New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 765557 link

Starred by 1 user

Issue metadata

Status: Duplicate
Owner: ----
Closed: Sep 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Mac
Pri: 3
Type: Bug



Sign in to add a comment

Null-dereference READ in blink::TextControlElement::SetInnerEditorValue

Project Member Reported by ClusterFuzz, Sep 15 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=4913128591851520

Fuzzer: inferno_layout_test_unmodified
Job Type: windows_asan_content_shell
Platform Id: windows

Crash Type: Null-dereference READ
Crash Address: 0x00000024
Crash State:
  blink::TextControlElement::SetInnerEditorValue
  blink::HTMLInputElement::SetInnerEditorValue
  blink::TextFieldInputType::UpdateView
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=windows_asan_content_shell&range=448729:448967

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4913128591851520

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Cc: msrchandra@chromium.org pnangunoori@chromium.org
Labels: Test-Predator-Wrong-CLs M-62
Owner: yoichio@chromium.org
Status: Assigned (was: Untriaged)
Predator and CL could not provide any possible suspects.
Using the code search for the file, “TextControlElement.cpp” assigning to concern owner from GIT revision log.

Suspecting Commit#
https://chromium.googlesource.com/chromium/src/+/d533dfc69bffca9ee92aeb533056ecd171ab8699

@yoichio-- Could you please look into this issue, kindly reassign if it has nothing to do with your changes.

Thank You.
Owner: pnangunoori@chromium.org
It is just refactoring.
Owner: yosin@chromium.org
Predator and CL could not provide any possible suspects.
Using the code search for the file, “TextControlElement.cpp” assigning to concern owner from GIT revision log.

Suspecting Commit#
https://chromium.googlesource.com/chromium/src/+/c0abcf3b4d587c919e50893bd8c9c0a53489e08e

@yosin -- Could you please look into this issue, kindly reassign if it has nothing to do with your changes.

Thank You.
Project Member

Comment 4 by ClusterFuzz, Sep 16 2017

Labels: OS-Mac OS-Linux

Comment 5 by yosin@chromium.org, Sep 19 2017

Components: Blink>Forms>Text
Labels: -Pri-1 Pri-3
Status: Untriaged (was: Assigned)
Route to Blink>Forms>Text

Comment 6 by yosin@chromium.org, Sep 19 2017

Owner: ----

Comment 7 by tkent@chromium.org, Sep 19 2017

Mergedinto: 580734
Status: Duplicate (was: Untriaged)
Using window.internals.shadowRoot -> WontFix.

Sign in to add a comment