Null-dereference READ in chrome |
|||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5629674929258496 Fuzzer: bj_broddelwerk Job Type: linux_cfi_chrome Platform Id: linux Crash Type: Null-dereference READ Crash Address: 0x000000000010 Crash State: chrome blink::Node::IsDescendantOf blink::SelectionForParagraphIteration Sanitizer: cfi (CFI) Regressed: https://clusterfuzz.com/revisions?job=linux_cfi_chrome&range=596889:609905 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5629674929258496 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Dec 5
Predator has provided 4 possible suspects 1. Make flat tree traversal faster by hayato@chromium.org 2. Rename blink::HTMLNames namespace to blink::html_names by tkent@chromium.org 3. Make flat tree traversal faster (2nd wave) by hayato@chromium.org 4. Rename blink::EventTypeNames namespace to blink::event_type_names by tkent@chromium.org Using the suspect file " core/dom/node.cc" suspecting following CL : https://chromium.googlesource.com/chromium/src/+/4377df6fcb5e5749cd359bf11656ef1ea53e99c6 hayato@ Could you please look into it.
,
Dec 19
ClusterFuzz has detected this issue as fixed in range 617610:617615. Detailed report: https://clusterfuzz.com/testcase?key=5629674929258496 Fuzzer: bj_broddelwerk Job Type: linux_cfi_chrome Platform Id: linux Crash Type: Null-dereference READ Crash Address: 0x000000000010 Crash State: chrome blink::Node::IsDescendantOf blink::SelectionForParagraphIteration Sanitizer: cfi (CFI) Regressed: https://clusterfuzz.com/revisions?job=linux_cfi_chrome&range=596889:609905 Fixed: https://clusterfuzz.com/revisions?job=linux_cfi_chrome&range=617610:617615 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5629674929258496 See https://github.com/google/clusterfuzz-tools for instructions to reproduce this bug locally. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Dec 19
ClusterFuzz testcase 5629674929258496 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
|||
►
Sign in to add a comment |
|||
Comment 1 by ClusterFuzz
, Dec 4Labels: Test-Predator-Auto-Components