Null-dereference READ in blink::LayoutBlock::AddChildBeforeDescendant |
||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=4974000680992768 Fuzzer: marty_html_twiddler Job Type: windows_asan_content_shell Platform Id: windows Crash Type: Null-dereference READ Crash Address: 0x00000014 Crash State: blink::LayoutBlock::AddChildBeforeDescendant blink::LayoutBlockFlow::AddChild blink::LayoutBlockFlow::AddChild Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=windows_asan_content_shell&range=497433:497463 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4974000680992768 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Aug 26 2017
,
Aug 28 2017
,
Aug 29 2017
Predator and CL could not provide any possible suspects. Using Code Search for the file, "LayoutBlock.cpp" assigning to the concern owner. Suspecting Commit# https://chromium.googlesource.com/chromium/src/+/3a60b020bf35bc4ba48bf85e71acffd76de43360 @yoichio -- Could you please look into the issue, kindly re-assign if this is not related to your changes. Thank You.
,
Aug 29 2017
I'm not in the regressed range.
,
Aug 29 2017
ClusterFuzz has detected this issue as fixed in range 497777:497807. Detailed report: https://clusterfuzz.com/testcase?key=4974000680992768 Fuzzer: marty_html_twiddler Job Type: windows_asan_content_shell Platform Id: windows Crash Type: Null-dereference READ Crash Address: 0x00000014 Crash State: blink::LayoutBlock::AddChildBeforeDescendant blink::LayoutBlockFlow::AddChild blink::LayoutBlockFlow::AddChild Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=windows_asan_content_shell&range=497433:497463 Fixed: https://clusterfuzz.com/revisions?job=windows_asan_content_shell&range=497777:497807 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4974000680992768 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Aug 29 2017
ClusterFuzz testcase 4974000680992768 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
||||||
►
Sign in to add a comment |
||||||
Comment 1 by ClusterFuzz
, Aug 26 2017