Null-dereference READ in blink::VisualOffsetFromPaintOffsetRoot |
|||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=4582011493941248 Fuzzer: inferno_twister_c Job Type: linux_asan_chrome_media Platform Id: linux Crash Type: Null-dereference READ Crash Address: 0x0000000000a0 Crash State: blink::VisualOffsetFromPaintOffsetRoot blink::PaintPropertyTreeBuilder::UpdatePropertiesForSelf blink::PrePaintTreeWalk::Walk Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=linux_asan_chrome_media&range=511462:511489 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4582011493941248 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Oct 27 2017
Testcase 4582011493941248 is a top crash on ClusterFuzz for linux, mac and windows platforms. Please prioritize fixing this crash. Marking this crash as a Beta release blocker. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Oct 27 2017
,
Oct 27 2017
,
Oct 27 2017
,
Oct 27 2017
Based on the crash stack, this seems to be caused by https://chromium-review.googlesource.com/719765 (in the regression range) which seems not in M-63 (Clusterfuzz-Wrong for this). chrishtr@ can you take a look?
,
Oct 27 2017
,
Oct 28 2017
ClusterFuzz has detected this issue as fixed in range 512010:512075. Detailed report: https://clusterfuzz.com/testcase?key=4582011493941248 Fuzzer: inferno_twister_c Job Type: linux_asan_chrome_media Platform Id: linux Crash Type: Null-dereference READ Crash Address: 0x0000000000a0 Crash State: blink::VisualOffsetFromPaintOffsetRoot blink::PaintPropertyTreeBuilder::UpdatePropertiesForSelf blink::PrePaintTreeWalk::Walk Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=linux_asan_chrome_media&range=511462:511489 Fixed: https://clusterfuzz.com/revisions?job=linux_asan_chrome_media&range=512010:512075 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4582011493941248 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page. |
|||||||
►
Sign in to add a comment |
|||||||
Comment 1 by ClusterFuzz
, Oct 27 2017