Traced stack-allocated object can be bound in WTF::Function |
||
Issue descriptionThis bug tracks work necessary to resolve the issue that a stack-allocated object that contains heap-allocated members that must be traced can be bound as an argument to a WTF::Function and thus remain untraced after the current stack frame has been cleaned up. This leads to the possibility of a use-after-free as demonstrated in issue 759457 .
,
May 21 2018
|
||
►
Sign in to add a comment |
||
Comment 1 by haraken@chromium.org
, Oct 6 2017