Integer-overflow in blink::PaintLayerScrollableArea::pageStep |
||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5127091340443648 Fuzzer: ifratric-browserfuzzer-v3 Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: blink::PaintLayerScrollableArea::pageStep blink::ScrollableArea::scrollStep blink::ScrollableArea::userScroll Sanitizer: undefined (UBSAN) Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=395936:396053 Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv95RqvK3hcazGN31eIVez4hE0KpxJqM-vOnnb4-sjgI0jLt5px_2IUWuW9zX0dgU_riUK652AvGDudcuv40dyp21pE1iV2rXmE6vrEalWXNFl2V-qhiQOZtQdrcdDUUKHrWxEwjzn3KsE4At8TzV7LRpsKVs6g?testcase_id=5127091340443648 Additional requirements: Requires Gestures Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Feb 24 2017
ClusterFuzz testcase 5127091340443648 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
||
►
Sign in to add a comment |
||
Comment 1 by ClusterFuzz
, Feb 24 2017