Issue metadata
Sign in to add a comment
|
Heap-use-after-free in libgdk-3.so.0 |
||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5017566599970816 Fuzzer: inferno_twister_custom_bundle Job Type: linux_tsan_chrome_mp Platform Id: linux Crash Type: Heap-use-after-free READ 1 Crash Address: 0x7b0800141a38 Crash State: libgdk-3.so.0 base::MessageLoop::RunHandler base::RunLoop::Run Sanitizer: thread (TSAN) Recommended Security Severity: High Regressed: https://clusterfuzz.com/revisions?job=linux_tsan_chrome_mp&range=458243:458264 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv97eUdqmBBmiTrvNigu8b4kgWB5gDagyksoh74Fs-RDTTP5KphhcYoQLrch5yhZ3Nl2y_XkF4mElf7bAsPya3hw1_IdCUbPBUf5TBRYS_MUrpJtt6j1y7CR4pfFtX2YJgDWI19eRvSCUZn6O-CWF60-LsIgifN8SmHiWOSoUJFQvX2D-WKgMgqgH9JxSYTsQeYzenUsl11fZsywCUwKlvms15CSXJ8iaJU2rbNjJ1acpcaxVJJyQ2t22nmSZAHJHj_yIKH0jdB4kKrOj38Fv1xNlCe00Cx31AAzSOiAh97Pf4hwVWOfEke17qOSLiFqbwjAFm73rYVnEdKxgy1VV6euGmYl1-3WnPVjgXWmvIiEs7MsoYCAjMSnufPezOYaF9av_vp19rO2tacnXkcEysKBRFa8lHQ?testcase_id=5017566599970816 Additional requirements: Requires Gestures Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Mar 29 2017
This issue is a security regression. If you are not able to fix this quickly, please revert the change that introduced it. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Mar 29 2017
,
Mar 30 2017
,
Mar 30 2017
Any context for why this is assigned to me?
,
Apr 7 2017
blame clusterfuzz's blame :-) The result is a list of CLs that change the crashed files. Author: rockot Project: chromium Changelist: https://chromium.googlesource.com/chromium/src/+/c6026704ff452d402924ce2d88b0168baf227b1e Time: Tue Mar 21 00:29:35 2017 File content_main_runner.cc is changed in this cl (and is part of stack frame #9, "content::RunNamedProcessTypeMain") File content_main_runner.cc is changed in this cl (and is part of stack frame #9, "content::RunNamedProcessTypeMain") Minimum distance from crash line to modified line: 33. (file: content_main_runner.cc, crashed on: 451, modified: 484). If you're not the best person to look at this, mind re-assinging?
,
Apr 10 2017
I see. Unfortunately the CL in question changes a line of code that is in literally *every* stack trace, because it's the main entry point of our binary. It looks like a crash in GDK? Unfortunately I have no idea to whom this should be reassigned. Guessing thomasanderson@ since the blame range also includes https://chromium.googlesource.com/chromium/src/+/0ff8b19608421be5fa5b53e90c097e4992723b90 and I assume GDK version is tied to GTK version.
,
Apr 11 2017
+inferno The libgdk-3.so.0 in the stack traces are missing symbols. Does clusterfuzz tsan not use instrumented libraries? Gtk3 and Gdk3 were added to instrumented libraries only recently, so maybe the tsan libs need to be rebuilt? (which could fix this issue?)
,
Apr 20 2017
,
Apr 25 2017
A friendly reminder that M59 Beta launch is coming soon! Your bug is labelled as Release Block Beta. All fixes need to be merged into the release branch (3071) latest by tomorrow, 04/26 4:00 PM PT in order to make into the desktop Beta final build cut. Thank you!
,
Apr 25 2017
inferno@ - mind looking at the question in #8 about missing symbols?
,
Apr 26 2017
thomasanderson: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Apr 26 2017
,
Apr 26 2017
awhalley@ should this still be considered as ReleaseBlock-Beta, or moved to ReleaseBlock-Stable?
,
Apr 26 2017
,
Apr 26 2017
Since it's moved to Security_Impact-Stable, moving this from RB-Beta to RB-Stable.
,
Apr 28 2017
Does not crash anymore.
,
Aug 5 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by sheriffbot@chromium.org
, Mar 29 2017