New issue
Advanced search Search tips

Issue 738498 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Aug 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 1
Type: Bug



Sign in to add a comment

Null-dereference READ in blink::LocalFrame::Client

Project Member Reported by ClusterFuzz, Jun 30 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5028820251049984

Fuzzer: inferno_twister
Job Type: mac_asan_content_shell
Platform Id: mac

Crash Type: Null-dereference READ
Crash Address: 0x000000000048
Crash State:
  blink::LocalFrame::Client
  blink::Document::open
  blink::Document::open
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=mac_asan_content_shell&range=482161:482264

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5028820251049984


Additional requirements: Requires HTTP

Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Components: Blink
Components: -Blink Blink>DOM

Comment 3 by hayato@chromium.org, Jul 19 2017

Components: -Blink>DOM Blink>HTML
It doesn't look related to Blink > DOM.
As I chatted with tkent@, let me use Blink > HTML for triage.

Project Member

Comment 5 by ClusterFuzz, Aug 20 2017

Status: WontFix (was: Assigned)
ClusterFuzz testcase 5028820251049984 is flaky and no longer reproduces, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment