRsKXV9zeXccVR2eOTRbtPU629ArPd7gV2d3Xcf0sHaMtVlzfzqX4PlV5yyUhxRF8E-miEHB8MiV32erHVmkgc_ZF933bkL2OL6v-Yde4YSaDLY4l39MBzwB7-_HglWq5BRncc8EwdcTixu3a-Fm-MbsvLEb168WESxIAWxnPlL3G_Z4VrlRr4l4NmSD3mYX9TU8XgqVXcdK4RTJI6WdFSzAM760cAELYhNiesYSZSkQm4CZ1vCfudqGrbku5A7GsRdNkeS-cBVK_A1JDP-E-3Wc8BqkU8fJ_NPzOlDWo69vyntDHfQHHbou15VxS1ftm8H_wLfDxe929iNV6NjahcRmdmiPmDtg8vmWA4ny1bFIhGUdtLaAMyX3fXnw?testcase_id=6141051216855040 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jun 1 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||
►
Sign in to add a comment |
|||||||||||||
Comment 1 by sheriffbot@chromium.org
, Jan 22 2017