Null-dereference WRITE in gl::Crash |
||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5070686754963456 Fuzzer: inferno_twister Job Type: linux_ubsan_vptr_content_shell_drt Platform Id: linux Crash Type: Null-dereference WRITE Crash Address: 0x000000000000 Crash State: gl::Crash bool IPC::MessageT<GpuChannelMsg_CrashForTesting_Meta, std::__1::tuple<>, void>: gpu::GpuChannel::OnControlMessageReceived Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_vptr_content_shell_drt&range=581064:581078 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5070686754963456 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Aug 8
I don't know where the command line flags are being set in the fuzzing harness, but this definitely isn't accessible from the renderer process unless --enable-gpu-benchmarking is being passed on the command line. |
||
►
Sign in to add a comment |
||
Comment 1 by kkaluri@chromium.org
, Aug 8Labels: M-70
Owner: kbr@chromium.org
Status: Assigned (was: Untriaged)