New issue
Advanced search Search tips

Issue 771781 link

Starred by 1 user

Issue metadata

Status: Available
Owner: ----
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Android , Windows , Chrome , Mac , Fuchsia
Pri: 3
Type: Bug

Blocked on:
issue 772211



Sign in to add a comment

Traced stack-allocated object can be bound in WTF::Function

Project Member Reported by reillyg@chromium.org, Oct 4 2017

Issue description

This bug tracks work necessary to resolve the issue that a stack-allocated object that contains heap-allocated members that must be traced can be bound as an argument to a WTF::Function and thus remain untraced after the current stack frame has been cleaned up.

This leads to the possibility of a use-after-free as demonstrated in  issue 759457 .
 
Blockedon: 772211
Cc: haraken@chromium.org
Status: Available (was: Untriaged)

Sign in to add a comment