Heap-use-after-free in test_runner::WebWidgetTestClient::AnimateNow |
|||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5782541130006528 Fuzzer: inferno_twister Job Type: mac_asan_content_shell Platform Id: mac Crash Type: Heap-use-after-free READ 8 Crash Address: 0x616000273680 Crash State: test_runner::WebWidgetTestClient::AnimateNow base::debug::TaskAnnotator::RunTask blink::scheduler::TaskQueueManager::ProcessTaskFromWorkQueue Sanitizer: address (ASAN) Recommended Security Severity: High Regressed: https://clusterfuzz.com/revisions?job=mac_asan_content_shell&range=502407:502440 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5782541130006528 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Dec 25 2017
Automatically assigning owner based on suspected regression changelist https://chromium.googlesource.com/chromium/src/+/0241e02bedc445db6bce2e909d386ed9c1386d6b (Remove tracked_objects.). If this is incorrect, please remove the owner and apply the Test-Predator-Wrong-CLs label.
,
Dec 25 2017
,
Dec 25 2017
,
Jan 8 2018
brettw: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jan 18 2018
brettw, have you had a chance to look at this? Also cc'ing reviewers from the suspected regression CL. It looks like the UAF is in WebWidgetTestClient, in which case I'm not sure this is really a security bug?
,
Jan 22 2018
brettw: Uh oh! This issue still open and hasn't been updated in the last 28 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jan 22 2018
,
Jan 25 2018
,
Jan 26 2018
,
Jan 31 2018
ClusterFuzz has detected this issue as fixed in range 532897:532997. Detailed report: https://clusterfuzz.com/testcase?key=5782541130006528 Fuzzer: inferno_twister Job Type: mac_asan_content_shell Platform Id: mac Crash Type: Heap-use-after-free READ 8 Crash Address: 0x616000273680 Crash State: test_runner::WebWidgetTestClient::AnimateNow base::debug::TaskAnnotator::RunTask blink::scheduler::TaskQueueManager::ProcessTaskFromWorkQueue Sanitizer: address (ASAN) Recommended Security Severity: High Regressed: https://clusterfuzz.com/revisions?job=mac_asan_content_shell&range=502407:502440 Fixed: https://clusterfuzz.com/revisions?job=mac_asan_content_shell&range=532897:532997 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5782541130006528 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jan 31 2018
ClusterFuzz testcase 5782541130006528 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Feb 8 2018
,
Feb 8 2018
,
Feb 9 2018
This bug requires manual review: M65 has already been promoted to the beta branch, so this requires manual review Please contact the milestone owner if you have questions. Owners: cmasso@(Android), cmasso@(iOS), bhthompson@(ChromeOS), govind@(Desktop) For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Feb 9 2018
[Bulk Edit] +awhalley@ (Security TPM) for M65 merge review
,
Feb 12 2018
,
Feb 12 2018
,
Apr 17 2018
,
May 9 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||
Comment 1 by ClusterFuzz
, Dec 25 2017Labels: Test-Predator-Auto-Components