Issue metadata
Sign in to add a comment
|
Bad-cast to sandbox::bpf_dsl::(anonymous namespace)::ReturnResultExprImpl from invalid vptr;blink::SVGString::calculateAnimatedValue;blink::SVGAnimateElement::calculateAnimatedValue |
||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5456145809670144 Fuzzer: ifratric-browserfuzzer-v3 Job Type: linux_cfi_chrome Platform Id: linux Crash Type: Bad-cast Crash Address: 0x7f0673099570 Crash State: Bad-cast to sandbox::bpf_dsl::(anonymous namespace)::ReturnResultExprImpl from invalid vptr blink::SVGString::calculateAnimatedValue blink::SVGAnimateElement::calculateAnimatedValue Sanitizer: cfi (CFI) Recommended Security Severity: High Regressed: https://clusterfuzz.com/revisions?job=linux_cfi_chrome&range=456721:456818 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv96qsL-_n7ToJchbVgDesiIvC_Isy1bRqUwG43qhQ5-jpMZJBvE0sPzFJRSJLvBq0UW7SXxNYVUFFI2LPC3D3Y6Dk37yNAIhK2nUNNwkF5MvOvIlk0M2EunXo0nZEagWR3o0N-cnxgLlWYyw_0q_0fap45GLWNNWdiZI6Bryj_k3Fmqr7DoycJIo47GM3saWBLPsJq6o4_gi4jsfeh8lO8ScS2XeIrlCsXz8aneX51WX-hL2JmKSAn8uLuP4ebciI3zhMshD6P3Ume5gK4GMBR82z1Slt0mq0J_75DDTbItmTjQoDVRKMzlcrhaOHSF04X_VqTXwoIZjZ8wlXN09ZC03bxiuy15-RE9djrkD7i77vdhRmxE?testcase_id=5456145809670144 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Mar 15 2017
ClusterFuzz testcase 5456145809670144 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Mar 15 2017
,
Jun 21 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jul 28
|
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by ClusterFuzz
, Mar 15 2017