New issue
Advanced search Search tips

Issue 683698 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 684407
Owner:
Closed: Jan 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: All
Pri: 1
Type: Bug-Security



Sign in to add a comment

Crash in v8::internal::Invoke

Project Member Reported by ClusterFuzz, Jan 22 2017

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5739655183204352

Fuzzer: libfuzzer_v8_wasm_code_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: UNKNOWN WRITE
Crash Address: 0x000001acbe51
Crash State:
  v8::internal::Invoke
  v8::internal::CallInternal
  v8::internal::Execution::Call
  
Sanitizer: address (ASAN)

Recommended Security Severity: High

Minimized Testcase (0.09 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96-0fIwTzntyWTb5JZA9WAi_fNFwIahGN6lVhBJF2zP2tEyTKauVyzUM9kcLAqUrpP9cV2zIT6tz7uv5_mH2KZ-XBbc_QwF0tQU8_ifYhmJzbYVJWe2uArsh14RJtDMlNttiTeBbOhjxnYl6yRfDg6hB1vH0LgzlHHGCHzSGy9VEpwn9P0gOVZNoCqxzxrRocMgxmqudC4DFMbM7yjdnAWW_X5EbNh2KeAKfMpmEUw4oDe5Or9Fwwoqj5D5EaExcTHEGRYfDqQXleuxzTI8-dMSKd4g5hD7r2yDbxxsnihq8HfB6Hm9ATi-SS_y9_rYY8jwWvOkrdDhQ1V0dI2HKTsnegcI0Q5_zyJ2fke4SirVHzRy7Jk?testcase_id=5739655183204352

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 
Project Member

Comment 1 by sheriffbot@chromium.org, Jan 23 2017

Labels: M-55
Project Member

Comment 2 by sheriffbot@chromium.org, Jan 23 2017

Labels: Pri-1
Cc: mstarzinger@chromium.org
Components: Blink>JavaScript>WebAssembly
Labels: -OS-Linux OS-All
Punting to the current v8 clusterfuzz sheriff.
Cc: ahaas@chromium.org
Owner: titzer@chromium.org
Status: Assigned (was: Untriaged)
Crash in WASM code from WASM fuzzer.
Project Member

Comment 5 by sheriffbot@chromium.org, Jan 26 2017

Labels: -M-55 M-56
Project Member

Comment 6 by ClusterFuzz, Jan 27 2017

ClusterFuzz has detected this issue as fixed in range 446320:446401.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5739655183204352

Fuzzer: libfuzzer_v8_wasm_code_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: UNKNOWN WRITE
Crash Address: 0x000001acbe51
Crash State:
  v8::internal::Invoke
  v8::internal::CallInternal
  v8::internal::Execution::Call
  
Sanitizer: address (ASAN)

Recommended Security Severity: High

Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=446320:446401

Minimized Testcase (0.09 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97Xu0Qht6wCWk0iCBforQ8FTSPmdFThznfLXxXr6NR0D-u2mbvbWeGg2jOmhCYQOcEubww6l_9pEaAPiLHFxlGAJ0ymNPCcukW3hBd3I8HQ6X8KkGFZfJ5Q7dmBorWSWgetvYv5PzEMiMwKjNknJnVf4LBZC0CHJGGaTfT7li9hStPfZUX5HGzYNz2dDwfkvz0lQpkxkwnEsFnv5378upJ25HF3CilI-iV5uA7ZHRSGETnMr5vdHpAK0_-ThfutEr7JvZuDCqqNSYDQ8Ww-s9rHQdk0VUvu0u2z8DYw1pOidKAY-ODCYa7JASph-dfMCxNUccmIRVFZkVfSf2Bphu6DMaS3sdu8YKwxBJovD7EoQQRSjkY?testcase_id=5739655183204352

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 7 by ClusterFuzz, Jan 27 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 5739655183204352 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 8 by sheriffbot@chromium.org, Jan 27 2017

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Project Member

Comment 9 by sheriffbot@chromium.org, Feb 3 2017

Labels: Merge-Request-57
Project Member

Comment 10 by sheriffbot@chromium.org, Feb 4 2017

Labels: -Merge-Request-57 Hotlist-Merge-Approved Merge-Approved-57
Your change meets the bar and is auto-approved for M57. Please go ahead and merge the CL to branch 2987 manually. Please contact milestone owner if you have questions.
Owners: amineer@(clank), cmasso@(bling), ketakid@(cros), govind@(desktop)

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Please merge your change to M57 branch 2987 before 5:00 PM PT, Monday (02/06/) so we can pick it up for next Beta release. Thank you.
Project Member

Comment 12 by sheriffbot@chromium.org, Feb 7 2017

This issue has been approved for a merge. Please merge the fix to any appropriate branches as soon as possible!

If all merges have been completed, please remove any remaining Merge-Approved labels from this issue.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
If possible, please merge your change to M57 branch 2987 before 5:00 PM PT today, Tuesday (02/07/17) so we can pick it up for tomorrow's Beta release. Thank you.
Please merge your change to M57 branch 2987 before 5:00 PM PT, Friday 02/10 (sooner the better please) so we can take it in for next week beta release. Thank you.
Mergedinto: 684407
Status: Duplicate (was: Verified)
Please merge your change to M57 branch 2987 before 5:00 PM PT, Friday 02/10 so we can take it in for next week beta release. Thank you.
Labels: -Merge-Approved-57 merge-merged-5.7
Per comment #17, this is already merged to M57.
Project Member

Comment 19 by sheriffbot@chromium.org, May 7 2017

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment