New issue
Advanced search Search tips

Issue 855004 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Jul 23
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 1
Type: Bug-Security



Sign in to add a comment

Heap-use-after-free in views::Slider::SetValueInternal

Project Member Reported by ClusterFuzz, Jun 21 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=4895393008320512

Fuzzer: attekett_webaudio_fuzzer
Job Type: linux_asan_chrome_chromeos
Platform Id: linux

Crash Type: Heap-use-after-free READ 8
Crash Address: 0x606000784c68
Crash State:
  views::Slider::SetValueInternal
  chromeos::CrasAudioHandler::OutputNodeVolumeChanged
  chromeos::FakeCrasAudioClient::NotifyOutputNodeVolumeChangedForTesting
  
Sanitizer: address (ASAN)

Recommended Security Severity: High

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4895393008320512

Additional requirements: Requires Gestures

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by sheriffbot@chromium.org, Jun 21 2018

Labels: M-69 Target-69
Project Member

Comment 2 by sheriffbot@chromium.org, Jun 21 2018

Labels: ReleaseBlock-Stable
This is a serious security regression. If you are not able to fix this quickly, please revert the change that introduced it.

If this doesn't affect a release branch, or has not been properly classified for severity, please update the Security_Impact or Security_Severity labels, and remove the ReleaseBlock label. To disable this altogether, apply ReleaseBlock-NA.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 3 by sheriffbot@chromium.org, Jun 21 2018

Labels: Pri-1
Project Member

Comment 4 by ClusterFuzz, Jun 24 2018

Labels: -Reproducible Unreproducible
ClusterFuzz testcase 4895393008320512 appears to be flaky, updating reproducibility label.
Components: Internals>Media>Audio
Owner: jen...@chromium.org
Status: Assigned (was: Untriaged)
Over to a chromeos/audio OWNER to look at.
Project Member

Comment 6 by sheriffbot@chromium.org, Jul 5

jennyz: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers?

If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one?

If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
This is a test failure, but I didn't see where the test code is. It may not be a real case we're going to run into in real world. I need to see how the test is written first. I am not familiar with how cluster_fuzzer testing works. 
Project Member

Comment 8 by ClusterFuzz, Jul 23

Status: WontFix (was: Assigned)
ClusterFuzz testcase 4895393008320512 is flaky and no longer crashes, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 9 by sheriffbot@chromium.org, Jul 24

Labels: -reward-topanel reward-ineligible
Project Member

Comment 10 by sheriffbot@chromium.org, Oct 30

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment