Issue metadata
Sign in to add a comment
|
Heap-use-after-free in base::Timer::RunScheduledTask |
||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4732537512656896 Fuzzer: inferno_twister Job Type: mac_asan_content_shell Platform Id: mac Crash Type: Heap-use-after-free READ 8 Crash Address: 0x61f00005b098 Crash State: base::Timer::RunScheduledTask base::debug::TaskAnnotator::RunTask base::MessageLoop::RunTask Sanitizer: address (ASAN) Recommended Security Severity: High Regressed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_content_shell&range=411257:411277 Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97oLjt7Ffmp2860AGcWDykqcdzBiUB1txpJ-NqBSuXpQ-x1Nryxotz4S2R-39sSwRAzgdUOfKGkkV4K3In86iei3ptT9FhEXYBtvk5_xhkqp19b2Hba7oSH3y-g8yL_yM66GUZ4CP00EsSy6-ihnIBNB1_2GAvLXDNkHR0vqlacZj0gYzX3GY-NovcrMB37NmAeAPdBGpN5LqGF5Ae5fB_a-ck2WaD2Fb1sXtIf3M4zi89hvM3G4ugFmcrkm-IP-EGHGwaR1YqDsYlWI28QiBbhWtSqcv4CL5FFjlJzt15eX6D9_lyqcb1q3yeYjVgLegpRO2T3FO9rVc1yTydw-DfMx7DcqWTurGLGTMRbWC_H6FAY_lGhnrXEHBshe51a5FHzg79K3pcTOh7PQv5h7rhn884Njw?testcase_id=4732537512656896 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Feb 21 2017
This issue is a security regression. If you are not able to fix this quickly, please revert the change that introduced it. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Feb 21 2017
,
Feb 22 2017
,
Jun 2 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by sheriffbot@chromium.org
, Feb 21 2017