New issue
Advanced search Search tips

Issue 838521 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: May 2018
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Integer-overflow in blink::LayoutTableSection::CalcRowLogicalHeight

Project Member Reported by ClusterFuzz, May 1 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5852386921545728

Fuzzer: inferno_twister
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  blink::LayoutTableSection::CalcRowLogicalHeight
  blink::LayoutTable::LayoutSection
  blink::LayoutTable::UpdateLayout
  
Sanitizer: undefined (UBSAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=523880:523906

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5852386921545728

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, May 1 2018

Components: Blink>Layout
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.

Comment 2 by e...@chromium.org, May 1 2018

Status: WontFix (was: Untriaged)
Project Member

Comment 3 by ClusterFuzz, May 8 2018

Labels: Needs-Feedback
ClusterFuzz testcase 5852386921545728 is still reproducing on tip-of-tree build (trunk).

If this testcase was not reproducible locally or unworkable, ignore this notification and we will file another bug soon with hopefully a better and workable testcase.

Otherwise, if this is not intended to be fixed (e.g. this is an intentional crash), please add ClusterFuzz-Ignore label to prevent future bug filing with similar crash stacktrace.
 Issue 851704  has been merged into this issue.
 Issue 855007  has been merged into this issue.

Sign in to add a comment