New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 716516 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Last visit > 30 days ago
Closed: May 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Mac
Pri: 1
Type: Bug



Sign in to add a comment

Stack-overflow in blink::Element::AttachLayoutTree

Project Member Reported by ClusterFuzz, Apr 28 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=4939343014920192

Fuzzer: inferno_layout_test_unmodified
Job Type: mac_asan_content_shell
Platform Id: mac

Crash Type: Stack-overflow
Crash Address: 0x7fff51322ba8
Crash State:
  blink::Element::AttachLayoutTree
  blink::ContainerNode::AttachLayoutTree
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=mac_asan_content_shell&range=451960:451968

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4939343014920192


Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 

Comment 1 by shrike@chromium.org, Apr 28 2017

Components: Blink>DOM
Owner: dominicc@chromium.org
Status: WontFix (was: Untriaged)
This is interesting; it is nearly verbatim LayoutTests/svg/as-image/svg-nested.html but it crashes, maybe mac asan has bigger frames because of the frame canaries.

For now the decision is not to limit the depth of the DOM.
Project Member

Comment 3 by ClusterFuzz, May 2 2017

Labels: OS-Linux
Project Member

Comment 4 by ClusterFuzz, May 12 2017

ClusterFuzz has detected this issue as fixed in range 471041:471079.

Detailed report: https://clusterfuzz.com/testcase?key=4939343014920192

Fuzzer: inferno_layout_test_unmodified
Job Type: mac_asan_content_shell
Platform Id: mac

Crash Type: Stack-overflow
Crash Address: 0x7fff51322ba8
Crash State:
  blink::Element::AttachLayoutTree
  blink::ContainerNode::AttachLayoutTree
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=mac_asan_content_shell&range=451960:451968
Fixed: https://clusterfuzz.com/revisions?job=mac_asan_content_shell&range=471041:471079

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4939343014920192


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Sign in to add a comment