New issue
Advanced search Search tips

Issue 865571 link

Starred by 1 user

Issue metadata

Status: Closed
Owner:
Closed: Aug 20
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Null-dereference READ in blink::mojom::SpeechRecognitionSessionClientProxy::ErrorOccurred

Project Member Reported by ClusterFuzz, Jul 19

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=4956500049788928

Fuzzer: inferno_twister
Job Type: linux_asan_chrome_media
Platform Id: linux

Crash Type: Null-dereference READ
Crash Address: 0x000000000008
Crash State:
  blink::mojom::SpeechRecognitionSessionClientProxy::ErrorOccurred
  content::SpeechRecognitionSession::OnRecognitionError
  content::SpeechRecognitionManagerImpl::RecognitionAllowedCallback
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=linux_asan_chrome_media&range=569602:569603

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4956500049788928

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, Jul 19

Components: Blink>Speech
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
Project Member

Comment 2 by ClusterFuzz, Jul 19

Labels: Test-Predator-Auto-Owner
Owner: adithyas@chromium.org
Status: Assigned (was: Untriaged)
Automatically assigning owner based on suspected regression changelist https://chromium.googlesource.com/chromium/src/+/f5b33428689a900261141871bf5346acf7619640 (Onion soupify SpeechRecognition).

If this is incorrect, please let us know why and apply the Test-Predator-Wrong-CLs label. If you aren't the correct owner for this issue, please unassign yourself as soon as possible so it can be re-triaged.
Project Member

Comment 3 by bugdroid1@chromium.org, Jul 24

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/1a14810374c4982d90068d1429abde3146a22508

commit 1a14810374c4982d90068d1429abde3146a22508
Author: Adithya Srinivasan <adithyas@chromium.org>
Date: Tue Jul 24 14:05:05 2018

Add connection error handler for SpeechRecognitionSessionClient

Bug:  865571 
Change-Id: I722a58f53bbeee0236e6fb64b8f7eb9956526c3c
Reviewed-on: https://chromium-review.googlesource.com/1147485
Reviewed-by: Kinuko Yasuda <kinuko@chromium.org>
Commit-Queue: Adithya Srinivasan <adithyas@chromium.org>
Cr-Commit-Position: refs/heads/master@{#577520}
[modify] https://crrev.com/1a14810374c4982d90068d1429abde3146a22508/content/browser/speech/speech_recognition_dispatcher_host.cc
[modify] https://crrev.com/1a14810374c4982d90068d1429abde3146a22508/content/browser/speech/speech_recognition_dispatcher_host.h

Project Member

Comment 4 by ClusterFuzz, Aug 20

ClusterFuzz testcase 4956500049788928 is associated with an obsolete fuzzer and can no longer be processed. Please close the issue if it is no longer actionable.
Project Member

Comment 5 by ClusterFuzz, Aug 20

ClusterFuzz testcase 4956500049788928 is associated with an obsolete fuzzer and can no longer be processed. Please close the issue if it is no longer actionable.
Project Member

Comment 6 by ClusterFuzz, Aug 20

ClusterFuzz testcase 4956500049788928 is associated with an obsolete fuzzer and can no longer be processed. Please close the issue if it is no longer actionable.
Project Member

Comment 7 by ClusterFuzz, Aug 20

ClusterFuzz testcase 4956500049788928 is associated with an obsolete fuzzer and can no longer be processed. Please close the issue if it is no longer actionable.
Project Member

Comment 8 by ClusterFuzz, Aug 20

ClusterFuzz testcase 4956500049788928 is associated with an obsolete fuzzer and can no longer be processed. Please close the issue if it is no longer actionable.
Project Member

Comment 9 by ClusterFuzz, Aug 20

ClusterFuzz testcase 4956500049788928 is associated with an obsolete fuzzer and can no longer be processed. Please close the issue if it is no longer actionable.
Project Member

Comment 10 by ClusterFuzz, Aug 20

ClusterFuzz testcase 4956500049788928 is associated with an obsolete fuzzer and can no longer be processed. Please close the issue if it is no longer actionable.
Project Member

Comment 11 by ClusterFuzz, Aug 20

ClusterFuzz testcase 4956500049788928 is associated with an obsolete fuzzer and can no longer be processed. Please close the issue if it is no longer actionable.
Project Member

Comment 12 by ClusterFuzz, Aug 20

ClusterFuzz testcase 4956500049788928 is associated with an obsolete fuzzer and can no longer be processed. Please close the issue if it is no longer actionable.
Project Member

Comment 13 by ClusterFuzz, Aug 20

ClusterFuzz testcase 4956500049788928 is associated with an obsolete fuzzer and can no longer be processed. Please close the issue if it is no longer actionable.
Project Member

Comment 14 by ClusterFuzz, Aug 20

ClusterFuzz testcase 4956500049788928 is associated with an obsolete fuzzer and can no longer be processed. Please close the issue if it is no longer actionable.
Project Member

Comment 15 by ClusterFuzz, Aug 20

ClusterFuzz testcase 4956500049788928 is associated with an obsolete fuzzer and can no longer be processed. Please close the issue if it is no longer actionable.
Project Member

Comment 16 by ClusterFuzz, Aug 20

ClusterFuzz testcase 4956500049788928 is associated with an obsolete fuzzer and can no longer be processed. Please close the issue if it is no longer actionable.
Project Member

Comment 17 by ClusterFuzz, Aug 20

ClusterFuzz testcase 4956500049788928 is associated with an obsolete fuzzer and can no longer be processed. Please close the issue if it is no longer actionable.
Project Member

Comment 18 by ClusterFuzz, Aug 20

ClusterFuzz testcase 4956500049788928 is associated with an obsolete fuzzer and can no longer be processed. Please close the issue if it is no longer actionable.
Project Member

Comment 19 by ClusterFuzz, Aug 20

ClusterFuzz testcase 4956500049788928 is associated with an obsolete fuzzer and can no longer be processed. Please close the issue if it is no longer actionable.
Project Member

Comment 20 by ClusterFuzz, Aug 20

ClusterFuzz testcase 4956500049788928 is associated with an obsolete fuzzer and can no longer be processed. Please close the issue if it is no longer actionable.
Project Member

Comment 21 by ClusterFuzz, Aug 20

ClusterFuzz testcase 4956500049788928 is associated with an obsolete fuzzer and can no longer be processed. Please close the issue if it is no longer actionable.
Project Member

Comment 22 by ClusterFuzz, Aug 20

ClusterFuzz testcase 4956500049788928 is associated with an obsolete fuzzer and can no longer be processed. Please close the issue if it is no longer actionable.
Status: Closed (was: Assigned)

Sign in to add a comment