New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 874581 link

Starred by 1 user

Issue metadata

Status: Duplicate
Owner:
Last visit > 30 days ago
Closed: Aug 16
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Null-dereference READ in blink::LiveNodeListBase::InvalidateCacheForAttribute

Project Member Reported by ClusterFuzz, Aug 15

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5786029362249728

Fuzzer: ifratric-browserfuzzer-v3
Job Type: linux_cfi_chrome
Platform Id: linux

Crash Type: Null-dereference READ
Crash Address: 0x000000000010
Crash State:
  blink::LiveNodeListBase::InvalidateCacheForAttribute
  blink::NodeListsNodeData::InvalidateCaches
  blink::ContainerNode::InvalidateNodeListCachesInAncestors
  
Sanitizer: cfi (CFI)

Regressed: https://clusterfuzz.com/revisions?job=linux_cfi_chrome&range=583177:583181

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5786029362249728

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, Aug 15

Components: Blink>DOM
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
Project Member

Comment 2 by ClusterFuzz, Aug 15

Labels: Test-Predator-Auto-Owner
Owner: kymuto@google.com
Status: Assigned (was: Untriaged)
Automatically assigning owner based on suspected regression changelist https://chromium.googlesource.com/chromium/src/+/0fd72b878bb8e5fef918b9a836d760d6cecc4150 (Add Assign function).

If this is incorrect, please let us know why and apply the Test-Predator-Wrong-CLs label. If you aren't the correct owner for this issue, please unassign yourself as soon as possible so it can be re-triaged.
Labels: Test-Predator-Wrong-CLs
Mergedinto: 762931
Status: Duplicate (was: Assigned)
I couldn't repro this. The repro case is too huge.
Given that CL is unlikely to the cause, and this crash is similar to bug 762931,
let's merge this into that.
Project Member

Comment 4 by ClusterFuzz, Aug 16

ClusterFuzz has detected this issue as fixed in range 583238:583249.

Detailed report: https://clusterfuzz.com/testcase?key=5786029362249728

Fuzzer: ifratric-browserfuzzer-v3
Job Type: linux_cfi_chrome
Platform Id: linux

Crash Type: Null-dereference READ
Crash Address: 0x000000000010
Crash State:
  blink::LiveNodeListBase::InvalidateCacheForAttribute
  blink::NodeListsNodeData::InvalidateCaches
  blink::ContainerNode::InvalidateNodeListCachesInAncestors
  
Sanitizer: cfi (CFI)

Regressed: https://clusterfuzz.com/revisions?job=linux_cfi_chrome&range=583177:583181
Fixed: https://clusterfuzz.com/revisions?job=linux_cfi_chrome&range=583238:583249

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5786029362249728

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Sign in to add a comment