Issue metadata
Sign in to add a comment
|
Crash in v8::internal::Invoke |
||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=6034059942952960 Fuzzer: ochang_js_fuzzer Job Type: linux_asan_d8_dbg Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x7fd55f102634 Crash State: v8::internal::Invoke v8::internal::CallInternal v8::Script::Run Sanitizer: address (ASAN) Recommended Security Severity: Medium Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6034059942952960 Issue manually filed by: ishell See https://github.com/google/clusterfuzz-tools for more information.
,
Nov 2 2017
Regression range points to b590679496e829fd2f88ba4494072f0196c979de, still reproduces with tip-of-tree as of today, hence I believe this is _not_ a pure dupe of issue 778574 .
,
Nov 10 2017
danno: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Nov 10 2017
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/d5885ca2b9b65769dfad9d55c21eb52b99f0071f commit d5885ca2b9b65769dfad9d55c21eb52b99f0071f Author: Daniel Clifford <danno@chromium.org> Date: Fri Nov 10 15:23:28 2017 Fix splice bug in handling of negative arguments length Bug: chromium:778668 Change-Id: Ie75f2ecb9e6134b6eb57c7d7fb6ea33cbb2fc2bf Reviewed-on: https://chromium-review.googlesource.com/753324 Commit-Queue: Daniel Clifford <danno@chromium.org> Reviewed-by: Igor Sheludko <ishell@chromium.org> Cr-Commit-Position: refs/heads/master@{#49301} [modify] https://crrev.com/d5885ca2b9b65769dfad9d55c21eb52b99f0071f/src/builtins/builtins-array-gen.cc [add] https://crrev.com/d5885ca2b9b65769dfad9d55c21eb52b99f0071f/test/mjsunit/regress/regress-778668.js
,
Nov 10 2017
,
Nov 11 2017
This is a serious security regression. If you are not able to fix this quickly, please revert the change that introduced it. If this doesn't affect a release branch, or has not been properly classified for severity, please update the Security_Impact or Security_Severity labels, and remove the ReleaseBlock label. To disable this altogether, apply ReleaseBlock-NA. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Nov 15 2017
Issue 779803 has been merged into this issue.
,
Nov 16 2017
,
Nov 16 2017
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/4002bf96e3ae9f3bb7c18009d34faa7980a61f85 commit 4002bf96e3ae9f3bb7c18009d34faa7980a61f85 Author: Daniel Clifford <danno@chromium.org> Date: Thu Nov 16 12:17:58 2017 Fix hole escape in dictionary mode Array.prototype.slice() Bug: chromium:778668 Change-Id: I0d2cc2166aab93bb7cb5dcc6c72cdb0b335a655f Reviewed-on: https://chromium-review.googlesource.com/774263 Commit-Queue: Daniel Clifford <danno@chromium.org> Reviewed-by: Igor Sheludko <ishell@chromium.org> Cr-Commit-Position: refs/heads/master@{#49410} [modify] https://crrev.com/4002bf96e3ae9f3bb7c18009d34faa7980a61f85/src/elements.cc [modify] https://crrev.com/4002bf96e3ae9f3bb7c18009d34faa7980a61f85/src/objects.cc [add] https://crrev.com/4002bf96e3ae9f3bb7c18009d34faa7980a61f85/test/mjsunit/regress/regress-784863.js
,
Nov 16 2017
,
Feb 22 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Mar 27 2018
,
Mar 31 2018
|
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by sheriffbot@chromium.org
, Oct 27 2017