New issue
Advanced search Search tips

Issue 853552 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Jun 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows
Pri: 1
Type: Bug-Security



Sign in to add a comment

Heap-use-after-free in blink::LayoutObject::ContainingBlock

Project Member Reported by ClusterFuzz, Jun 17 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5627573481242624

Fuzzer: mbarbella_webcomponents
Job Type: windows_asan_content_shell
Platform Id: windows

Crash Type: Heap-use-after-free READ 4
Crash Address: 0x11e70c3d1fc0
Crash State:
  blink::LayoutObject::ContainingBlock
  blink::LayoutObject::Container
  blink::LayoutObject::MarkContainerChainForLayout
  
Sanitizer: address (ASAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=windows_asan_content_shell&range=567880:567882

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5627573481242624

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, Jun 17 2018

Components: Blink>Layout
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
Project Member

Comment 2 by ClusterFuzz, Jun 17 2018

Labels: Test-Predator-Auto-Owner
Owner: mstensho@chromium.org
Status: Assigned (was: Untriaged)
Automatically assigning owner based on suspected regression changelist https://chromium.googlesource.com/chromium/src/+/2394d0acf8bf0b0236b2646e4c823a57de7bd941 (Floats and out-of-flow objects may not be adjacent to anonymous blocks.).

If this is incorrect, please let us know why and apply the Test-Predator-Wrong-CLs label. If you aren't the correct owner for this issue, please unassign yourself as soon as possible so it can be re-triaged.
Cc: e...@chromium.org mstensho@chromium.org
 Issue 853522  has been merged into this issue.
 Issue 853537  has been merged into this issue.
 Issue 853538  has been merged into this issue.
 Issue 853540  has been merged into this issue.
Project Member

Comment 4 by ClusterFuzz, Jun 17 2018

Labels: OS-Linux
 Issue 853567  has been merged into this issue.
Project Member

Comment 7 by ClusterFuzz, Jun 18 2018

ClusterFuzz has detected this issue as fixed in range 567913:567914.

Detailed report: https://clusterfuzz.com/testcase?key=5627573481242624

Fuzzer: mbarbella_webcomponents
Job Type: windows_asan_content_shell
Platform Id: windows

Crash Type: Heap-use-after-free READ 4
Crash Address: 0x11e70c3d1fc0
Crash State:
  blink::LayoutObject::ContainingBlock
  blink::LayoutObject::Container
  blink::LayoutObject::MarkContainerChainForLayout
  
Sanitizer: address (ASAN)

Recommended Security Severity: High

Regressed: https://clusterfuzz.com/revisions?job=windows_asan_content_shell&range=567880:567882
Fixed: https://clusterfuzz.com/revisions?job=windows_asan_content_shell&range=567913:567914

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5627573481242624

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 8 by ClusterFuzz, Jun 18 2018

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 5627573481242624 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 9 by sheriffbot@chromium.org, Jun 18 2018

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Project Member

Comment 11 by ClusterFuzz, Jun 25 2018

Labels: Needs-Feedback
ClusterFuzz testcase 5352322314797056 is still reproducing on tip-of-tree build (trunk).

Please re-test your fix against this testcase and if the fix was incorrect or incomplete, please re-open the bug. Otherwise, ignore this notification and add ClusterFuzz-Wrong label.
Labels: -Needs-Feedback
That testcase was for  bug 853538 , which was incorrectly marked as duplicate of this bug. I have reopened it.
Project Member

Comment 13 by sheriffbot@chromium.org, Jul 28

Labels: Pri-1
Project Member

Comment 14 by sheriffbot@chromium.org, Sep 24

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment