Integer-overflow in blink::LayoutFrameSet::UpdateLayout |
||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5194601586229248 Fuzzer: ifratric-browserfuzzer-v3 Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: blink::LayoutFrameSet::UpdateLayout LayoutIfNeeded blink::GridTrackSizingAlgorithmStrategy::LogicalHeightForChild Sanitizer: undefined (UBSAN) Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5194601586229248 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Jun 29 2018
Predator and CL could not provide any possible suspects. Using Code Search for the file, "grid_track_sizing_algorithm.cc" suspecting the below Cl might have caused this issue Suspect CL: https://chromium.googlesource.com/chromium/src/+/75d24bd94da41caf2a6a0061b3ae528a7528a79e jfernandez@ -- Could you please check whether this is caused with respect to your change, if not please help us in assigning it to the right owner. Thanks!
,
Jun 29 2018
,
Jun 29 2018
Umm, I cannot reproduce it in today's ToT (linux)
,
Jun 29 2018
It's not reproducible in the following versions either: * Google Chrome 69.0.3472.3 (Official Build) dev (64-bit) * Google Chrome 68.0.3440.42 (Official Build) beta (64-bit)
,
Jun 29 2018
I tried to build at the specific suspicious commit and I'm still unable to reproduce the issue. In my opinion, it's not the root cause of the issue.
,
Jun 29 2018
,
Jun 29 2018
,
Jun 29 2018
,
Jun 29 2018
I think I managed to reproduce the issue.
,
Jun 29 2018
I think I managed to reproduce the issue.
,
Jul 1
,
Jul 4
,
Aug 2
,
Dec 14
Non-security numeric overflow bugs are considered won't fix.
,
Dec 21
ClusterFuzz testcase 5194601586229248 is still reproducing on tip-of-tree build (trunk). If this testcase was not reproducible locally or unworkable, ignore this notification and we will file another bug soon with hopefully a better and workable testcase. Otherwise, if this is not intended to be fixed (e.g. this is an intentional crash), please add ClusterFuzz-Ignore label to prevent future bug filing with similar crash stacktrace. |
||||||||||||||
►
Sign in to add a comment |
||||||||||||||
Comment 1 by ClusterFuzz
, Jun 29 2018Labels: Test-Predator-Auto-Components