New issue
Advanced search Search tips

Issue 820289 link

Starred by 2 users

Issue metadata

Status: Duplicate
Owner: ----
Closed: Mar 2018
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Crash in resource_coordinator::TabManager::PurgeBackgroundedTabsIfNeeded

Reported by chromium...@gmail.com, Mar 8 2018

Issue description

VERSION
Chrome Version: 67.0.3365.0 (Official Build) canary (64-bit)
Operating System: Mac and Windows 7

REPRODUCTION CASE
1. Load https://test.shhnjk.com/csp_open.php
2. Click on "go"
3. Wait >> crash!

Note: This looks like it can take several tries to repo.


crash/82ac8a001f7853c3.


rax=000000000c083540 rbx=000000000eac1120 rcx=000000000a7f6080
rdx=000007fef26f4520 rsi=000000000be892f8 rdi=000000000a7f6080
rip=000007feeff18940 rsp=000000000027eb10 rbp=000000000000000a
 r8=000000000027ea28  r9=0000000000000001 r10=0000000000000000
r11=0000000000000246 r12=000000000be89318 r13=00000000039c7f10
r14=000007fef291f7c8 r15=00000000039f83c0
iopl=0         nv up ei pl nz na pe nc
cs=0033  ss=0000  ds=0000  es=0000  fs=0053  gs=002b             efl=00010202
*** WARNING: Unable to verify checksum for chrome.dll
chrome_7feef8d0000!resource_coordinator::TabManager::PurgeBackgroundedTabsIfNeeded+0x44:
000007fe`eff18940 ff5050          call    qword ptr [rax+50h] ds:00000000`0c083590=241a326100000000
0:000> k
  *** Stack trace for last set context - .thread/.cxr resets it
Child-SP          RetAddr           Call Site
00000000`0027eb10 000007fe`efd34227 chrome_7feef8d0000!resource_coordinator::TabManager::PurgeBackgroundedTabsIfNeeded+0x44 [C:\b\c\b\win64_clang\src\chrome\browser\resource_coordinator\tab_manager.cc @ 487]
00000000`0027eb70 000007fe`ef8f664f chrome_7feef8d0000!base::Timer::RunScheduledTask+0xa7 [C:\b\c\b\win64_clang\src\base\timer\timer.cc @ 261]
00000000`0027ebc0 000007fe`ef8f613c chrome_7feef8d0000!base::debug::TaskAnnotator::RunTask+0xdf [C:\b\c\b\win64_clang\src\base\debug\task_annotator.cc @ 61]
00000000`0027ece0 000007fe`ef8f7041 chrome_7feef8d0000!base::MessageLoop::RunTask+0x23c [C:\b\c\b\win64_clang\src\base\message_loop\message_loop.cc @ 396]
00000000`0027ee40 000007fe`ef9feeb2 chrome_7feef8d0000!base::MessageLoop::DoDelayedWork+0x141 [C:\b\c\b\win64_clang\src\base\message_loop\message_loop.cc @ 491]
00000000`0027efb0 000007fe`ef941a28 chrome_7feef8d0000!base::MessagePumpForUI::DoRunLoop+0xc2 [C:\b\c\b\win64_clang\src\base\message_loop\message_pump_win.cc @ 177]
00000000`0027f060 000007fe`ef8f5165 chrome_7feef8d0000!base::MessagePumpWin::Run+0x68 [C:\b\c\b\win64_clang\src\base\message_loop\message_pump_win.cc @ 58]
00000000`0027f0c0 000007fe`efccfd1b chrome_7feef8d0000!base::RunLoop::Run+0x35 [C:\b\c\b\win64_clang\src\base\run_loop.cc @ 139]
00000000`0027f0f0 000007fe`efccfb0c chrome_7feef8d0000!ChromeBrowserMainParts::MainMessageLoopRun+0x9f [C:\b\c\b\win64_clang\src\chrome\browser\chrome_browser_main.cc @ 2178]
00000000`0027f1e0 000007fe`efccfab7 chrome_7feef8d0000!content::BrowserMainLoop::RunMainMessageLoopParts+0x48 [C:\b\c\b\win64_clang\src\content\browser\browser_main_loop.cc @ 1105]
00000000`0027f2a0 000007fe`ef8eb01a chrome_7feef8d0000!content::BrowserMainRunnerImpl::Run+0x11 [C:\b\c\b\win64_clang\src\content\browser\browser_main_runner.cc @ 161]
00000000`0027f2d0 000007fe`ef8eaeb7 chrome_7feef8d0000!content::BrowserMain+0xc6 [C:\b\c\b\win64_clang\src\content\browser\browser_main.cc @ 46]
00000000`0027f3b0 000007fe`ef8ead61 chrome_7feef8d0000!content::RunNamedProcessTypeMain+0x11a [C:\b\c\b\win64_clang\src\content\app\content_main_runner.cc @ 423]
00000000`0027f510 000007fe`ef8d7955 chrome_7feef8d0000!content::ContentMainRunnerImpl::Run+0x115 [C:\b\c\b\win64_clang\src\content\app\content_main_runner.cc @ 703]
00000000`0027f5b0 000007fe`ef8d7418 chrome_7feef8d0000!service_manager::Main+0x478 [C:\b\c\b\win64_clang\src\services\service_manager\embedder\main.cc @ 453]
00000000`0027f8e0 000007fe`ef8d38a5 chrome_7feef8d0000!content::ContentMain+0x41 [C:\b\c\b\win64_clang\src\content\app\content_main.cc @ 19]
*** WARNING: Unable to verify checksum for chrome.exe
00000000`0027f970 00000001`3fa3354c chrome_7feef8d0000!ChromeMain+0x123 [C:\b\c\b\win64_clang\src\chrome\app\chrome_main.cc @ 104]
00000000`0027fa40 00000001`3fa3169c chrome!MainDllLoader::Launch+0x26c [C:\b\c\b\win64_clang\src\chrome\app\main_dll_loader_win.cc @ 198]
00000000`0027fb30 00000001`3fb0c5c3 chrome!wWinMain+0x69c [C:\b\c\b\win64_clang\src\chrome\app\chrome_exe_main_win.cc @ 230]
*** WARNING: Unable to verify checksum for kernel32.dll
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for kernel32.dll - 
00000000`0027ff10 00000000`774ef56d chrome!__scrt_common_main_seh+0x117 [f:\dd\vctools\crt\vcstartup\src\startup\exe_common.inl @ 283]

 
Mergedinto: 818454
Status: Duplicate (was: Unconfirmed)
Thanks for the report. Our crash telemetry picked this one up, and a fix is being worked on.
Project Member

Comment 2 by sheriffbot@chromium.org, Jun 15 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment