New issue
Advanced search Search tips

Issue 743142 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Sep 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 1
Type: Bug-Security



Sign in to add a comment

Crash in glvmRasterOpRead

Project Member Reported by ClusterFuzz, Jul 14 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=6667596102631424

Fuzzer: ifratric-browserfuzzer-v3
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: UNKNOWN READ
Crash Address: 0x000237b8d7f8
Crash State:
  glvmRasterOpRead
  glvmInterpretFPTransformFour
  gldLLVMFPTransform2x2
  
Sanitizer: address (ASAN)

Recommended Security Severity: Medium

Regressed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=418815:418836

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6667596102631424


Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 

Comment 1 by raymes@chromium.org, Jul 14 2017

Cc: danakj@chromium.org
Components: Internals>GPU>Internals
Owner: tobiasjs@chromium.org
Status: Assigned (was: Untriaged)
tobiasjs: could you please help triage? It looks like there was a change to gles2_cmd_decoder.cc in the regression range in https://codereview.chromium.org/2242453002
Project Member

Comment 2 by sheriffbot@chromium.org, Jul 15 2017

Labels: M-61
Project Member

Comment 3 by sheriffbot@chromium.org, Jul 15 2017

Labels: ReleaseBlock-Stable
This is a serious security regression. If you are not able to fix this quickly, please revert the change that introduced it.

If this doesn't affect a release branch, or has not been properly classified for severity, please update the Security_Impact or Security_Severity labels, and remove the ReleaseBlock label. To disable this altogether, apply ReleaseBlock-NA.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 4 by sheriffbot@chromium.org, Jul 15 2017

Labels: Pri-1

Comment 5 by danakj@chromium.org, Jul 18 2017

Cc: -danakj@chromium.org
Project Member

Comment 6 by sheriffbot@chromium.org, Jul 26 2017

Labels: -Security_Impact-Head Security_Impact-Beta

Comment 7 by gov...@chromium.org, Jul 26 2017

URGENT - PTAL.
Your bug is labelled as Stable ReleaseBlock, pls make sure to land the fix and get it merged into the M61 branch #3163 ASAP to have enough baking time in Beta before Stable promotion. Thank you!

Know that this issue shouldn't block the release?  Remove the ReleaseBlock-Stable label.

Labels: -Security_Impact-Beta -ReleaseBlock-Stable Security_Impact-Stable
I really don't think this should be assigned to me (but I don't know who to reassign it to). As I pointed out, the repro case doesn't contain anything that would trigger the code in my CL (there's no YUV conversion, to the best of my knowledge).

I also haven't been able to reproduce this on a Mac, which suggests a driver issue, and doesn't bode well for resolving the issue.
Cc: boliu@chromium.org
Cc: -boliu@chromium.org
Owner: ccameron@chromium.org
Hi Chris,

Sorry to punt this to you. Could you please take a look?
Project Member

Comment 12 by sheriffbot@chromium.org, Jul 29 2017

ccameron: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers?

If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one?

If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 13 by sheriffbot@chromium.org, Aug 12 2017

ccameron: Uh oh! This issue still open and hasn't been updated in the last 28 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers?

If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one?

If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 14 by ClusterFuzz, Sep 5 2017

Status: WontFix (was: Assigned)
ClusterFuzz testcase 6667596102631424 is flaky and no longer crashes, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 15 by sheriffbot@chromium.org, Dec 13 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment