Integer-overflow in blink::list_marker_text::GetText |
|||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5911422188650496 Fuzzer: ifratric-browserfuzzer-v3 Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: blink::list_marker_text::GetText blink::LayoutListMarker::UpdateContent blink::LayoutListMarker::ComputePreferredLogicalWidths Sanitizer: undefined (UBSAN) Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5911422188650496 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Oct 24
,
Oct 26
|
|||
►
Sign in to add a comment |
|||
Comment 1 by kkaluri@chromium.org
, Oct 22Labels: M-70 CF-NeedsTriage Test-Predator-Wrong