Issue metadata
Sign in to add a comment
|
Bad-cast to blink::GarbageCollectedMixin from invalid vptr in blink::ObjectAliveTrait<blink::ActiveScriptWrappableBase, true>::IsHeapObjectAlive |
||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=4769847234527232 Fuzzer: attekett_surku_fuzzer Job Type: linux_cfi_chrome Platform Id: linux Crash Type: Bad-cast Crash Address: 0x1e6f7fe19e90 Crash State: Bad-cast to blink::GarbageCollectedMixin from invalid vptr blink::ObjectAliveTrait<blink::ActiveScriptWrappableBase, true>::IsHeapObjectAlive bool WTF::HashTraits<blink::WeakMember<blink::ActiveScriptWrappableBase> >::TraceInCollection<blink::Visitor*> Sanitizer: cfi (CFI) Recommended Security Severity: High Regressed: https://clusterfuzz.com/revisions?job=linux_cfi_chrome&range=428749:428854 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4769847234527232 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Feb 10 2018
,
Feb 10 2018
ClusterFuzz has detected this issue as fixed in range 535905:535934. Detailed report: https://clusterfuzz.com/testcase?key=4769847234527232 Fuzzer: attekett_surku_fuzzer Job Type: linux_cfi_chrome Platform Id: linux Crash Type: Bad-cast Crash Address: 0x1e6f7fe19e90 Crash State: Bad-cast to blink::GarbageCollectedMixin from invalid vptr blink::ObjectAliveTrait<blink::ActiveScriptWrappableBase, true>::IsHeapObjectAlive bool WTF::HashTraits<blink::WeakMember<blink::ActiveScriptWrappableBase> >::TraceInCollection<blink::Visitor*> Sanitizer: cfi (CFI) Recommended Security Severity: High Regressed: https://clusterfuzz.com/revisions?job=linux_cfi_chrome&range=428749:428854 Fixed: https://clusterfuzz.com/revisions?job=linux_cfi_chrome&range=535905:535934 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4769847234527232 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
May 20 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by aarya@google.com
, Feb 10 2018Status: Duplicate (was: Untriaged)