Issue metadata
Sign in to add a comment
|
Container-overflow in views::Textfield::UpdateAfterChange |
||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5859030304817152 Fuzzer: cdiehl_dharma Job Type: linux_asan_chrome_chromeos Platform Id: linux Crash Type: Container-overflow READ 8 Crash Address: 0x6030003b32a0 Crash State: views::Textfield::UpdateAfterChange views::Textfield::ConfirmCompositionText ui::InputMethodChromeOS::OnWillChangeFocusedClient Sanitizer: address (ASAN) Recommended Security Severity: Medium Regressed: https://clusterfuzz.com/revisions?job=linux_asan_chrome_chromeos&range=533005:533006 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5859030304817152 Additional requirements: Requires Gestures Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Jan 31 2018
,
Jan 31 2018
This is a serious security regression. If you are not able to fix this quickly, please revert the change that introduced it. If this doesn't affect a release branch, or has not been properly classified for severity, please update the Security_Impact or Security_Severity labels, and remove the ReleaseBlock label. To disable this altogether, apply ReleaseBlock-NA. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jan 31 2018
,
Jan 31 2018
The change list identified does not directly have anything to do with the codepath that crashed. The open Issue 786534 looks quite similar with a different stack and regression range.
,
Feb 1 2018
,
Feb 1 2018
,
Feb 7 2018
,
Feb 14 2018
gayane: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Feb 14 2018
sergeyu@ I don't think the change is related. Could you also have a look?
,
Feb 14 2018
I don't have access to the clusterfuzz report. I can't access crbug.com/786534 either. From what I see here the problem doesn't seem to be related to the change that removed WebRTC experiment.
,
Feb 15 2018
I cannot access the bug you mentioned either, but I was able to see the clusterfuzz report with my chromium account
,
Feb 15 2018
Looks like an issue in ash window selector, sammiequon@, can you please take a look.
,
Feb 22 2018
crash repro steps 1. Open 1 window at least. 2. Enter overview (F5). 3. Press Ctrl+Alt+U. 4. Close all windows.
,
Mar 2 2018
sammiequon@: Are you actively working on this? It is a security regression, and a stable blocker.
,
Mar 2 2018
Re #15 https://chromium-review.googlesource.com/c/chromium/src/+/932547 just sent to CQ, that should fix this
,
Mar 2 2018
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/5e8ca713db9ff36b42f288d5af043a2703449c0a commit 5e8ca713db9ff36b42f288d5af043a2703449c0a Author: Sammie Quon <sammiequon@google.com> Date: Fri Mar 02 22:35:07 2018 overview: Fix crash when exit after using Ctrl Shift U. We should instead prevent Ctrl Shift U mode in overview somehow, but this will stop the crash in the meantime. Test: ash_unittests WindowSelectorTest.ExitInUnderlineMode Bug: 807517 Change-Id: Ie7d889937c110583454a281a318b682f62cd6084 Reviewed-on: https://chromium-review.googlesource.com/932547 Reviewed-by: Mitsuru Oshima <oshima@chromium.org> Commit-Queue: Sammie Quon <sammiequon@chromium.org> Cr-Commit-Position: refs/heads/master@{#540664} [modify] https://crrev.com/5e8ca713db9ff36b42f288d5af043a2703449c0a/ash/wm/overview/window_selector.cc [modify] https://crrev.com/5e8ca713db9ff36b42f288d5af043a2703449c0a/ash/wm/overview/window_selector_unittest.cc
,
Mar 7 2018
,
Mar 7 2018
,
Mar 16 2018
,
Mar 16 2018
This bug requires manual review: M66 has already been promoted to the beta branch, so this requires manual review Please contact the milestone owner if you have questions. Owners: cmasso@(Android), cmasso@(iOS), josafat@(ChromeOS), abdulsyed@(Desktop) For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Mar 19 2018
+josafat for merge approval
,
Mar 19 2018
Approved. Branch:3359
,
Mar 19 2018
Also found by internal fuzzers during the 48 hour window, I'm afraid.
,
Mar 19 2018
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/36da9721f559a62fc6a02224c168e5b31a639886 commit 36da9721f559a62fc6a02224c168e5b31a639886 Author: Sammie Quon <sammiequon@google.com> Date: Mon Mar 19 22:12:11 2018 [merge to 66] overview: Fix crash when exit after using Ctrl Shift U. We should instead prevent Ctrl Shift U mode in overview somehow, but this will stop the crash in the meantime. TBR=sammiequon@google.com (cherry picked from commit 5e8ca713db9ff36b42f288d5af043a2703449c0a) Test: ash_unittests WindowSelectorTest.ExitInUnderlineMode Bug: 807517 Change-Id: Ie7d889937c110583454a281a318b682f62cd6084 Reviewed-on: https://chromium-review.googlesource.com/932547 Reviewed-by: Mitsuru Oshima <oshima@chromium.org> Commit-Queue: Sammie Quon <sammiequon@chromium.org> Cr-Original-Commit-Position: refs/heads/master@{#540664} Reviewed-on: https://chromium-review.googlesource.com/969641 Reviewed-by: Sammie Quon <sammiequon@chromium.org> Cr-Commit-Position: refs/branch-heads/3359@{#328} Cr-Branched-From: 66afc5e5d10127546cc4b98b9117aff588b5e66b-refs/heads/master@{#540276} [modify] https://crrev.com/36da9721f559a62fc6a02224c168e5b31a639886/ash/wm/overview/window_selector.cc [modify] https://crrev.com/36da9721f559a62fc6a02224c168e5b31a639886/ash/wm/overview/window_selector_unittest.cc
,
Mar 28 2018
,
Jun 13 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by ClusterFuzz
, Jan 31 2018Owner: gayane@chromium.org
Status: Assigned (was: Untriaged)