New issue
Advanced search Search tips

Issue 714418 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue v8:6263
Owner:
Closed: Apr 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 1
Type: Bug-Security



Sign in to add a comment

Use-after-poison in v8::internal::wasm::WasmFullDecoder::InitSsaEnv

Project Member Reported by ClusterFuzz, Apr 22 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=6465344391872512

Fuzzer: mbarbella_js_mutation
Job Type: windows_asan_d8
Platform Id: windows

Crash Type: Use-after-poison READ 4
Crash Address: 0x0dd75934
Crash State:
  v8::internal::wasm::WasmFullDecoder::InitSsaEnv
  v8::internal::wasm::WasmFullDecoder::Decode
  v8::internal::wasm::BuildTFGraph
  
Sanitizer: address (ASAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=windows_asan_d8&range=460544:464119

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6465344391872512


Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Project Member

Comment 1 by sheriffbot@chromium.org, Apr 23 2017

Labels: M-59
Project Member

Comment 2 by sheriffbot@chromium.org, Apr 23 2017

Labels: ReleaseBlock-Beta
This issue is a security regression. If you are not able to fix this quickly, please revert the change that introduced it.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 3 by sheriffbot@chromium.org, Apr 23 2017

Labels: Pri-1
Cc: clemensh@chromium.org
Components: -Blink>JavaScript Blink>JavaScript>WebAssembly
Owner: ahaas@chromium.org
Status: Assigned (was: Untriaged)
Crashes reliably, but at vastly different locations in the code. Regression range inconclusive. Seems to be tied to async compilation.
Project Member

Comment 5 by sheriffbot@chromium.org, Apr 24 2017

Labels: -Security_Impact-Head Security_Impact-Beta

Comment 6 by gov...@chromium.org, Apr 25 2017

A friendly reminder that M59 Beta  launch is coming soon! Your bug is labelled as Release Block Beta. All fixes need to be merged into the release branch (3071) latest by tomorrow, 04/26 4:00 PM PT in order to make into the desktop Beta final build cut. Thank you!

Comment 7 by ahaas@chromium.org, Apr 26 2017

Labels: -ReleaseBlock-Beta
Mergedinto: v8:6263
Status: Duplicate (was: Assigned)
This issue only happens on d8, not with chrome. I remove the ReleaseBlock-Beta label therefore.
Project Member

Comment 8 by ClusterFuzz, May 10 2017

ClusterFuzz has detected this issue as fixed in range 470142:470314.

Detailed report: https://clusterfuzz.com/testcase?key=6465344391872512

Fuzzer: mbarbella_js_mutation
Job Type: windows_asan_d8
Platform Id: windows

Crash Type: Use-after-poison READ 4
Crash Address: 0x0dd75934
Crash State:
  v8::internal::wasm::WasmFullDecoder::InitSsaEnv
  v8::internal::wasm::WasmFullDecoder::Decode
  v8::internal::wasm::BuildTFGraph
  
Sanitizer: address (ASAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=windows_asan_d8&range=460544:464119
Fixed: https://clusterfuzz.com/revisions?job=windows_asan_d8&range=470142:470314

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6465344391872512


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 9 by sheriffbot@chromium.org, Aug 2 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment