New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 810505 link

Starred by 1 user

Issue metadata

Status: Verified
Owner: ----
Closed: Feb 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Null-dereference READ in blink::RuleSet::CompactPendingRules

Project Member Reported by ClusterFuzz, Feb 8 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5103975154843648

Fuzzer: j00ru_htmlcss_fuzz
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Null-dereference READ
Crash Address: 0x000000000008
Crash State:
  blink::RuleSet::CompactPendingRules
  blink::RuleSet::CompactRules
  blink::StyleEngine::ApplyRuleSetChanges
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=535339:535340

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5103975154843648

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Cc: brajkumar@chromium.org
Components: Blink>CSS
Labels: M-66 Test-Predator-Wrong CF-NeedsTriage
Unable to find actual suspect through code search and also from the provided CL under regression range, hence adding appropriate label and leaving it as untriaged for further updates.

Thanks!
restarted the task to redo regression

Comment 3 by e...@chromium.org, Feb 9 2018

Cc: futhark@chromium.org
Labels: -Pri-1 Pri-2
Status: Available (was: Untriaged)
Project Member

Comment 4 by ClusterFuzz, Feb 10 2018

ClusterFuzz has detected this issue as fixed in range 535922:535929.

Detailed report: https://clusterfuzz.com/testcase?key=5103975154843648

Fuzzer: j00ru_htmlcss_fuzz
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Null-dereference READ
Crash Address: 0x000000000008
Crash State:
  blink::RuleSet::CompactPendingRules
  blink::RuleSet::CompactRules
  blink::StyleEngine::ApplyRuleSetChanges
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=535301:535306
Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_chrome&range=535922:535929

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5103975154843648

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 5 by ClusterFuzz, Feb 10 2018

Labels: ClusterFuzz-Verified
Status: Verified (was: Available)
ClusterFuzz testcase 5103975154843648 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment