Closed Bug 757023 Opened 12 years ago Closed 12 years ago

Heap-use-after-free in XPCNativeScriptableInfo::Mark()

Categories

(Core :: XPConnect, defect)

15 Branch
x86_64
Linux
defect
Not set
critical

Tracking

()

RESOLVED DUPLICATE of bug 752340

People

(Reporter: ax330d, Assigned: mccr8)

Details

(Keywords: crash, sec-other, testcase, Whiteboard: [asan][sg:dupe 752340])

Attachments

(3 files)

Attached file ASan log
ASan reported heap-use-after-free, log is attached. Unfortunately no test-case at the moment. 

Version where bug was found: http://hg.mozilla.org/mozilla-central/rev/95437bcc43dc
Don't know how far we'll get without a testcase, but maybe bholley can spot something from the trace.
Component: Untriaged → XPConnect
Product: Firefox → Core
QA Contact: untriaged → xpconnect
Whiteboard: [asan]
Maybe this is bug 751454? Fix just landed.
The bug is still on cf4face65451, but I am working on test-case - will provide it in a day or two.
It is not that reliable - sometimes one have to wait for ~15 seconds until it crashes.
Confirmed this using today's daily m-c asan build ( https://ftp.mozilla.org/pub/mozilla.org/firefox/try-builds/choller@mozilla.com-2debc330caa1/try-linux64/ ).
Status: UNCONFIRMED → NEW
Ever confirmed: true
Assignee: nobody → continuation
Severity: normal → critical
This looks like another variant of bug 752340.  With the assertion from that bug, this test case hits it immediately.  With the assertion and the fix in place, it doesn't seem to crash, even after a minute or so.
Status: NEW → RESOLVED
Closed: 12 years ago
Resolution: --- → DUPLICATE
Group: core-security
Keywords: sec-other
Whiteboard: [asan] → [asan][sg:dupe 752340]
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: