Issue metadata
Sign in to add a comment
|
Null-dereference READ in blink::Document::SetCompatibilityMode |
||||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5007771595177984 Fuzzer: attekett_dom_fuzzer Job Type: linux_cfi_chrome Platform Id: linux Crash Type: Null-dereference READ Crash Address: 0x0000000004bc Crash State: blink::Document::SetCompatibilityMode blink::HTMLTreeBuilder::DefaultForInitial blink::HTMLTreeBuilder::ProcessStartTag Sanitizer: cfi (CFI) Regressed: https://clusterfuzz.com/revisions?job=linux_cfi_chrome&range=536346:536353 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5007771595177984 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Apr 5 2018
I think this is a dupe, I asked clusterfuzz to try again to double check that the fix landed also works here.
,
Apr 10 2018
ClusterFuzz has detected this issue as fixed in range 547798:549174. Detailed report: https://clusterfuzz.com/testcase?key=5007771595177984 Fuzzer: attekett_dom_fuzzer Job Type: linux_cfi_chrome Platform Id: linux Crash Type: Null-dereference READ Crash Address: 0x0000000004bc Crash State: blink::Document::SetCompatibilityMode blink::HTMLTreeBuilder::DefaultForInitial blink::HTMLTreeBuilder::ProcessStartTag Sanitizer: cfi (CFI) Regressed: https://clusterfuzz.com/revisions?job=linux_cfi_chrome&range=536346:536353 Fixed: https://clusterfuzz.com/revisions?job=linux_cfi_chrome&range=547798:549174 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5007771595177984 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Apr 10 2018
ClusterFuzz testcase 5007771595177984 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Apr 10 2018
Clusterfuzz verified the fix, I'm marking as a dupe so we can track the fix. |
|||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||
Comment 1 by brajkumar@chromium.org
, Apr 5 2018Components: Blink>DOM Blink>HTML
Labels: -Type-Bug M-66 Test-Predator-Wrong Type-Bug-Regression
Owner: lfg@chromium.org
Status: Assigned (was: Untriaged)