New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 696462 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 696251
Owner:
OOO until 2019-02-10
Closed: Feb 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Security



Sign in to add a comment

Heap-buffer-overflow in __RT_impl_Runtime_TypedArraySortFast

Project Member Reported by ClusterFuzz, Feb 27 2017

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4613217012940800

Fuzzer: decoder_langfuzz
Job Type: linux_asan_d8
Platform Id: linux

Crash Type: Heap-buffer-overflow READ 1
Crash Address: 0x622000002c89
Crash State:
  __RT_impl_Runtime_TypedArraySortFast
  v8::internal::Runtime_TypedArraySortFast
  v8::internal::Invoke
  
Sanitizer: address (ASAN)

Recommended Security Severity: Medium

Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv94gxV8Oiifs-MqnmUOwuko57yt7uVFxQblYM9Cef_Dz15efgNXZvuCnY_Bf5ye1EUCtoPRePKldcqbbhGOG9wRl9odqkIjy5H4_-xk3GPQiKFfhyyS0FhTMCc02U6DyeGDWLrlmkPSiofcgsfZPG_ywSTkvTzdZl6ZxkC5gZkzp8PNJDWTI8dScTYKCpRlIKTedLanQFfGSjTWY1IMHXXzb6nGa1rFrISwXoRuVLEcT1_Oy3x765jys-PGq1hFamCaduMO9s-ZFhlQpFkTVtPpEPmbJ-Gw7sBZMGrPqm5xFUsrfeAqdgAV_jOJ9NONV7FgvRGk_8f2FfQzAw5zrB9bBs8upT_-81IPyl9nyv4E-svQ80aI?testcase_id=4613217012940800


Issue manually filed by: mstarzinger

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: titzer@chromium.org

Comment 2 by titzer@chromium.org, Feb 27 2017

Cc: -titzer@chromium.org cwhan.t...@gmail.com
Owner: petermarshall@chromium.org
Status: Assigned (was: Untriaged)
This is crashing in the new, fast, C++ code for sorting typed arrays.

It reproduces in debug mode on ToT.

Peter, can you take a look, since you reviewed the patch that introduced this code?

Comment 3 by titzer@chromium.org, Feb 27 2017

Cc: titzer@chromium.org
 Issue 696463  has been merged into this issue.
Project Member

Comment 5 by sheriffbot@chromium.org, Feb 27 2017

Labels: M-58
Project Member

Comment 6 by sheriffbot@chromium.org, Feb 27 2017

Labels: ReleaseBlock-Beta
This issue is a security regression. If you are not able to fix this quickly, please revert the change that introduced it.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 7 by sheriffbot@chromium.org, Feb 27 2017

Labels: Pri-1
Project Member

Comment 8 by ClusterFuzz, Feb 28 2017

ClusterFuzz has detected this issue as fixed in range 43445:43446.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4613217012940800

Fuzzer: decoder_langfuzz
Job Type: linux_asan_d8
Platform Id: linux

Crash Type: Heap-buffer-overflow READ 1
Crash Address: 0x622000002c89
Crash State:
  __RT_impl_Runtime_TypedArraySortFast
  v8::internal::Runtime_TypedArraySortFast
  v8::internal::Invoke
  
Sanitizer: address (ASAN)

Recommended Security Severity: Medium

Fixed: V8: 43445:43446

Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv94gxV8Oiifs-MqnmUOwuko57yt7uVFxQblYM9Cef_Dz15efgNXZvuCnY_Bf5ye1EUCtoPRePKldcqbbhGOG9wRl9odqkIjy5H4_-xk3GPQiKFfhyyS0FhTMCc02U6DyeGDWLrlmkPSiofcgsfZPG_ywSTkvTzdZl6ZxkC5gZkzp8PNJDWTI8dScTYKCpRlIKTedLanQFfGSjTWY1IMHXXzb6nGa1rFrISwXoRuVLEcT1_Oy3x765jys-PGq1hFamCaduMO9s-ZFhlQpFkTVtPpEPmbJ-Gw7sBZMGrPqm5xFUsrfeAqdgAV_jOJ9NONV7FgvRGk_8f2FfQzAw5zrB9bBs8upT_-81IPyl9nyv4E-svQ80aI?testcase_id=4613217012940800


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 9 by ClusterFuzz, Feb 28 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 5546830428635136 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 10 by sheriffbot@chromium.org, Mar 1 2017

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Mergedinto: 696251
Status: Duplicate (was: Verified)
Project Member

Comment 12 by sheriffbot@chromium.org, Mar 9 2017

Labels: -reward-topanel reward-ineligible
Project Member

Comment 13 by sheriffbot@chromium.org, Jun 8 2017

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment