Closed Bug 1161366 Opened 5 years ago Closed 5 years ago
crash in Font
Face .load when loading a second face for a font using unicode-range
The attachment will crash Firefox with a null pointer dereference if the Font Loading API is enabled (as it is currently on Nightly/Aurora).
This is because we're parsing the font descriptor values passing null for the sheet URI. The sheet URI gets stored in the URLValue, and then copied into the gfxFontFaceSrc object, where its operator== assumes that it is non-null.
Assignee: nobody → cam
Status: NEW → ASSIGNED
Attachment #8601252 - Flags: review?(dbaron)
Comment on attachment 8601252 [details] [diff] [review] patch Maybe call the variable docURI instead of just uri? r=dbaron
Attachment #8601252 - Flags: review?(dbaron) → review+
You need to log in before you can comment on or make changes to this bug.