New issue
Advanced search Search tips

Issue 747824 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 767023
Owner:
Closed: Dec 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Mac
Pri: 1
Type: Bug



Sign in to add a comment

Heap-use-after-free in test_runner::TestRunnerForSpecificView::Reset

Project Member Reported by ClusterFuzz, Jul 24 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5457206125527040

Fuzzer: inferno_layout_test_unmodified
Job Type: linux_asan_content_shell_drt
Platform Id: linux

Crash Type: Heap-use-after-free READ 8
Crash Address: 0x617000275280
Crash State:
  test_runner::TestRunnerForSpecificView::Reset
  test_runner::WebViewTestProxyBase::Reset
  test_runner::TestInterfaces::ResetAll
  
Sanitizer: address (ASAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_asan_content_shell_drt&range=432464:432588

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5457206125527040


Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by sheriffbot@chromium.org, Jul 24 2017

Labels: M-59
Project Member

Comment 2 by sheriffbot@chromium.org, Jul 24 2017

Labels: Pri-1
Components: Tests
Owner: dmazz...@chromium.org
Status: Assigned (was: Untriaged)
Can one of the content/shell/test_runner/OWNERS PTAL?
Project Member

Comment 4 by sheriffbot@chromium.org, Jul 26 2017

Labels: -M-59 M-60
Project Member

Comment 5 by ClusterFuzz, Jul 27 2017

Labels: OS-Mac
Project Member

Comment 6 by sheriffbot@chromium.org, Aug 7 2017

dmazzoni: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers?

If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one?

If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 7 by kenrb@chromium.org, Aug 11 2017

 Issue 754671  has been merged into this issue.

Comment 8 by kenrb@chromium.org, Aug 11 2017

Cc: lukasza@chromium.org mbarbe...@chromium.org
cc'ing Marty for a question because it is his fuzzer. (And Lukasz because he had a previous iteration of this bug assigned to him.)

Is there any point in keeping security flags on this bug? It seems strange to have a crash in test_runner being labeled as Sev-High.
Project Member

Comment 9 by sheriffbot@chromium.org, Aug 21 2017

dmazzoni: Uh oh! This issue still open and hasn't been updated in the last 28 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers?

If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one?

If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
FWIW, I've tried to and failed to repro via:
$ .../clusterfuzz-tools/releases/clusterfuzz reproduce --current -j 500 -l 25 --iterations 20 5457206125527040
...
UnreproducibleError: The crash cannot be reproduced after trying 20 times.
...

This isn't entirely unexpected though based on  https://crbug.com/739147#c15 

Project Member

Comment 11 by sheriffbot@chromium.org, Sep 6 2017

Labels: -M-60 M-61
Project Member

Comment 12 by ClusterFuzz, Sep 18 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 6455627328258048 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 13 by sheriffbot@chromium.org, Sep 18 2017

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Project Member

Comment 14 by sheriffbot@chromium.org, Sep 20 2017

Labels: Merge-Request-62
Project Member

Comment 15 by sheriffbot@chromium.org, Sep 20 2017

Labels: -Merge-Request-62 Merge-Review-62 Hotlist-Merge-Review
This bug requires manual review: M62 has already been promoted to the beta branch, so this requires manual review
Please contact the milestone owner if you have questions.
Owners: amineer@(Android), cmasso@(iOS), bhthompson@(ChromeOS), abdulsyed@(Desktop)

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Status: Assigned (was: Verified)
This isn't actually fixed (redid the CF job). Re-opening...
Project Member

Comment 17 by sheriffbot@chromium.org, Sep 22 2017

Labels: Deadline-Exceeded
We commit ourselves to a 60 day deadline for fixing for high severity vulnerabilities, and have exceeded it here. If you're unable to look into this soon, could you please find another owner or remove yourself so that this gets back into the security triage queue?

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 18 by sheriffbot@chromium.org, Sep 22 2017

Status: Fixed (was: Assigned)
Please mark security bugs as fixed as soon as the fix lands, and before requesting merges. This update is based on the merge- labels applied to this issue. Please reopen if this update was incorrect.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: -Merge-Review-62 Merge-Rejected-62
Per comment 16, this bug is not fixed. Rejecting merge. 
Labels: -M-61 ClusterFuzz-Wrong M-63
Status: Assigned (was: Fixed)
Re-opening per #16

Comment 21 by vakh@chromium.org, Nov 3 2017

Echoing #c8 -- if this is a test only bug, can we remove the security label? thanks.
Labels: -Type-Bug-Security -Restrict-View-SecurityNotify -Security_Impact-Stable -Security_Severity-High Type-Bug
Removing the security flags is fine.
Mergedinto: 767023
Status: Duplicate (was: Assigned)

Sign in to add a comment