Issue metadata
Sign in to add a comment
|
Heap-buffer-overflow in v8::internal::FixedArray::set |
||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5017709745274880 Fuzzer: mbarbella_js_mutation Job Type: windows_asan_d8_dbg Platform Id: windows Crash Type: Heap-buffer-overflow READ 2 Crash Address: 0x0beefdb6 Crash State: v8::internal::FixedArray::set v8::internal::wasm::CompileLazy v8::internal::__RT_impl_Runtime_WasmCompileLazy Sanitizer: address (ASAN) Recommended Security Severity: Medium Regressed: https://clusterfuzz.com/revisions?job=windows_asan_d8_dbg&range=49947:49948 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5017709745274880 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Dec 10 2017
Automatically assigning owner based on suspected regression changelist https://chromium.googlesource.com/v8/v8/+/f2e19a63873a700e6c0a1bca35e8301bd50db4e1 ([wasm] Add --wasm-jit-to-native under --future). If this is incorrect, please remove the owner and apply the Test-Predator-Wrong-CLs label.
,
Dec 11 2017
Lowering priority - this happens under the --future flag only
,
Dec 11 2017
,
Dec 11 2017
,
Dec 11 2017
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/e33a911ade76e07b38734f898d92fb84cbfb5d72 commit e33a911ade76e07b38734f898d92fb84cbfb5d72 Author: Mircea Trofin <mtrofin@chromium.org> Date: Mon Dec 11 17:17:25 2017 [wasm] Fix free object pointer access followed by allocation Straight forward bug - we took a naked pointer after which we perform an allocation. Bug: chromium:793671 Change-Id: I0cebd606c31edaca27abedc19bc878204eb9a18b Reviewed-on: https://chromium-review.googlesource.com/818634 Commit-Queue: Mircea Trofin <mtrofin@chromium.org> Reviewed-by: Clemens Hammacher <clemensh@chromium.org> Cr-Commit-Position: refs/heads/master@{#50003} [modify] https://crrev.com/e33a911ade76e07b38734f898d92fb84cbfb5d72/src/wasm/module-compiler.cc
,
Dec 12 2017
,
Dec 13 2017
,
Mar 20 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by ClusterFuzz
, Dec 10 2017Labels: Test-Predator-Auto-Components