Null-dereference READ in blink::TextControlInnerEditorElement::CustomStyleForLayoutObject |
|||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=6086207816859648 Fuzzer: ifratric-browserfuzzer-v3 Job Type: mac_asan_chrome Platform Id: mac Crash Type: Null-dereference READ Crash Address: 0x000000000010 Crash State: blink::TextControlInnerEditorElement::CustomStyleForLayoutObject blink::Element::StyleForLayoutObject blink::Element::RecalcOwnStyle Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=521257:521271 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6086207816859648 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Dec 18 2017
Automatically assigning owner based on suspected regression changelist https://chromium.googlesource.com/chromium/src/+/27fc5a3a1f3f1bdfa1e23602260c3d206b9ea79f (Remove AlwaysCreateUserAgentShadowRoot). If this is incorrect, please remove the owner and apply the Test-Predator-Wrong-CLs label.
,
Dec 20 2017
,
Dec 26 2017
Non-security nullptr deref, deprioritizing. Feel free to own this.
,
Dec 26 2017
Issue 794875 has been merged into this issue.
,
Jan 6 2018
ClusterFuzz has detected this issue as fixed in range 527241:527247. Detailed report: https://clusterfuzz.com/testcase?key=6086207816859648 Fuzzer: ifratric-browserfuzzer-v3 Job Type: mac_asan_chrome Platform Id: mac Crash Type: Null-dereference READ Crash Address: 0x000000000010 Crash State: blink::TextControlInnerEditorElement::CustomStyleForLayoutObject blink::Element::StyleForLayoutObject blink::Element::RecalcOwnStyle Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=521257:521271 Fixed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=527241:527247 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6086207816859648 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jan 6 2018
ClusterFuzz testcase 6086207816859648 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Jan 9 2018
This was same as issue 792903 , which reverts the CL pointed out by comment#2 here. Revert CL was: https://chromium-review.googlesource.com/c/chromium/src/+/851852 |
|||||
►
Sign in to add a comment |
|||||
Comment 1 by ClusterFuzz
, Dec 18 2017Labels: Test-Predator-Auto-Components