New issue
Advanced search Search tips

Issue 901988 link

Starred by 2 users

Issue metadata

Status: Verified
Owner: ----
Closed: Nov 11
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 1
Type: Bug



Sign in to add a comment

Null-dereference READ in blink::LineBreakIteratorPool::Take

Project Member Reported by ClusterFuzz, Nov 5

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5724077366706176

Fuzzer: inferno_twister_c
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: Null-dereference READ
Crash Address: 0x000000000000
Crash State:
  blink::LineBreakIteratorPool::Take
  blink::AcquireLineBreakIterator
  blink::LazyLineBreakIterator::GetIterator
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=603104:603123

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5724077366706176

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Project Member

Comment 1 by ClusterFuzz, Nov 5

Components: Platform
Labels: Test-Predator-Auto-Components
Automatically applying components based on crash stacktrace and information from OWNERS files.

If this is incorrect, please apply the Test-Predator-Wrong-Components label.
Cc: kkaluri@chromium.org
Labels: M-72 Test-Predator-Wrong CF-NeedsTriage
Unable to find actual suspect through code search and also observing no CL's under regression range, hence adding appropriate label and requesting someone from dev team to look in to this issue.

Thanks!
Project Member

Comment 3 by ClusterFuzz, Nov 11

ClusterFuzz has detected this issue as fixed in range 607123:607124.

Detailed report: https://clusterfuzz.com/testcase?key=5724077366706176

Fuzzer: inferno_twister_c
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: Null-dereference READ
Crash Address: 0x000000000000
Crash State:
  blink::LineBreakIteratorPool::Take
  blink::AcquireLineBreakIterator
  blink::LazyLineBreakIterator::GetIterator
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=603104:603123
Fixed: https://clusterfuzz.com/revisions?job=mac_asan_chrome&range=607123:607124

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5724077366706176

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 4 by ClusterFuzz, Nov 11

Labels: ClusterFuzz-Verified
Status: Verified (was: Untriaged)
ClusterFuzz testcase 5724077366706176 is verified as fixed, so closing issue as verified.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment