New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 853492 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Jul 4
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Security



Sign in to add a comment

CHECK failure: object->IsAbstractCode() || object->IsSeqString() || object->IsExternalString()

Project Member Reported by ClusterFuzz, Jun 16 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=6164912544677888

Fuzzer: ochang_js_fuzzer
Job Type: linux_d8_dbg
Platform Id: linux

Crash Type: CHECK failure
Crash Address: 
Crash State:
  object->IsAbstractCode() || object->IsSeqString() || object->IsExternalString() 
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_d8_dbg&range=53773:53774

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6164912544677888

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, Jun 16 2018

Cc: kanghua...@intel.com
Labels: Test-Predator-Auto-CC
Automatically adding ccs based on suspected regression changelists:

[turbofan] Add verification for jump optimization. by kanghua.yu@intel.com - https://chromium.googlesource.com/v8/v8/+/86e68d02afef57fe0b443a44b99c681991047d06

If this is incorrect, please let us know why and apply the Test-Predator-Wrong-CLs label.
Project Member

Comment 2 by sheriffbot@chromium.org, Jun 17 2018

Labels: Pri-1

Comment 3 by wfh@chromium.org, Jun 19 2018

Cc: danno@chromium.org
Owner: jarin@chromium.org
Status: Assigned (was: Untriaged)
Hi, please take a look at this new CHECK.

It seems pretty strongly tied to https://chromium-review.googlesource.com/c/v8/v8/+/1100491

It seems like this just triggers a CHECK so does this have any security implications?

-> jarin as I can't assign to a non-contributer.

Comment 4 by och...@chromium.org, Jun 26 2018

Labels: Security_Impact-Head
Project Member

Comment 5 by sheriffbot@chromium.org, Jun 26 2018

Labels: M-69 Target-69
Project Member

Comment 6 by sheriffbot@chromium.org, Jun 26 2018

Labels: ReleaseBlock-Stable
This is a serious security regression. If you are not able to fix this quickly, please revert the change that introduced it.

If this doesn't affect a release branch, or has not been properly classified for severity, please update the Security_Impact or Security_Severity labels, and remove the ReleaseBlock label. To disable this altogether, apply ReleaseBlock-NA.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
I am not authorized to access this page, could you please provide back trace for analysis.
Project Member

Comment 8 by sheriffbot@chromium.org, Jul 1

jarin: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers?

If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one?

If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 9 by ClusterFuzz, Jul 4

Labels: -Reproducible Unreproducible
ClusterFuzz testcase 6164912544677888 appears to be flaky, updating reproducibility label.
Project Member

Comment 10 by ClusterFuzz, Jul 4

Status: WontFix (was: Assigned)
ClusterFuzz testcase 6164912544677888 is flaky and no longer crashes, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 11 by sheriffbot@chromium.org, Oct 11

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment