Closed
Bug 1451057
Opened 8 years ago
Closed 8 years ago
AddressSanitizer: heap-buffer-overflow mozilla-central/toolkit/components/alerts/nsXULAlerts.cpp:148:55 in nsXULAlerts::ShowAlert(nsIAlertNotification*, nsIObserver*)
Categories
(Toolkit Graveyard :: Notifications and Alerts, defect)
Toolkit Graveyard
Notifications and Alerts
Tracking
(firefox61 affected)
RESOLVED
INVALID
| Tracking | Status | |
|---|---|---|
| firefox61 | --- | affected |
People
(Reporter: Alex_Gaynor, Unassigned)
Details
Attachments
(1 file)
|
8.83 KB,
patch
|
Details | Diff | Splinter Review |
This was triggered by a currently in-development IPC fuzzer (so there's a small chance it's actually a bug in the fuzzer, but I believe this is real). I don't yet have a deterministic reproducer for it unfortunately :-(
Hopefully the stack-trace is enough to help debug it. Please let me know if there's more that I can share that'd be helpful.
=================================================================
==28102==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x61d00020eb90 at pc 0x7fc74ad30e3b bp 0x7ffe8cd9d550 sp 0x7ffe8cd9d548
READ of size 8 at 0x61d00020eb90 thread T0
#0 0x7fc74ad30e3a in nsXULAlerts::ShowAlert(nsIAlertNotification*, nsIObserver*) /home/osboxes/mozilla-central/toolkit/components/alerts/nsXULAlerts.cpp:148:55
#1 0x7fc74ad2ce7b in (anonymous namespace)::ShowWithBackend(nsIAlertsService*, nsIAlertNotification*, nsIObserver*, nsTSubstring<char16_t> const&) /home/osboxes/mozilla-central/toolkit/components/alerts/nsAlertsService.cpp:140:20
#2 0x7fc74ad2c38f in nsAlertsService::ShowPersistentNotification(nsTSubstring<char16_t> const&, nsIAlertNotification*, nsIObserver*) /home/osboxes/mozilla-central/toolkit/components/alerts/nsAlertsService.cpp:258:10
#3 0x7fc745b3f90a in mozilla::dom::ContentParent::RecvShowAlert(nsIAlertNotification* const&) /home/osboxes/mozilla-central/dom/ipc/ContentParent.cpp:3797:18
#4 0x7fc73e0f9158 in mozilla::dom::PContentParent::OnMessageReceived(IPC::Message const&) /home/osboxes/mozilla-central/obj-x86_64-pc-linux-gnu/ipc/ipdl/PContentParent.cpp:4617:20
#5 0x7fc74ce238de in void mozilla::ipc::FuzzProtocol<mozilla::dom::ContentParent>(mozilla::dom::ContentParent*, unsigned char const*, unsigned long) /home/osboxes/mozilla-central/obj-x86_64-pc-linux-gnu/dist/include/ProtocolFuzzer.h:41:17
#6 0x7fc74ce2364c in RunContentParentIPCFuzzing(unsigned char const*, unsigned long) /home/osboxes/mozilla-central/dom/ipc/fuzztest/content_parent_ipc_libfuzz.cpp:27:3
#7 0x5e655b in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:517:13
#8 0x5e3754 in fuzzer::Fuzzer::RunOne(unsigned char const*, unsigned long, bool, fuzzer::InputInfo*, bool*) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:442:3
#9 0x5e7db9 in fuzzer::Fuzzer::MutateAndTestOne() /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:650:19
#10 0x5e9fa5 in fuzzer::Fuzzer::Loop(std::vector<std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> >, fuzzer::fuzzer_allocator<std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> > > > const&) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:773:5
#11 0x5cb8fa in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerDriver.cpp:754:6
#12 0x7fc74b50e88f in mozilla::FuzzerRunner::Run(int*, char***) /home/osboxes/mozilla-central/tools/fuzzing/interface/harness/FuzzerRunner.cpp:60:10
#13 0x7fc74b4257da in XREMain::XRE_mainStartup(bool*) /home/osboxes/mozilla-central/toolkit/xre/nsAppRunner.cpp:3960:35
#14 0x7fc74b438737 in XREMain::XRE_main(int, char**, mozilla::BootstrapConfig const&) /home/osboxes/mozilla-central/toolkit/xre/nsAppRunner.cpp:4896:12
#15 0x7fc74b43a29a in XRE_main(int, char**, mozilla::BootstrapConfig const&) /home/osboxes/mozilla-central/toolkit/xre/nsAppRunner.cpp:5003:21
#16 0x51e145 in do_main(int, char**, char**) /home/osboxes/mozilla-central/browser/app/nsBrowserApp.cpp:231:22
#17 0x51e145 in main /home/osboxes/mozilla-central/browser/app/nsBrowserApp.cpp:304
#18 0x7fc760fc32e0 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x202e0)
#19 0x425559 in _start (/home/osboxes/mozilla-central/obj-x86_64-pc-linux-gnu/dist/bin/firefox+0x425559)
Address 0x61d00020eb90 is a wild pointer.
SUMMARY: AddressSanitizer: heap-buffer-overflow /home/osboxes/mozilla-central/toolkit/components/alerts/nsXULAlerts.cpp:148:55 in nsXULAlerts::ShowAlert(nsIAlertNotification*, nsIObserver*)
Shadow bytes around the buggy address:
0x0c3a80039d20: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
0x0c3a80039d30: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
0x0c3a80039d40: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
0x0c3a80039d50: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
0x0c3a80039d60: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
=>0x0c3a80039d70: fa fa[fa]fa fa fa fa fa fa fa fa fa fa fa fa fa
0x0c3a80039d80: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
0x0c3a80039d90: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
0x0c3a80039da0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
0x0c3a80039db0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
0x0c3a80039dc0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
Shadow byte legend (one shadow byte represents 8 application bytes):
Addressable: 00
Partially addressable: 01 02 03 04 05 06 07
Heap left redzone: fa
Freed heap region: fd
Stack left redzone: f1
Stack mid redzone: f2
Stack right redzone: f3
Stack after return: f5
Stack use after scope: f8
Global redzone: f9
Global init order: f6
Poisoned by user: f7
Container overflow: fc
Array cookie: ac
Intra object redzone: bb
ASan internal: fe
Left alloca redzone: ca
Right alloca redzone: cb
==28102==ABORTING
| Reporter | ||
Comment 1•8 years ago
|
||
Here's a probably-related crash I just encountered.
It appears there's a retained reference to a previous ContentParent instance. I suspect there's the possibility my fuzzer isn't deleting itself correctly, but would appreciate an additional perspective:
==28575==ERROR: AddressSanitizer: heap-use-after-free on address 0x61d00027c190 at pc 0x7fef458a6e3b bp 0x7ffc6be85a10 sp 0x7ffc6be85a08
READ of size 8 at 0x61d00027c190 thread T0
#0 0x7fef458a6e3a in nsXULAlerts::ShowAlert(nsIAlertNotification*, nsIObserver*) /home/osboxes/mozilla-central/toolkit/components/alerts/nsXULAlerts.cpp:148:55
#1 0x7fef458a2e7b in (anonymous namespace)::ShowWithBackend(nsIAlertsService*, nsIAlertNotification*, nsIObserver*, nsTSubstring<char16_t> const&) /home/osboxes/mozilla-central/toolkit/components/alerts/nsAlertsService.cpp:140:20
#2 0x7fef458a238f in nsAlertsService::ShowPersistentNotification(nsTSubstring<char16_t> const&, nsIAlertNotification*, nsIObserver*) /home/osboxes/mozilla-central/toolkit/components/alerts/nsAlertsService.cpp:258:10
#3 0x7fef406b590a in mozilla::dom::ContentParent::RecvShowAlert(nsIAlertNotification* const&) /home/osboxes/mozilla-central/dom/ipc/ContentParent.cpp:3797:18
#4 0x7fef38c6f158 in mozilla::dom::PContentParent::OnMessageReceived(IPC::Message const&) /home/osboxes/mozilla-central/obj-x86_64-pc-linux-gnu/ipc/ipdl/PContentParent.cpp:4617:20
#5 0x7fef479998de in void mozilla::ipc::FuzzProtocol<mozilla::dom::ContentParent>(mozilla::dom::ContentParent*, unsigned char const*, unsigned long) /home/osboxes/mozilla-central/obj-x86_64-pc-linux-gnu/dist/include/ProtocolFuzzer.h:41:17
#6 0x7fef4799964c in RunContentParentIPCFuzzing(unsigned char const*, unsigned long) /home/osboxes/mozilla-central/dom/ipc/fuzztest/content_parent_ipc_libfuzz.cpp:27:3
#7 0x5e655b in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:517:13
#8 0x5e3754 in fuzzer::Fuzzer::RunOne(unsigned char const*, unsigned long, bool, fuzzer::InputInfo*, bool*) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:442:3
#9 0x5e7db9 in fuzzer::Fuzzer::MutateAndTestOne() /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:650:19
#10 0x5e9fa5 in fuzzer::Fuzzer::Loop(std::vector<std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> >, fuzzer::fuzzer_allocator<std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> > > > const&) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:773:5
#11 0x5cb8fa in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerDriver.cpp:754:6
#12 0x7fef4608488f in mozilla::FuzzerRunner::Run(int*, char***) /home/osboxes/mozilla-central/tools/fuzzing/interface/harness/FuzzerRunner.cpp:60:10
#13 0x7fef45f9b7da in XREMain::XRE_mainStartup(bool*) /home/osboxes/mozilla-central/toolkit/xre/nsAppRunner.cpp:3960:35
#14 0x7fef45fae737 in XREMain::XRE_main(int, char**, mozilla::BootstrapConfig const&) /home/osboxes/mozilla-central/toolkit/xre/nsAppRunner.cpp:4896:12
#15 0x7fef45fb029a in XRE_main(int, char**, mozilla::BootstrapConfig const&) /home/osboxes/mozilla-central/toolkit/xre/nsAppRunner.cpp:5003:21
#16 0x51e145 in do_main(int, char**, char**) /home/osboxes/mozilla-central/browser/app/nsBrowserApp.cpp:231:22
#17 0x51e145 in main /home/osboxes/mozilla-central/browser/app/nsBrowserApp.cpp:304
#18 0x7fef5bb392e0 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x202e0)
#19 0x425559 in _start (/home/osboxes/mozilla-central/obj-x86_64-pc-linux-gnu/dist/bin/firefox+0x425559)
0x61d00027c190 is located 1808 bytes inside of 2144-byte region [0x61d00027ba80,0x61d00027c2e0)
freed by thread T0 here:
#0 0x4e3520 in __interceptor_cfree.localalias.0 (/home/osboxes/mozilla-central/obj-x86_64-pc-linux-gnu/dist/bin/firefox+0x4e3520)
#1 0x7fef47999654 in RunContentParentIPCFuzzing(unsigned char const*, unsigned long) /home/osboxes/mozilla-central/dom/ipc/fuzztest/content_parent_ipc_libfuzz.cpp:28:3
#2 0x5e655b in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:517:13
#3 0x5e3754 in fuzzer::Fuzzer::RunOne(unsigned char const*, unsigned long, bool, fuzzer::InputInfo*, bool*) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:442:3
#4 0x5e7db9 in fuzzer::Fuzzer::MutateAndTestOne() /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:650:19
#5 0x5e9fa5 in fuzzer::Fuzzer::Loop(std::vector<std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> >, fuzzer::fuzzer_allocator<std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> > > > const&) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:773:5
#6 0x5cb8fa in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerDriver.cpp:754:6
#7 0x7fef4608488f in mozilla::FuzzerRunner::Run(int*, char***) /home/osboxes/mozilla-central/tools/fuzzing/interface/harness/FuzzerRunner.cpp:60:10
#8 0x7fef45f9b7da in XREMain::XRE_mainStartup(bool*) /home/osboxes/mozilla-central/toolkit/xre/nsAppRunner.cpp:3960:35
#9 0x7fef45fae737 in XREMain::XRE_main(int, char**, mozilla::BootstrapConfig const&) /home/osboxes/mozilla-central/toolkit/xre/nsAppRunner.cpp:4896:12
#10 0x7fef45fb029a in XRE_main(int, char**, mozilla::BootstrapConfig const&) /home/osboxes/mozilla-central/toolkit/xre/nsAppRunner.cpp:5003:21
#11 0x51e145 in do_main(int, char**, char**) /home/osboxes/mozilla-central/browser/app/nsBrowserApp.cpp:231:22
#12 0x51e145 in main /home/osboxes/mozilla-central/browser/app/nsBrowserApp.cpp:304
#13 0x7fef5bb392e0 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x202e0)
previously allocated by thread T0 here:
#0 0x4e36e8 in malloc (/home/osboxes/mozilla-central/obj-x86_64-pc-linux-gnu/dist/bin/firefox+0x4e36e8)
#1 0x51f29d in moz_xmalloc /home/osboxes/mozilla-central/memory/mozalloc/mozalloc.cpp:70:17
#2 0x7fef46087f35 in operator new(unsigned long) /home/osboxes/mozilla-central/obj-x86_64-pc-linux-gnu/dist/include/mozilla/mozalloc.h:156:12
#3 0x7fef46087f35 in mozilla::ipc::ProtocolFuzzerHelper::CreateContentParent(mozilla::dom::ContentParent*, nsTSubstring<char16_t> const&) /home/osboxes/mozilla-central/tools/fuzzing/ipc/ProtocolFuzzer.cpp:16
#4 0x7fef4799962e in RunContentParentIPCFuzzing(unsigned char const*, unsigned long) /home/osboxes/mozilla-central/dom/ipc/fuzztest/content_parent_ipc_libfuzz.cpp:25:5
#5 0x5e655b in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:517:13
#6 0x5e3754 in fuzzer::Fuzzer::RunOne(unsigned char const*, unsigned long, bool, fuzzer::InputInfo*, bool*) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:442:3
#7 0x5e7db9 in fuzzer::Fuzzer::MutateAndTestOne() /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:650:19
#8 0x5e9fa5 in fuzzer::Fuzzer::Loop(std::vector<std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> >, fuzzer::fuzzer_allocator<std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> > > > const&) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:773:5
#9 0x5cb8fa in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerDriver.cpp:754:6
#10 0x7fef4608488f in mozilla::FuzzerRunner::Run(int*, char***) /home/osboxes/mozilla-central/tools/fuzzing/interface/harness/FuzzerRunner.cpp:60:10
#11 0x7fef45f9b7da in XREMain::XRE_mainStartup(bool*) /home/osboxes/mozilla-central/toolkit/xre/nsAppRunner.cpp:3960:35
#12 0x7fef45fae737 in XREMain::XRE_main(int, char**, mozilla::BootstrapConfig const&) /home/osboxes/mozilla-central/toolkit/xre/nsAppRunner.cpp:4896:12
#13 0x7fef45fb029a in XRE_main(int, char**, mozilla::BootstrapConfig const&) /home/osboxes/mozilla-central/toolkit/xre/nsAppRunner.cpp:5003:21
#14 0x51e145 in do_main(int, char**, char**) /home/osboxes/mozilla-central/browser/app/nsBrowserApp.cpp:231:22
#15 0x51e145 in main /home/osboxes/mozilla-central/browser/app/nsBrowserApp.cpp:304
#16 0x7fef5bb392e0 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x202e0)
SUMMARY: AddressSanitizer: heap-use-after-free /home/osboxes/mozilla-central/toolkit/components/alerts/nsXULAlerts.cpp:148:55 in nsXULAlerts::ShowAlert(nsIAlertNotification*, nsIObserver*)
Shadow bytes around the buggy address:
0x0c3a800477e0: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd
0x0c3a800477f0: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd
0x0c3a80047800: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd
0x0c3a80047810: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd
0x0c3a80047820: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd
=>0x0c3a80047830: fd fd[fd]fd fd fd fd fd fd fd fd fd fd fd fd fd
0x0c3a80047840: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd
0x0c3a80047850: fd fd fd fd fd fd fd fd fd fd fd fd fa fa fa fa
0x0c3a80047860: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
0x0c3a80047870: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
0x0c3a80047880: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
Shadow byte legend (one shadow byte represents 8 application bytes):
Addressable: 00
Partially addressable: 01 02 03 04 05 06 07
Heap left redzone: fa
Freed heap region: fd
Stack left redzone: f1
Stack mid redzone: f2
Stack right redzone: f3
Stack after return: f5
Stack use after scope: f8
Global redzone: f9
Global init order: f6
Poisoned by user: f7
Container overflow: fc
Array cookie: ac
Intra object redzone: bb
ASan internal: fe
Left alloca redzone: ca
Right alloca redzone: cb
==28575==ABORTING
MS: 1 ChangeBinInt-; base unit: d6a57faa36c66875733fd8ba6e394b04f09dbcfe
0x72,0x0,0x0,0x0,0xff,0xff,0xff,0x7f,0xa2,0x0,0x2d,0x0,0x20,0x8,0x0,0x18,0x0,0x0,0x0,0x0,0x2d,0x0,0x0,0x8,0x0,0xe8,0xff,0xff,0xff,0x0,0x6f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x6e,0x73,0x7f,0x0,0x0,0x0,0xff,0xff,0xff,0x7f,0x73,0x0,0x2d,0x49,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7,0xc1,0xff,0xff,0x0,0x14,0x7f,0x0,0x0,0x0,0xff,0xff,0xff,0x7f,0x79,0x0,0x2d,0x0,0x0,0x0,0x0,0x0,0x1c,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xd7,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x2,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0xfb,0x87,0x89,0xff,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x41,0x0,0xa,0x0,0x0,0x0,0x0,0x0,0xff,0xff,0x1,0x60,0xa,0xab,0x0,0xf5,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xff,0x72,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,
r\x00\x00\x00\xff\xff\xff\x7f\xa2\x00-\x00 \x08\x00\x18\x00\x00\x00\x00-\x00\x00\x08\x00\xe8\xff\xff\xff\x00o\x00\x00\x00\x00\x00\x00\x00ns\x7f\x00\x00\x00\xff\xff\xff\x7fs\x00-I\x00\x00\x00\x00\x00\x00\x00\x07\xc1\xff\xff\x00\x14\x7f\x00\x00\x00\xff\xff\xff\x7fy\x00-\x00\x00\x00\x00\x00\x1c\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\xd7\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\xfb\x87\x89\xff\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00A\x00\x0a\x00\x00\x00\x00\x00\xff\xff\x01`\x0a\xab\x00\xf5\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\xffr\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00
artifact_prefix='./'; Test unit written to ./crash-7ed05d227cda6049fdef8524ee0476a62ee38de1
Base64: cgAAAP///3+iAC0AIAgAGAAAAAAtAAAIAOj///8AbwAAAAAAAABuc38AAAD///9/cwAtSQAAAAAAAAAHwf//ABR/AAAA////f3kALQAAAAAAHAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA1wAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEAAAAAAAACAAAAAAAAAAAAAAAAAAABAPuHif8AAAAAAAAAAAAAAEEACgAAAAAA//8BYAqrAPUAAAAAAAAAAAAAAAAA/3IAAAAAAAAAAAAAAAAAAA==
| Reporter | ||
Comment 2•8 years ago
|
||
Here's what the fuzzer looks like, the lifecycle bits are in ProtocolFuzzer.h, ProtocolFuzzer.cpp, and content_parent_ipc_libfuzz.cpp.
| Reporter | ||
Comment 3•8 years ago
|
||
Ok, so what's happening is that a pending alert is queued in |mPendingPersistentAlerts|, and then the content process is destroyed -- and the ContentParent freed with it -- but the pending alert is left there, with the ContentParent referenced in mListenere. Then later on something touches the pending alerts and the UAF occurs.
Since PendingAlert::mListener is an nsCOMPtr, it should keep the ContentParent alive, even if process dies. Does that sound correct?
Is there code that clears out PendingAlerts from different ContentParents when a child process dies, or do they just sit there, pending, forever? My inclination is now that this is really a bug in the lifetime management in my fuzzer, but perhaps there's a memory leak if you've got a pending alert when your process dies.
Updated•8 years ago
|
Flags: needinfo?(agaynor)
| Reporter | ||
Comment 4•8 years ago
|
||
I'm confident this is a false positive. Sorry about the noise!
Status: NEW → RESOLVED
Closed: 8 years ago
Flags: needinfo?(agaynor)
Resolution: --- → INVALID
Updated•6 years ago
|
Group: toolkit-core-security
Updated•3 years ago
|
Product: Toolkit → Toolkit Graveyard
You need to log in
before you can comment on or make changes to this bug.
Description
•