New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 764151 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Sep 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 1
Type: Bug



Sign in to add a comment

Null-dereference READ in blink::MemoryCache::Remove

Project Member Reported by ClusterFuzz, Sep 12 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5344883534725120

Fuzzer: inferno_twister
Job Type: mac_asan_content_shell
Platform Id: mac

Crash Type: Null-dereference READ
Crash Address: 0x000000000008
Crash State:
  blink::MemoryCache::Remove
  blink::ImageResource::DecodeError
  blink::ImageResource::UpdateImage
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=mac_asan_content_shell&range=500882:500909

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5344883534725120

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Cc: msrchandra@chromium.org kkaluri@chromium.org
Components: Blink>MemoryAllocator
Labels: M-63 Test-Predator-Wrong
Owner: hirosh...@chromium.org
Status: Assigned (was: Untriaged)
Predator and CL could not provide any possibl suspects.
Using Code Search for the file, "ImageResource.cpp" assigning to the concern owner who might be related or worked on similar file.

Suspected CL: https://chromium.googlesource.com/chromium/src/+/942393c6c300f35c3e74c94f95ddc730eff3025b

hiroshige@ -- Could you please look into the issue, kindly re-assign if this is not related to your changes.


Thank You.
Project Member

Comment 2 by ClusterFuzz, Sep 13 2017

ClusterFuzz has detected this issue as fixed in range 501402:501443.

Detailed report: https://clusterfuzz.com/testcase?key=5344883534725120

Fuzzer: inferno_twister
Job Type: mac_asan_content_shell
Platform Id: mac

Crash Type: Null-dereference READ
Crash Address: 0x000000000008
Crash State:
  blink::MemoryCache::Remove
  blink::ImageResource::DecodeError
  blink::ImageResource::UpdateImage
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=mac_asan_content_shell&range=500882:500909
Fixed: https://clusterfuzz.com/revisions?job=mac_asan_content_shell&range=501402:501443

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5344883534725120

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 3 by ClusterFuzz, Sep 13 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 5344883534725120 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment