New issue
Advanced search Search tips

Issue 726073 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 725929
Owner: ----
Closed: May 2017
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 1
Type: Bug-Security



Sign in to add a comment

Heap-use-after-free in blink::NodeListsNodeData::AddCache<blink::HTMLCollection>

Project Member Reported by ClusterFuzz, May 24 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5391361603010560

Fuzzer: inferno_webbot
Job Type: windows_asan_chrome
Platform Id: windows

Crash Type: Heap-use-after-free READ 4
Crash Address: 0x27113968
Crash State:
  blink::NodeListsNodeData::AddCache<blink::HTMLCollection>
  blink::Document::forms
  blink::WebDocument::Forms
  
Sanitizer: address (ASAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=windows_asan_chrome&range=474215:474241

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5391361603010560


Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Project Member

Comment 1 by sheriffbot@chromium.org, May 25 2017

Labels: M-60
Project Member

Comment 2 by sheriffbot@chromium.org, May 25 2017

Labels: ReleaseBlock-Beta
This issue is a security regression. If you are not able to fix this quickly, please revert the change that introduced it.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 3 by sheriffbot@chromium.org, May 25 2017

Labels: Pri-1

Comment 4 by kenrb@chromium.org, May 25 2017

Mergedinto: 725929
Status: Duplicate (was: Untriaged)
Duping to 725929. The crash stack looks different but the suspect CL is still in the regression range, and it is one of many UaFs related to Collections popping up today.
Project Member

Comment 5 by ClusterFuzz, May 27 2017

ClusterFuzz has detected this issue as fixed in range 474847:474872.

Detailed report: https://clusterfuzz.com/testcase?key=5391361603010560

Fuzzer: inferno_webbot
Job Type: windows_asan_chrome
Platform Id: windows

Crash Type: Heap-use-after-free READ 4
Crash Address: 0x27113968
Crash State:
  blink::NodeListsNodeData::AddCache<blink::HTMLCollection>
  blink::Document::forms
  blink::WebDocument::Forms
  
Sanitizer: address (ASAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=windows_asan_chrome&range=474215:474241
Fixed: https://clusterfuzz.com/revisions?job=windows_asan_chrome&range=474847:474872

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5391361603010560


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 6 by sheriffbot@chromium.org, Sep 2 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment