Null-dereference READ in instance_type |
|||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=4661786682064896 Fuzzer: v8_builtins_generator Job Type: linux_asan_d8_v8_arm64_dbg Platform Id: linux Crash Type: Null-dereference READ Crash Address: 0x000000000000 Crash State: instance_type IsString IsString Sanitizer: address (ASAN) Regressed: V8: 45863:45864 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4661786682064896 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jun 13 2017
,
Jun 13 2017
,
Jun 13 2017
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/f52c8f9f28628a21dd2a231c68a39d0e39d90c46 commit f52c8f9f28628a21dd2a231c68a39d0e39d90c46 Author: Alexey Kozyatinskiy <kozyatinskiy@chromium.org> Date: Tue Jun 13 10:38:15 2017 [inspector] console.context should be ready for GC context_name pointer can be changed after GC triggered by AddProperty. R=ishell@chromium.org Bug: chromium:732717 Change-Id: Ie8e2497fa9f3bac80e0ad68153956e382731e284 Reviewed-on: https://chromium-review.googlesource.com/532994 Commit-Queue: Aleksey Kozyatinskiy <kozyatinskiy@chromium.org> Reviewed-by: Igor Sheludko <ishell@chromium.org> Cr-Commit-Position: refs/heads/master@{#45898} [modify] https://crrev.com/f52c8f9f28628a21dd2a231c68a39d0e39d90c46/src/builtins/builtins-console.cc [add] https://crrev.com/f52c8f9f28628a21dd2a231c68a39d0e39d90c46/test/inspector/runtime/regression-732717-expected.txt [add] https://crrev.com/f52c8f9f28628a21dd2a231c68a39d0e39d90c46/test/inspector/runtime/regression-732717.js
,
Jun 13 2017
,
Jun 14 2017
ClusterFuzz has detected this issue as fixed in range 45897:45898. Detailed report: https://clusterfuzz.com/testcase?key=4661786682064896 Fuzzer: v8_builtins_generator Job Type: linux_asan_d8_v8_arm64_dbg Platform Id: linux Crash Type: Null-dereference READ Crash Address: 0x000000000000 Crash State: instance_type IsString IsString Sanitizer: address (ASAN) Regressed: V8: 45863:45864 Fixed: V8: 45897:45898 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4661786682064896 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page. |
|||
►
Sign in to add a comment |
|||
Comment 1 by mstarzinger@chromium.org
, Jun 13 2017Owner: kozyatinskiy@chromium.org
Status: Assigned (was: Untriaged)