Issue metadata
Sign in to add a comment
|
Use-after-poison in std::__1::vector<v8::internal::MachineRepresentation, v8::internal::ZoneAllocato |
||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5169707530584064 Fuzzer: ochang_js_fuzzer Job Type: linux_asan_d8_v8_mipsel_dbg Platform Id: linux Crash Type: Use-after-poison WRITE 16 Crash Address: 0xea157940 Crash State: std::__1::vector<v8::internal::MachineRepresentation, v8::internal::ZoneAllocato v8::internal::wasm::WasmDecoder< v8::internal::wasm::BuildTFGraph Sanitizer: address (ASAN) Recommended Security Severity: High Regressed: https://clusterfuzz.com/revisions?job=linux_asan_d8_v8_mipsel_dbg&range=44496:44497 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5169707530584064 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Nov 20 2017
Automatically assigning owner based on suspected regression changelist https://chromium.googlesource.com/v8/v8/+/9a4bbad80aebcf1719657a6996a8487725e89a52 (MIPS[64]: One more fix for derived construct stub). If this is incorrect, please remove the owner and apply the Test-Predator-Wrong-CLs label.
,
Nov 20 2017
,
Nov 20 2017
,
Nov 21 2017
ClusterFuzz has detected this issue as fixed in range 49505:49506. Detailed report: https://clusterfuzz.com/testcase?key=5169707530584064 Fuzzer: ochang_js_fuzzer Job Type: linux_asan_d8_v8_mipsel_dbg Platform Id: linux Crash Type: Use-after-poison WRITE 16 Crash Address: 0xea157940 Crash State: std::__1::vector<v8::internal::MachineRepresentation, v8::internal::ZoneAllocato v8::internal::wasm::WasmDecoder< v8::internal::wasm::BuildTFGraph Sanitizer: address (ASAN) Recommended Security Severity: High Regressed: https://clusterfuzz.com/revisions?job=linux_asan_d8_v8_mipsel_dbg&range=44496:44497 Fixed: https://clusterfuzz.com/revisions?job=linux_asan_d8_v8_mipsel_dbg&range=49505:49506 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5169707530584064 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Nov 21 2017
ClusterFuzz testcase 5169707530584064 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Nov 21 2017
,
Feb 27 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Mar 27 2018
|
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by ClusterFuzz
, Nov 20 2017Labels: Test-Predator-Auto-Components