New issue
Advanced search Search tips

Issue 733163 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Jun 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 1
Type: Bug-Security



Sign in to add a comment

Heap-use-after-free in v8::internal::wasm::AsyncCompileJob::DecodeModule::Run

Project Member Reported by ClusterFuzz, Jun 14 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=6248448801374208

Fuzzer: inferno_js_fuzzer
Job Type: windows_asan_d8
Platform Id: windows

Crash Type: Heap-use-after-free READ 4
Crash Address: 0x0b601634
Crash State:
  v8::internal::wasm::AsyncCompileJob::DecodeModule::Run
  v8::platform::WorkerThread::Run
  v8::base::ThreadEntry
  
Sanitizer: address (ASAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=windows_asan_d8&range=470050:470100

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6248448801374208


Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: ahaas@chromium.org
Components: -Blink>JavaScript Blink>JavaScript>WebAssembly
Owner: clemensh@chromium.org
Status: Assigned (was: Untriaged)
This is a use in wasm::AsyncCompileJob on a worker thread after the Isolate has been torn down by the main thread. Regression range contains almost exclusively CLs related to WebAssembly, they might however just flush out the problem.
Project Member

Comment 2 by sheriffbot@chromium.org, Jun 14 2017

Labels: M-61
Project Member

Comment 3 by sheriffbot@chromium.org, Jun 14 2017

Labels: ReleaseBlock-Beta
This issue is a security regression. If you are not able to fix this quickly, please revert the change that introduced it.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 4 by sheriffbot@chromium.org, Jun 14 2017

Labels: Pri-1
Project Member

Comment 5 by ClusterFuzz, Jun 15 2017

ClusterFuzz has detected this issue as fixed in range 479356:479374.

Detailed report: https://clusterfuzz.com/testcase?key=6248448801374208

Fuzzer: inferno_js_fuzzer
Job Type: windows_asan_d8
Platform Id: windows

Crash Type: Heap-use-after-free READ 4
Crash Address: 0x0b601634
Crash State:
  v8::internal::wasm::AsyncCompileJob::DecodeModule::Run
  v8::platform::WorkerThread::Run
  v8::base::ThreadEntry
  
Sanitizer: address (ASAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=windows_asan_d8&range=470050:470100
Fixed: https://clusterfuzz.com/revisions?job=windows_asan_d8&range=479356:479374

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6248448801374208


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 6 by ClusterFuzz, Jun 15 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 6248448801374208 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 7 by sheriffbot@chromium.org, Jun 15 2017

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Was probably fixed by https://chromium-review.googlesource.com/532993.
Labels: -ReleaseBlock-Beta
Project Member

Comment 10 by sheriffbot@chromium.org, Sep 21 2017

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment