New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 834953 link

Starred by 2 users

Issue metadata

Status: Verified
Owner: ----
Closed: Jul 19
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 3
Type: Bug



Sign in to add a comment

Null-dereference READ in blink::EditingIgnoresContent

Project Member Reported by ClusterFuzz, Apr 19 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5931914784145408

Fuzzer: bj_broddelwerk
Job Type: windows_asan_chrome_no_sandbox
Platform Id: windows

Crash Type: Null-dereference READ
Crash Address: 0x000000000000
Crash State:
  blink::EditingIgnoresContent
  blink::PositionTemplate<class blink::EditingAlgorithm<class blink::FlatTreeTrave
  blink::ApplyBlockElementCommand::RangeForParagraphSplittingTextNodesIfNeeded
  
Sanitizer: address (ASAN)

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5931914784145408

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Cc: brajkumar@chromium.org
Components: Blink>Editing
Labels: M-66 Test-Predator-Wrong CF-NeedsTriage
Unable to find actual suspect through code search and also observing no CL under regression range, hence adding appropriate label and requesting someone from blink team to look in to this issue.

Thanks!

Comment 2 by yosin@chromium.org, May 28 2018

Status: Available (was: Untriaged)

Comment 3 by yosin@chromium.org, May 29 2018

Labels: Pri-3
Lower to Pri-3 since it is caused by unusual HTML.
Project Member

Comment 4 by ClusterFuzz, Jul 19

ClusterFuzz has detected this issue as fixed in range 575974:575975.

Detailed report: https://clusterfuzz.com/testcase?key=5931914784145408

Fuzzer: bj_broddelwerk
Job Type: windows_asan_chrome_no_sandbox
Platform Id: windows

Crash Type: Null-dereference READ
Crash Address: 0x000000000000
Crash State:
  blink::EditingIgnoresContent
  blink::PositionTemplate<class blink::EditingAlgorithm<class blink::FlatTreeTrave
  blink::ApplyBlockElementCommand::RangeForParagraphSplittingTextNodesIfNeeded
  
Sanitizer: address (ASAN)

Fixed: https://clusterfuzz.com/revisions?job=windows_asan_chrome_no_sandbox&range=575974:575975

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5931914784145408

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 5 by ClusterFuzz, Jul 19

Labels: ClusterFuzz-Verified
Status: Verified (was: Available)
ClusterFuzz testcase 5931914784145408 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment