Issue metadata
Sign in to add a comment
|
Heap-buffer-overflow in v8::internal::Simulator::DecodeType2 |
||||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=4887047853834240 Fuzzer: decoder_langfuzz Job Type: linux_asan_d8_v8_arm_dbg Platform Id: linux Crash Type: Heap-buffer-overflow WRITE 4 Crash Address: 0xd99ff7fc Crash State: v8::internal::Simulator::DecodeType2 v8::internal::Simulator::InstructionDecode v8::internal::Simulator::CallInternal Sanitizer: address (ASAN) Recommended Security Severity: High Regressed: V8: 40662:40663 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv967IEgHiNdrjgZB_Lbj4Z3BqfCe13XoInG_x85bG1mnrqsx576TjK6qLa0csSz6Eb7mf8N3dgTxi3Fm9XY1a6FdVofgu2GuXO3MfGXagOj6NCemexZXzMBdC_SnzvOwz9_XO0v6h4by1MaWGGoX_3ZDvkTDtTOtiYYh4gLXrubozNKl20GgSP-hEXs4KI2IN94DvzdXMGZhhiHFLKHfNgsSDM9r_4OOxQfTFLGwvjrQP0ovwyj2kDdGVIX6heyv8qPjKIX2fYOLfFSXD3v845hS3fo1_gHtKj-FrupsToJux5X9QtjFpPuNr4ATkuhnjKiTAFq_th8cSb22a5jy24VoftZn7zljbs1NRZ307Hj6mcgAXUw?testcase_id=4887047853834240 Issue manually filed by: rossberg See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Mar 16 2017
,
Aug 11 2017
ClusterFuzz has detected this issue as fixed in range 47276:47277. Detailed report: https://clusterfuzz.com/testcase?key=4887047853834240 Fuzzer: decoder_langfuzz Job Type: linux_asan_d8_v8_arm_dbg Platform Id: linux Crash Type: Heap-buffer-overflow WRITE 4 Crash Address: 0xeeeff7fc Crash State: v8::internal::Simulator::DecodeType2 v8::internal::Simulator::InstructionDecode v8::internal::Simulator::CallInternal Sanitizer: address (ASAN) Recommended Security Severity: High Regressed: V8: 40662:40663 Fixed: V8: 47276:47277 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4887047853834240 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Nov 18 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||
Comment 1 by rossberg@chromium.org
, Mar 16 2017Status: Duplicate (was: Untriaged)