Closed Bug 1398638 Opened 7 years ago Closed 7 years ago

Crash in mozilla::layers::RenderLayers<T>

Categories

(Core :: Graphics: Layers, defect)

56 Branch
Unspecified
Android
defect
Not set
critical

Tracking

()

RESOLVED DUPLICATE of bug 1395138

People

(Reporter: n.nethercote, Unassigned)

Details

(Keywords: crash)

Crash Data

This bug was filed from the Socorro interface and is 
report bp-67a920ac-98aa-4815-86c4-997740170909.
=============================================================

This signature has been around for a while, but seems to be more common over the past week or so.

The most notable thing is that the crash address is 0xe5e5e5f5 in the majority of cases. 0xe5 is jemalloc's poison-on-free pattern, so this suggests a UAF.

snorp, any ideas?
Flags: needinfo?(snorp)
Group: core-security
Status: NEW → RESOLVED
Closed: 7 years ago
Resolution: --- → DUPLICATE
Group: core-security → gfx-core-security
Group: gfx-core-security
You need to log in before you can comment on or make changes to this bug.