Issue metadata
Sign in to add a comment
|
Heap-use-after-free in blink::LayoutBlock::dirtyForLayoutFromPercentageHeightDescendants |
||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=4579055522545664 Fuzzer: bj_broddelwerk Job Type: mac_asan_chrome Platform Id: mac Crash Type: Heap-use-after-free READ 8 Crash Address: 0x6130000951c0 Crash State: blink::LayoutBlock::dirtyForLayoutFromPercentageHeightDescendants blink::LayoutBlockFlow::layoutBlockChildren blink::LayoutBlockFlow::layoutChildren Sanitizer: address (ASAN) Recommended Security Severity: High Regressed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=456626:457730 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv95_RWY68ZSqqW4bralt_qwcfYodx-ggBZZAP246rzHyoSiFztMR66KQEIZjMMUSbQ95ikmBkWV33u6coD0tGoxJ7WKHFWWZkVqvkUeN8tX2amr63c3JagR3-8iYKnotJthS4l4a_RRRWHITKTMPHaVAZSmZNDqAhJfIIIh14u6zq8-_AHAr7uRaCaevUZ9hPD7ENXYZkCVZQAlAcBT9qyVQI9enfxBi-_rvBNtZSDVplxHM1VhsS6TKHrPEjfd-PTeXZ4_4j6Hyde-sK3T52JD6I_SIW2wFPTFlK1NLQuf6IRsFxXdgw4g0BVAPZ_otlV5pEfhjdt7c5m6aR4mo4WARLgr_prshlzfChCme_6ytCqylkzkGS5QH23bU2cVb_3lsKTm4-CPPUuDH9mzCFw6HJr5HBA?testcase_id=4579055522545664 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Apr 9 2017
ClusterFuzz testcase 4579055522545664 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Apr 9 2017
,
Jul 16 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jul 28
|
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by ClusterFuzz
, Apr 9 2017