New issue
Advanced search Search tips

Issue 846192 link

Starred by 2 users

Issue metadata

Status: Verified
Owner: ----
Closed: May 2018
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Security



Sign in to add a comment

Bad-cast to blink::LayoutObject from invalid vptr in blink::LayoutBlockFlow::RemoveChild

Project Member Reported by ClusterFuzz, May 24 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=4505325672333312

Fuzzer: bj_broddelwerk
Job Type: linux_cfi_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0xd0c5c10ed8140000
Crash State:
  Bad-cast to blink::LayoutObject from invalid vptr
  blink::LayoutBlockFlow::RemoveChild
  blink::LayoutObject::WillBeDestroyed
  
Sanitizer: cfi (CFI)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_cfi_chrome&range=559420:559432

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4505325672333312

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, May 24 2018

ClusterFuzz has detected this issue as fixed in range 560941:560959.

Detailed report: https://clusterfuzz.com/testcase?key=4505325672333312

Fuzzer: bj_broddelwerk
Job Type: linux_cfi_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0xd0c5c10ed8140000
Crash State:
  Bad-cast to blink::LayoutObject from invalid vptr
  blink::LayoutBlockFlow::RemoveChild
  blink::LayoutObject::WillBeDestroyed
  
Sanitizer: cfi (CFI)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=linux_cfi_chrome&range=559420:559432
Fixed: https://clusterfuzz.com/revisions?job=linux_cfi_chrome&range=560941:560959

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4505325672333312

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Very likely dupe of Issue 844277 which has the same regression range and which was fixed in the Fixed range.
Project Member

Comment 3 by sheriffbot@chromium.org, May 24 2018

Labels: M-68
Project Member

Comment 4 by ClusterFuzz, May 24 2018

Components: Blink>Layout
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
Project Member

Comment 5 by ClusterFuzz, May 24 2018

Labels: ClusterFuzz-Verified
Status: Verified (was: Untriaged)
ClusterFuzz testcase 4505325672333312 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 6 by sheriffbot@chromium.org, May 24 2018

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Project Member

Comment 7 by sheriffbot@chromium.org, Jul 28

Labels: Pri-1
Project Member

Comment 8 by sheriffbot@chromium.org, Aug 30

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment