Seems like the pointer mAnimatedGeometryRoot is not initialized in the rarely used nsDisplayItem that takes an nsIFrame*.
I'm guessing we could possibly end up dereferencing an uninitialized pointer here, so maybe not a bad idea to uplift since it should be completely safe.
2 years ago
Attachment #8915149 - Flags: review?(matt.woodrow) → review+
[Tracking Requested - why for this release]: see comment 2
Pushed by firstname.lastname@example.org: https://hg.mozilla.org/integration/mozilla-inbound/rev/c45a9377bfb7 Make sure mAnimatedGeometryRoot is initialized to nullptr in the rarely used nsDisplayItem ctor that takes an nsIFrame*. r=mattwoodrow
please request uplift to beta when you get a chance.
Comment on attachment 8915149 [details] [diff] [review] patch Approval Request Comment [Feature/Bug causing the regression]: been around a while [User impact if declined]: potential dereference of uninitialized memory [Is this code covered by automated tests?]: how we'd trigger a derefernce is unexplored [Has the fix been verified in Nightly?]: yes [Needs manual test from QE? If yes, steps to reproduce]: no [List of other uplifts needed for the feature/fix]: none [Is the change risky?]: no [Why is the change risky/not risky?]: simply initializing a pointer to null - crashing would be better than a security issue [String changes made/needed]: none
Attachment #8915149 - Flags: approval-mozilla-beta?
Comment on attachment 8915149 [details] [diff] [review] patch makes sense, beta57+
Attachment #8915149 - Flags: approval-mozilla-beta? → approval-mozilla-beta+
(In reply to Jonathan Watt [:jwatt] (needinfo? me) from comment #7) > [Needs manual test from QE? If yes, steps to reproduce]: no Marking this issue as qe-, per Jonathan's assessment on manual testing needs
You need to log in before you can comment on or make changes to this bug.