Null-dereference READ in blink::LocalFrameView::UpdateGeometry |
||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=4854907818737664 Fuzzer: inferno_twister_c Job Type: linux_asan_content_shell_drt Platform Id: linux Crash Type: Null-dereference READ Crash Address: 0x000000000098 Crash State: blink::LocalFrameView::UpdateGeometry blink::RootScrollerController::UpdateIFrameGeometryAndLayoutSize blink::RootScrollerController::DidResizeFrameView Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=linux_asan_content_shell_drt&range=530923:530929 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4854907818737664 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Jan 24 2018
Automatically applying components based on crash stacktrace and information from OWNERS files. If this is incorrect, please apply the Test-Predator-Wrong-Components label.
,
Jan 26 2018
,
Jan 29 2018
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/1277149bdcf1ee445039a6f148e71fae487005fa commit 1277149bdcf1ee445039a6f148e71fae487005fa Author: David Bokan <bokan@chromium.org> Date: Mon Jan 29 13:51:57 2018 Fix nullptr crash in RootScrollerController The stacktrace in the bug revealed a path where we don't check that the LocalFrameView isn't null. No test since I couldn't reproduce the crash. Bug: 805420 Change-Id: Ief57e784e765efadb18b5c9c040e7b5a40ee904c Reviewed-on: https://chromium-review.googlesource.com/887826 Reviewed-by: Dave Tapuska <dtapuska@chromium.org> Commit-Queue: David Bokan <bokan@chromium.org> Cr-Commit-Position: refs/heads/master@{#532412} [modify] https://crrev.com/1277149bdcf1ee445039a6f148e71fae487005fa/third_party/WebKit/Source/core/page/scrolling/RootScrollerController.cpp
,
Feb 12 2018
ClusterFuzz testcase 4854907818737664 is flaky and no longer crashes, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
||||
►
Sign in to add a comment |
||||
Comment 1 by ClusterFuzz
, Jan 24 2018Owner: bokan@chromium.org
Status: Assigned (was: Untriaged)