Issue metadata
Sign in to add a comment
|
CHECK failure: nofMappedParameters <= context_object->length() in objects-debug.cc |
||||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=6343749881036800 Fuzzer: inferno_js_fuzzer_c Job Type: linux_asan_d8 Platform Id: linux Crash Type: CHECK failure Crash Address: Crash State: nofMappedParameters <= context_object->length() in objects-debug.cc v8::internal::SloppyArgumentsElements::SloppyArgumentsElementsVerify v8::internal::JSArgumentsObject::JSArgumentsObjectVerify Sanitizer: address (ASAN) Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6343749881036800 Issue manually filed by: ishell See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. |
|||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||
Comment 1 by ishell@chromium.org
, May 27 2017Mergedinto: 726836
Owner: cbruni@chromium.org
Status: Duplicate (was: Untriaged)