New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 706345 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Apr 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Security



Sign in to add a comment

Heap-use-after-free in libgdk-3.so.0

Project Member Reported by ClusterFuzz, Mar 29 2017

Issue description

Project Member

Comment 1 by sheriffbot@chromium.org, Mar 29 2017

Labels: M-59
Project Member

Comment 2 by sheriffbot@chromium.org, Mar 29 2017

Labels: ReleaseBlock-Beta
This issue is a security regression. If you are not able to fix this quickly, please revert the change that introduced it.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 3 by sheriffbot@chromium.org, Mar 29 2017

Labels: Pri-1

Comment 4 by ta...@google.com, Mar 30 2017

Components: Internals
Owner: roc...@chromium.org
Status: Assigned (was: Untriaged)

Comment 5 by roc...@chromium.org, Mar 30 2017

Any context for why this is assigned to me?
blame clusterfuzz's blame :-)

The result is a list of CLs that change the crashed files. 

Author: rockot
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/c6026704ff452d402924ce2d88b0168baf227b1e
Time: Tue Mar 21 00:29:35 2017
File content_main_runner.cc is changed in this cl (and is part of stack frame #9, "content::RunNamedProcessTypeMain")
File content_main_runner.cc is changed in this cl (and is part of stack frame #9, "content::RunNamedProcessTypeMain")
Minimum distance from crash line to modified line: 33. (file: content_main_runner.cc, crashed on: 451, modified: 484).

If you're not the best person to look at this, mind re-assinging?

Comment 7 by roc...@chromium.org, Apr 10 2017

Cc: roc...@chromium.org
Owner: thomasanderson@chromium.org
I see. Unfortunately the CL in question changes a line of code that is in literally *every* stack trace, because it's the main entry point of our binary. It looks like a crash in GDK?

Unfortunately I have no idea to whom this should be reassigned. Guessing thomasanderson@ since the blame range also includes https://chromium.googlesource.com/chromium/src/+/0ff8b19608421be5fa5b53e90c097e4992723b90 and I assume GDK version is tied to GTK version.
Cc: infe...@chromium.org
+inferno 

The libgdk-3.so.0 in the stack traces are missing symbols.  Does clusterfuzz tsan not use instrumented libraries?

Gtk3 and Gdk3 were added to instrumented libraries only recently, so maybe the tsan libs need to be rebuilt? (which could fix this issue?)
Project Member

Comment 9 by sheriffbot@chromium.org, Apr 20 2017

Labels: -Security_Impact-Head Security_Impact-Beta
A friendly reminder that M59 Beta  launch is coming soon! Your bug is labelled as Release Block Beta. All fixes need to be merged into the release branch (3071) latest by tomorrow, 04/26 4:00 PM PT in order to make into the desktop Beta final build cut. Thank you!
inferno@ - mind looking at the question in #8 about missing symbols?
Project Member

Comment 12 by sheriffbot@chromium.org, Apr 26 2017

thomasanderson: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers?

If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one?

If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: -Security_Impact-Beta Security_Impact-Stable
awhalley@ should this still be considered as ReleaseBlock-Beta, or moved to ReleaseBlock-Stable?
Cc: pbomm...@chromium.org
Labels: -ReleaseBlock-Beta ReleaseBlock-Stable
Since it's moved to Security_Impact-Stable, moving this from RB-Beta to RB-Stable. 

Comment 17 by aarya@google.com, Apr 28 2017

Status: WontFix (was: Assigned)
Does not crash anymore.
Project Member

Comment 18 by sheriffbot@chromium.org, Aug 5 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment