New issue
Advanced search Search tips

Issue 758935 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 755381
Owner:
Closed: Aug 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Security



Sign in to add a comment

Heap-use-after-free in base::internal::Invoker<base::internal::BindState<long

Project Member Reported by ClusterFuzz, Aug 25 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5926265529040896

Fuzzer: inferno_flicker
Job Type: linux_asan_chrome_media
Platform Id: linux

Crash Type: Heap-use-after-free READ 8
Crash Address: 0x6110000bf440
Crash State:
  base::internal::Invoker<base::internal::BindState<long
  void base::internal::ReturnAsParamAdapter<long>
  base::internal::Invoker<base::internal::BindState<void
  
Sanitizer: address (ASAN)

Recommended Security Severity: High

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5926265529040896

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.

Note: This crash might not be reproducible with the provided testcase. That said, for the past 14 days we've been seeing this crash frequently. If you are unable to reproduce this, please try a speculative fix based on the crash stacktrace in the report. The fix can be verified by looking at the crash statistics in the report, a day after the fix is deployed. If the fix resolved the issue, please close the bug by marking as Fixed.
 
Project Member

Comment 1 by sheriffbot@chromium.org, Aug 25 2017

Labels: Pri-1

Comment 2 by ta...@google.com, Aug 25 2017

Cc: ajha@chromium.org
Components: Internals>Core
Owner: tzik@chromium.org
This could be related to 758283

Comment 3 by ta...@google.com, Aug 25 2017

Labels: Security_Impact-Head
Status: Assigned (was: Untriaged)
Project Member

Comment 4 by sheriffbot@chromium.org, Aug 26 2017

Labels: M-62

Comment 5 by tzik@chromium.org, Aug 26 2017

Labels: QA-Triage-Wrong
Mergedinto: 755381
Status: Duplicate (was: Assigned)
Project Member

Comment 6 by sheriffbot@chromium.org, Dec 3 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment