New issue
Advanced search Search tips

Issue 871744 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Aug 9
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Null-dereference READ in chrome

Project Member Reported by ClusterFuzz, Aug 7

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5003297174585344

Fuzzer: ifratric-browserfuzzer-v3
Job Type: linux_cfi_chrome
Platform Id: linux

Crash Type: Null-dereference READ
Crash Address: 0x000000000008
Crash State:
  chrome
  blink::EffectPaintPropertyNode const& blink::LowestCommonAncestor<blink::EffectP
  blink::ConversionContext::SwitchToEffect
  
Sanitizer: cfi (CFI)

Regressed: https://clusterfuzz.com/revisions?job=linux_cfi_chrome&range=581002:581008

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5003297174585344

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Cc: kkaluri@chromium.org
Components: Blink>Paint
Labels: M-70 Test-Predator-Wrong
Owner: wangxianzhu@chromium.org
Status: Assigned (was: Untriaged)
Predator and CL could not provide any possible suspects.
Using the code search for the file, “paint_property_node.h” assigning to concern owner from GIT blame.
Suspecting Commit# https://chromium.googlesource.com/chromium/src/+/70fc0b018c9517558b7aa2be00edf2debb449123

wangxianzhu@ -- Could you please look into this issue, kindly reassign if it has nothing to do with your changes.


Thank You.

Predator and CL could not provide any possible suspects.
Using the code search for the file, “paint_property_node.h” assigning to concern owner from GIT blame.
Suspecting Commit# https://chromium.googlesource.com/chromium/src/+/70fc0b018c9517558b7aa2be00edf2debb449123

wangxianzhu@ -- Could you please look into this issue, kindly reassign if it has nothing to do with your changes.


Thank You.

Project Member

Comment 4 by ClusterFuzz, Aug 9

ClusterFuzz has detected this issue as fixed in range 581724:581733.

Detailed report: https://clusterfuzz.com/testcase?key=5003297174585344

Fuzzer: ifratric-browserfuzzer-v3
Job Type: linux_cfi_chrome
Platform Id: linux

Crash Type: Null-dereference READ
Crash Address: 0x000000000008
Crash State:
  chrome
  blink::EffectPaintPropertyNode const& blink::LowestCommonAncestor<blink::EffectP
  blink::ConversionContext::SwitchToEffect
  
Sanitizer: cfi (CFI)

Regressed: https://clusterfuzz.com/revisions?job=linux_cfi_chrome&range=581002:581008
Fixed: https://clusterfuzz.com/revisions?job=linux_cfi_chrome&range=581724:581733

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5003297174585344

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 5 by ClusterFuzz, Aug 9

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase 5003297174585344 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment