Issue metadata
Sign in to add a comment
|
Bad-cast to blink::LayoutObject from invalid vptr in blink::LayoutBlockFlow::RemoveChild |
||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=4505325672333312 Fuzzer: bj_broddelwerk Job Type: linux_cfi_chrome Platform Id: linux Crash Type: Bad-cast Crash Address: 0xd0c5c10ed8140000 Crash State: Bad-cast to blink::LayoutObject from invalid vptr blink::LayoutBlockFlow::RemoveChild blink::LayoutObject::WillBeDestroyed Sanitizer: cfi (CFI) Recommended Security Severity: High Regressed: https://clusterfuzz.com/revisions?job=linux_cfi_chrome&range=559420:559432 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4505325672333312 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
May 24 2018
Very likely dupe of Issue 844277 which has the same regression range and which was fixed in the Fixed range.
,
May 24 2018
,
May 24 2018
Automatically applying components based on crash stacktrace and information from OWNERS files. If this is incorrect, please apply the Test-Predator-Wrong-Components label.
,
May 24 2018
ClusterFuzz testcase 4505325672333312 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
May 24 2018
,
Jul 28
,
Aug 30
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by ClusterFuzz
, May 24 2018