Null-dereference in blink::SetSelectionState |
||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=6099314006032384 Fuzzer: miaubiz_css_fuzzer Job Type: windows_syzyasan_chrome Platform Id: windows Crash Type: Null-dereference Crash Address: 0x00000027 Crash State: blink::SetSelectionState blink::UpdateLayoutObjectState blink::LayoutSelection::Commit Memory Tool: SYZYASAN Regressed: https://clusterfuzz.com/revisions?job=windows_syzyasan_chrome&range=483471:483525 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6099314006032384 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jul 4 2017
Reproduced on Version 61.0.3147.0 (Official Build) canary (64-bit)
,
Jul 4 2017
Working on relative task which fill fix this.
,
Jul 11 2017
ClusterFuzz has detected this issue as fixed in range 485175:485183. Detailed report: https://clusterfuzz.com/testcase?key=6099314006032384 Fuzzer: miaubiz_css_fuzzer Job Type: windows_syzyasan_chrome Platform Id: windows Crash Type: Null-dereference Crash Address: 0x00000027 Crash State: blink::SetSelectionState blink::UpdateLayoutObjectState blink::LayoutSelection::Commit Memory Tool: SYZYASAN Regressed: https://clusterfuzz.com/revisions?job=windows_syzyasan_chrome&range=483471:483525 Fixed: https://clusterfuzz.com/revisions?job=windows_syzyasan_chrome&range=485175:485183 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6099314006032384 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jul 11 2017
ClusterFuzz testcase 6099314006032384 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
||||
►
Sign in to add a comment |
||||
Comment 1 by msrchandra@chromium.org
, Jul 3 2017Labels: M-61 Test-Predator-Wrong
Owner: yoichio@chromium.org
Status: Assigned (was: Untriaged)