New issue
Advanced search Search tips

Issue 714192 link

Starred by 1 user

Issue metadata

Status: Untriaged
Owner: ----
Cc:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: Bug



Sign in to add a comment

Null pointer dereference in ipc_mojo_bootstrap

Project Member Reported by csharrison@chromium.org, Apr 21 2017

Issue description

There was an issue where an endpoint client could be dereferenced after the endpoint is detached.

Fix is up here https://codereview.chromium.org/2834493008 but we should add a regression test in a followup.
 
Project Member

Comment 1 by bugdroid1@chromium.org, Apr 21 2017

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/1af8d6abdae50ae8b8df88c7796a9d042461b4d0

commit 1af8d6abdae50ae8b8df88c7796a9d042461b4d0
Author: csharrison <csharrison@chromium.org>
Date: Fri Apr 21 17:47:23 2017

Fix null pointer dereference in ipc_boostrap

This was being hit when a sync message is dequeued and handled, and the
receiver endpoint immediately destroys itself.

BUG=714192

Review-Url: https://codereview.chromium.org/2834493008
Cr-Commit-Position: refs/heads/master@{#466383}

[modify] https://crrev.com/1af8d6abdae50ae8b8df88c7796a9d042461b4d0/ipc/ipc_mojo_bootstrap.cc

Cc: -roc...@chromium.org rockot@google.com

Sign in to add a comment