Heap-use-after-free in test_runner::TestRunnerForSpecificView::Reset |
||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5457206125527040 Fuzzer: inferno_layout_test_unmodified Job Type: linux_asan_content_shell_drt Platform Id: linux Crash Type: Heap-use-after-free READ 8 Crash Address: 0x617000275280 Crash State: test_runner::TestRunnerForSpecificView::Reset test_runner::WebViewTestProxyBase::Reset test_runner::TestInterfaces::ResetAll Sanitizer: address (ASAN) Recommended Security Severity: High Regressed: https://clusterfuzz.com/revisions?job=linux_asan_content_shell_drt&range=432464:432588 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5457206125527040 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Jul 24 2017
,
Jul 24 2017
Can one of the content/shell/test_runner/OWNERS PTAL?
,
Jul 26 2017
,
Jul 27 2017
,
Aug 7 2017
dmazzoni: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Aug 11 2017
Issue 754671 has been merged into this issue.
,
Aug 11 2017
cc'ing Marty for a question because it is his fuzzer. (And Lukasz because he had a previous iteration of this bug assigned to him.) Is there any point in keeping security flags on this bug? It seems strange to have a crash in test_runner being labeled as Sev-High.
,
Aug 21 2017
dmazzoni: Uh oh! This issue still open and hasn't been updated in the last 28 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Aug 21 2017
FWIW, I've tried to and failed to repro via: $ .../clusterfuzz-tools/releases/clusterfuzz reproduce --current -j 500 -l 25 --iterations 20 5457206125527040 ... UnreproducibleError: The crash cannot be reproduced after trying 20 times. ... This isn't entirely unexpected though based on https://crbug.com/739147#c15
,
Sep 6 2017
,
Sep 18 2017
ClusterFuzz testcase 6455627328258048 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Sep 18 2017
,
Sep 20 2017
,
Sep 20 2017
This bug requires manual review: M62 has already been promoted to the beta branch, so this requires manual review Please contact the milestone owner if you have questions. Owners: amineer@(Android), cmasso@(iOS), bhthompson@(ChromeOS), abdulsyed@(Desktop) For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Sep 21 2017
This isn't actually fixed (redid the CF job). Re-opening...
,
Sep 22 2017
We commit ourselves to a 60 day deadline for fixing for high severity vulnerabilities, and have exceeded it here. If you're unable to look into this soon, could you please find another owner or remove yourself so that this gets back into the security triage queue? For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Sep 22 2017
Please mark security bugs as fixed as soon as the fix lands, and before requesting merges. This update is based on the merge- labels applied to this issue. Please reopen if this update was incorrect. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Sep 22 2017
Per comment 16, this bug is not fixed. Rejecting merge.
,
Oct 16 2017
Re-opening per #16
,
Nov 3 2017
Echoing #c8 -- if this is a test only bug, can we remove the security label? thanks.
,
Nov 5 2017
Removing the security flags is fine.
,
Dec 18 2017
|
||||||||||||||||||
►
Sign in to add a comment |
||||||||||||||||||
Comment 1 by sheriffbot@chromium.org
, Jul 24 2017