New issue
Advanced search Search tips

Issue 725340 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Jun 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug-Security



Sign in to add a comment

Use-of-uninitialized-value in gfx::internal::TextRunHarfBuzz::GetClusterAt

Project Member Reported by ClusterFuzz, May 23 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=4659846615138304

Fuzzer: svg_xml_tokenfuzz
Job Type: linux_msan_chrome
Platform Id: linux

Crash Type: Use-of-uninitialized-value
Crash Address: 
Crash State:
  gfx::internal::TextRunHarfBuzz::GetClusterAt
  gfx::RenderTextHarfBuzz::DrawVisualText
  gfx::RenderText::Draw
  
Sanitizer: memory (MSAN)

Recommended Security Severity: Low

Regressed: https://clusterfuzz.com/revisions?job=linux_msan_chrome&range=465390:465399

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4659846615138304


Additional requirements: Requires Gestures

Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Project Member

Comment 1 by sheriffbot@chromium.org, May 23 2017

Labels: Pri-2

Comment 2 by kenrb@chromium.org, May 24 2017

Components: UI>Input>Text
Owner: karandeepb@chromium.org
Status: Assigned (was: Untriaged)
karandeepb@: Can you please take a look at this security bug? There is a narrow regression range but it doesn't contain any plausible candidates to have caused the regression. It looks like you are familiar with the code here, so are you able to investigate and/or assign to a better owner?
Cc: msw@chromium.org
Will take me some time to reproduce and investigate this. Let me know if this is high priority. Also, cc'ing msw@ in case he wants to take a look.
Project Member

Comment 4 by ClusterFuzz, Jun 23 2017

Status: WontFix (was: Assigned)
ClusterFuzz testcase 4659846615138304 is flaky and no longer reproduces, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 5 by sheriffbot@chromium.org, Sep 30 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment