Null-dereference READ in blink::LayoutTable::UpdateCollapsedOuterBorders |
||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=4922304386826240 Fuzzer: j00ru_htmlcss_fuzz Job Type: windows_asan_chrome Platform Id: windows Crash Type: Null-dereference READ Crash Address: 0x000000a8 Crash State: blink::LayoutTable::UpdateCollapsedOuterBorders blink::LayoutTable::BorderLeft blink::LayoutBoxModelObject::BorderEnd Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=windows_asan_chrome&range=501180:501203 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4922304386826240 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Sep 13 2017
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/3343091dc68bb4903d5277cf5e6aa6c74fdc5069 commit 3343091dc68bb4903d5277cf5e6aa6c74fdc5069 Author: Xianzhu Wang <wangxianzhu@chromium.org> Date: Wed Sep 13 00:18:34 2017 Fix null pointer in LayoutTable::UpdateCollapsedOuterBorders(). Check for null BottomNonEmptySection even if TopNonEmptySection is not null because of crbug.com/764525 . Bug: 764284 Change-Id: I4d45cbd3432722a8958ba647767d97b782c10512 Reviewed-on: https://chromium-review.googlesource.com/664303 Reviewed-by: David Grogan <dgrogan@chromium.org> Commit-Queue: Xianzhu Wang <wangxianzhu@chromium.org> Cr-Commit-Position: refs/heads/master@{#501471} [modify] https://crrev.com/3343091dc68bb4903d5277cf5e6aa6c74fdc5069/third_party/WebKit/Source/core/layout/LayoutTable.cpp [modify] https://crrev.com/3343091dc68bb4903d5277cf5e6aa6c74fdc5069/third_party/WebKit/Source/core/layout/LayoutTableTest.cpp
,
Sep 13 2017
,
Sep 13 2017
ClusterFuzz has detected this issue as fixed in range 501470:501529. Detailed report: https://clusterfuzz.com/testcase?key=4922304386826240 Fuzzer: j00ru_htmlcss_fuzz Job Type: windows_asan_chrome Platform Id: windows Crash Type: Null-dereference READ Crash Address: 0x000000a8 Crash State: blink::LayoutTable::UpdateCollapsedOuterBorders blink::LayoutTable::BorderLeft blink::LayoutBoxModelObject::BorderEnd Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=windows_asan_chrome&range=501180:501203 Fixed: https://clusterfuzz.com/revisions?job=windows_asan_chrome&range=501470:501529 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4922304386826240 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Sep 13 2017
ClusterFuzz testcase 4922304386826240 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Sep 14 2017
This bug requires manual review: M62 has already been promoted to the beta branch, so this requires manual review Please contact the milestone owner if you have questions. Owners: amineer@(Android), cmasso@(iOS), bhthompson@(ChromeOS), abdulsyed@(Desktop) For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Sep 14 2017
Approving merge to M62. Branch:3202
,
Sep 14 2017
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/18b74f607c498f25cd708a95f394a510a9ffaffd commit 18b74f607c498f25cd708a95f394a510a9ffaffd Author: Xianzhu Wang <wangxianzhu@chromium.org> Date: Thu Sep 14 23:23:06 2017 Fix null pointer in LayoutTable::UpdateCollapsedOuterBorders(). Check for null BottomNonEmptySection even if TopNonEmptySection is not null because of crbug.com/764525 . TBR=wangxianzhu@chromium.org (cherry picked from commit 3343091dc68bb4903d5277cf5e6aa6c74fdc5069) Bug: 764284 Change-Id: I4d45cbd3432722a8958ba647767d97b782c10512 Reviewed-on: https://chromium-review.googlesource.com/664303 Reviewed-by: David Grogan <dgrogan@chromium.org> Commit-Queue: Xianzhu Wang <wangxianzhu@chromium.org> Cr-Original-Commit-Position: refs/heads/master@{#501471} Reviewed-on: https://chromium-review.googlesource.com/668157 Reviewed-by: Xianzhu Wang <wangxianzhu@chromium.org> Cr-Commit-Position: refs/branch-heads/3202@{#241} Cr-Branched-From: fa6a5d87adff761bc16afc5498c3f5944c1daa68-refs/heads/master@{#499098} [modify] https://crrev.com/18b74f607c498f25cd708a95f394a510a9ffaffd/third_party/WebKit/Source/core/layout/LayoutTable.cpp [modify] https://crrev.com/18b74f607c498f25cd708a95f394a510a9ffaffd/third_party/WebKit/Source/core/layout/LayoutTableTest.cpp |
||||||
►
Sign in to add a comment |
||||||
Comment 1 by kkaluri@chromium.org
, Sep 12 2017Components: Blink>Layout
Labels: Test-Predator-Wrong-CLs M-63
Owner: wangxianzhu@chromium.org
Status: Assigned (was: Untriaged)