Issue metadata
Sign in to add a comment
|
Global-buffer-overflow in MemoryRead<unsigned |
||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=4829822520655872 Fuzzer: ochang_js_fuzzer Job Type: linux_asan_d8_v8_arm64_dbg Platform Id: linux Crash Type: Global-buffer-overflow READ 4 Crash Address: 0x7f40c3c0d8a3 Crash State: MemoryRead<unsigned v8::internal::Simulator::LoadStoreHelper v8::internal::Simulator::ExecuteInstruction Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=linux_asan_d8_v8_arm64_dbg&range=56413:56414 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4829822520655872 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Oct 6
,
Oct 8
,
Oct 8
The following revision refers to this bug: https://chromium.googlesource.com/v8/v8.git/+/890fd9c89f877de1269026135a30e7d4d582ef4b commit 890fd9c89f877de1269026135a30e7d4d582ef4b Author: Maya Lekova <mslekova@chromium.org> Date: Mon Oct 08 09:16:14 2018 [async-await] Fix global-buffer-overflow issue when loading flag Bug: chromium:892858 Change-Id: I97b0b239e3ee0a9073fdbd609fb26271dda64d6d Reviewed-on: https://chromium-review.googlesource.com/c/1267936 Commit-Queue: Maya Lekova <mslekova@chromium.org> Reviewed-by: Benedikt Meurer <bmeurer@chromium.org> Cr-Commit-Position: refs/heads/master@{#56432} [modify] https://crrev.com/890fd9c89f877de1269026135a30e7d4d582ef4b/src/builtins/builtins-async-gen.cc [add] https://crrev.com/890fd9c89f877de1269026135a30e7d4d582ef4b/test/mjsunit/regress/regress-892858.js
,
Oct 8
,
Oct 8
,
Oct 9
ClusterFuzz has detected this issue as fixed in range 56431:56432. Detailed report: https://clusterfuzz.com/testcase?key=4829822520655872 Fuzzer: ochang_js_fuzzer Job Type: linux_asan_d8_v8_arm64_dbg Platform Id: linux Crash Type: Global-buffer-overflow READ 4 Crash Address: 0x7f40c3c0d8a3 Crash State: MemoryRead<unsigned v8::internal::Simulator::LoadStoreHelper v8::internal::Simulator::ExecuteInstruction Sanitizer: address (ASAN) Regressed: https://clusterfuzz.com/revisions?job=linux_asan_d8_v8_arm64_dbg&range=56413:56414 Fixed: https://clusterfuzz.com/revisions?job=linux_asan_d8_v8_arm64_dbg&range=56431:56432 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4829822520655872 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Oct 9
ClusterFuzz testcase 4829822520655872 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Jan 14
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by ClusterFuzz
, Oct 6Owner: mslekova@chromium.org
Status: Assigned (was: Untriaged)