Closed Bug 1451057 Opened 8 years ago Closed 8 years ago

AddressSanitizer: heap-buffer-overflow mozilla-central/toolkit/components/alerts/nsXULAlerts.cpp:148:55 in nsXULAlerts::ShowAlert(nsIAlertNotification*, nsIObserver*)

Categories

(Toolkit Graveyard :: Notifications and Alerts, defect)

defect
Not set
normal

Tracking

(firefox61 affected)

RESOLVED INVALID
Tracking Status
firefox61 --- affected

People

(Reporter: Alex_Gaynor, Unassigned)

Details

Attachments

(1 file)

This was triggered by a currently in-development IPC fuzzer (so there's a small chance it's actually a bug in the fuzzer, but I believe this is real). I don't yet have a deterministic reproducer for it unfortunately :-( Hopefully the stack-trace is enough to help debug it. Please let me know if there's more that I can share that'd be helpful. ================================================================= ==28102==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x61d00020eb90 at pc 0x7fc74ad30e3b bp 0x7ffe8cd9d550 sp 0x7ffe8cd9d548 READ of size 8 at 0x61d00020eb90 thread T0 #0 0x7fc74ad30e3a in nsXULAlerts::ShowAlert(nsIAlertNotification*, nsIObserver*) /home/osboxes/mozilla-central/toolkit/components/alerts/nsXULAlerts.cpp:148:55 #1 0x7fc74ad2ce7b in (anonymous namespace)::ShowWithBackend(nsIAlertsService*, nsIAlertNotification*, nsIObserver*, nsTSubstring<char16_t> const&) /home/osboxes/mozilla-central/toolkit/components/alerts/nsAlertsService.cpp:140:20 #2 0x7fc74ad2c38f in nsAlertsService::ShowPersistentNotification(nsTSubstring<char16_t> const&, nsIAlertNotification*, nsIObserver*) /home/osboxes/mozilla-central/toolkit/components/alerts/nsAlertsService.cpp:258:10 #3 0x7fc745b3f90a in mozilla::dom::ContentParent::RecvShowAlert(nsIAlertNotification* const&) /home/osboxes/mozilla-central/dom/ipc/ContentParent.cpp:3797:18 #4 0x7fc73e0f9158 in mozilla::dom::PContentParent::OnMessageReceived(IPC::Message const&) /home/osboxes/mozilla-central/obj-x86_64-pc-linux-gnu/ipc/ipdl/PContentParent.cpp:4617:20 #5 0x7fc74ce238de in void mozilla::ipc::FuzzProtocol<mozilla::dom::ContentParent>(mozilla::dom::ContentParent*, unsigned char const*, unsigned long) /home/osboxes/mozilla-central/obj-x86_64-pc-linux-gnu/dist/include/ProtocolFuzzer.h:41:17 #6 0x7fc74ce2364c in RunContentParentIPCFuzzing(unsigned char const*, unsigned long) /home/osboxes/mozilla-central/dom/ipc/fuzztest/content_parent_ipc_libfuzz.cpp:27:3 #7 0x5e655b in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:517:13 #8 0x5e3754 in fuzzer::Fuzzer::RunOne(unsigned char const*, unsigned long, bool, fuzzer::InputInfo*, bool*) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:442:3 #9 0x5e7db9 in fuzzer::Fuzzer::MutateAndTestOne() /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:650:19 #10 0x5e9fa5 in fuzzer::Fuzzer::Loop(std::vector<std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> >, fuzzer::fuzzer_allocator<std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> > > > const&) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:773:5 #11 0x5cb8fa in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerDriver.cpp:754:6 #12 0x7fc74b50e88f in mozilla::FuzzerRunner::Run(int*, char***) /home/osboxes/mozilla-central/tools/fuzzing/interface/harness/FuzzerRunner.cpp:60:10 #13 0x7fc74b4257da in XREMain::XRE_mainStartup(bool*) /home/osboxes/mozilla-central/toolkit/xre/nsAppRunner.cpp:3960:35 #14 0x7fc74b438737 in XREMain::XRE_main(int, char**, mozilla::BootstrapConfig const&) /home/osboxes/mozilla-central/toolkit/xre/nsAppRunner.cpp:4896:12 #15 0x7fc74b43a29a in XRE_main(int, char**, mozilla::BootstrapConfig const&) /home/osboxes/mozilla-central/toolkit/xre/nsAppRunner.cpp:5003:21 #16 0x51e145 in do_main(int, char**, char**) /home/osboxes/mozilla-central/browser/app/nsBrowserApp.cpp:231:22 #17 0x51e145 in main /home/osboxes/mozilla-central/browser/app/nsBrowserApp.cpp:304 #18 0x7fc760fc32e0 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x202e0) #19 0x425559 in _start (/home/osboxes/mozilla-central/obj-x86_64-pc-linux-gnu/dist/bin/firefox+0x425559) Address 0x61d00020eb90 is a wild pointer. SUMMARY: AddressSanitizer: heap-buffer-overflow /home/osboxes/mozilla-central/toolkit/components/alerts/nsXULAlerts.cpp:148:55 in nsXULAlerts::ShowAlert(nsIAlertNotification*, nsIObserver*) Shadow bytes around the buggy address: 0x0c3a80039d20: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa 0x0c3a80039d30: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa 0x0c3a80039d40: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa 0x0c3a80039d50: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa 0x0c3a80039d60: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa =>0x0c3a80039d70: fa fa[fa]fa fa fa fa fa fa fa fa fa fa fa fa fa 0x0c3a80039d80: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa 0x0c3a80039d90: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa 0x0c3a80039da0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa 0x0c3a80039db0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa 0x0c3a80039dc0: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa Shadow byte legend (one shadow byte represents 8 application bytes): Addressable: 00 Partially addressable: 01 02 03 04 05 06 07 Heap left redzone: fa Freed heap region: fd Stack left redzone: f1 Stack mid redzone: f2 Stack right redzone: f3 Stack after return: f5 Stack use after scope: f8 Global redzone: f9 Global init order: f6 Poisoned by user: f7 Container overflow: fc Array cookie: ac Intra object redzone: bb ASan internal: fe Left alloca redzone: ca Right alloca redzone: cb ==28102==ABORTING
Here's a probably-related crash I just encountered. It appears there's a retained reference to a previous ContentParent instance. I suspect there's the possibility my fuzzer isn't deleting itself correctly, but would appreciate an additional perspective: ==28575==ERROR: AddressSanitizer: heap-use-after-free on address 0x61d00027c190 at pc 0x7fef458a6e3b bp 0x7ffc6be85a10 sp 0x7ffc6be85a08 READ of size 8 at 0x61d00027c190 thread T0 #0 0x7fef458a6e3a in nsXULAlerts::ShowAlert(nsIAlertNotification*, nsIObserver*) /home/osboxes/mozilla-central/toolkit/components/alerts/nsXULAlerts.cpp:148:55 #1 0x7fef458a2e7b in (anonymous namespace)::ShowWithBackend(nsIAlertsService*, nsIAlertNotification*, nsIObserver*, nsTSubstring<char16_t> const&) /home/osboxes/mozilla-central/toolkit/components/alerts/nsAlertsService.cpp:140:20 #2 0x7fef458a238f in nsAlertsService::ShowPersistentNotification(nsTSubstring<char16_t> const&, nsIAlertNotification*, nsIObserver*) /home/osboxes/mozilla-central/toolkit/components/alerts/nsAlertsService.cpp:258:10 #3 0x7fef406b590a in mozilla::dom::ContentParent::RecvShowAlert(nsIAlertNotification* const&) /home/osboxes/mozilla-central/dom/ipc/ContentParent.cpp:3797:18 #4 0x7fef38c6f158 in mozilla::dom::PContentParent::OnMessageReceived(IPC::Message const&) /home/osboxes/mozilla-central/obj-x86_64-pc-linux-gnu/ipc/ipdl/PContentParent.cpp:4617:20 #5 0x7fef479998de in void mozilla::ipc::FuzzProtocol<mozilla::dom::ContentParent>(mozilla::dom::ContentParent*, unsigned char const*, unsigned long) /home/osboxes/mozilla-central/obj-x86_64-pc-linux-gnu/dist/include/ProtocolFuzzer.h:41:17 #6 0x7fef4799964c in RunContentParentIPCFuzzing(unsigned char const*, unsigned long) /home/osboxes/mozilla-central/dom/ipc/fuzztest/content_parent_ipc_libfuzz.cpp:27:3 #7 0x5e655b in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:517:13 #8 0x5e3754 in fuzzer::Fuzzer::RunOne(unsigned char const*, unsigned long, bool, fuzzer::InputInfo*, bool*) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:442:3 #9 0x5e7db9 in fuzzer::Fuzzer::MutateAndTestOne() /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:650:19 #10 0x5e9fa5 in fuzzer::Fuzzer::Loop(std::vector<std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> >, fuzzer::fuzzer_allocator<std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> > > > const&) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:773:5 #11 0x5cb8fa in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerDriver.cpp:754:6 #12 0x7fef4608488f in mozilla::FuzzerRunner::Run(int*, char***) /home/osboxes/mozilla-central/tools/fuzzing/interface/harness/FuzzerRunner.cpp:60:10 #13 0x7fef45f9b7da in XREMain::XRE_mainStartup(bool*) /home/osboxes/mozilla-central/toolkit/xre/nsAppRunner.cpp:3960:35 #14 0x7fef45fae737 in XREMain::XRE_main(int, char**, mozilla::BootstrapConfig const&) /home/osboxes/mozilla-central/toolkit/xre/nsAppRunner.cpp:4896:12 #15 0x7fef45fb029a in XRE_main(int, char**, mozilla::BootstrapConfig const&) /home/osboxes/mozilla-central/toolkit/xre/nsAppRunner.cpp:5003:21 #16 0x51e145 in do_main(int, char**, char**) /home/osboxes/mozilla-central/browser/app/nsBrowserApp.cpp:231:22 #17 0x51e145 in main /home/osboxes/mozilla-central/browser/app/nsBrowserApp.cpp:304 #18 0x7fef5bb392e0 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x202e0) #19 0x425559 in _start (/home/osboxes/mozilla-central/obj-x86_64-pc-linux-gnu/dist/bin/firefox+0x425559) 0x61d00027c190 is located 1808 bytes inside of 2144-byte region [0x61d00027ba80,0x61d00027c2e0) freed by thread T0 here: #0 0x4e3520 in __interceptor_cfree.localalias.0 (/home/osboxes/mozilla-central/obj-x86_64-pc-linux-gnu/dist/bin/firefox+0x4e3520) #1 0x7fef47999654 in RunContentParentIPCFuzzing(unsigned char const*, unsigned long) /home/osboxes/mozilla-central/dom/ipc/fuzztest/content_parent_ipc_libfuzz.cpp:28:3 #2 0x5e655b in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:517:13 #3 0x5e3754 in fuzzer::Fuzzer::RunOne(unsigned char const*, unsigned long, bool, fuzzer::InputInfo*, bool*) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:442:3 #4 0x5e7db9 in fuzzer::Fuzzer::MutateAndTestOne() /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:650:19 #5 0x5e9fa5 in fuzzer::Fuzzer::Loop(std::vector<std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> >, fuzzer::fuzzer_allocator<std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> > > > const&) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:773:5 #6 0x5cb8fa in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerDriver.cpp:754:6 #7 0x7fef4608488f in mozilla::FuzzerRunner::Run(int*, char***) /home/osboxes/mozilla-central/tools/fuzzing/interface/harness/FuzzerRunner.cpp:60:10 #8 0x7fef45f9b7da in XREMain::XRE_mainStartup(bool*) /home/osboxes/mozilla-central/toolkit/xre/nsAppRunner.cpp:3960:35 #9 0x7fef45fae737 in XREMain::XRE_main(int, char**, mozilla::BootstrapConfig const&) /home/osboxes/mozilla-central/toolkit/xre/nsAppRunner.cpp:4896:12 #10 0x7fef45fb029a in XRE_main(int, char**, mozilla::BootstrapConfig const&) /home/osboxes/mozilla-central/toolkit/xre/nsAppRunner.cpp:5003:21 #11 0x51e145 in do_main(int, char**, char**) /home/osboxes/mozilla-central/browser/app/nsBrowserApp.cpp:231:22 #12 0x51e145 in main /home/osboxes/mozilla-central/browser/app/nsBrowserApp.cpp:304 #13 0x7fef5bb392e0 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x202e0) previously allocated by thread T0 here: #0 0x4e36e8 in malloc (/home/osboxes/mozilla-central/obj-x86_64-pc-linux-gnu/dist/bin/firefox+0x4e36e8) #1 0x51f29d in moz_xmalloc /home/osboxes/mozilla-central/memory/mozalloc/mozalloc.cpp:70:17 #2 0x7fef46087f35 in operator new(unsigned long) /home/osboxes/mozilla-central/obj-x86_64-pc-linux-gnu/dist/include/mozilla/mozalloc.h:156:12 #3 0x7fef46087f35 in mozilla::ipc::ProtocolFuzzerHelper::CreateContentParent(mozilla::dom::ContentParent*, nsTSubstring<char16_t> const&) /home/osboxes/mozilla-central/tools/fuzzing/ipc/ProtocolFuzzer.cpp:16 #4 0x7fef4799962e in RunContentParentIPCFuzzing(unsigned char const*, unsigned long) /home/osboxes/mozilla-central/dom/ipc/fuzztest/content_parent_ipc_libfuzz.cpp:25:5 #5 0x5e655b in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:517:13 #6 0x5e3754 in fuzzer::Fuzzer::RunOne(unsigned char const*, unsigned long, bool, fuzzer::InputInfo*, bool*) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:442:3 #7 0x5e7db9 in fuzzer::Fuzzer::MutateAndTestOne() /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:650:19 #8 0x5e9fa5 in fuzzer::Fuzzer::Loop(std::vector<std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> >, fuzzer::fuzzer_allocator<std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> > > > const&) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerLoop.cpp:773:5 #9 0x5cb8fa in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) /home/osboxes/mozilla-central/tools/fuzzing/libfuzzer/FuzzerDriver.cpp:754:6 #10 0x7fef4608488f in mozilla::FuzzerRunner::Run(int*, char***) /home/osboxes/mozilla-central/tools/fuzzing/interface/harness/FuzzerRunner.cpp:60:10 #11 0x7fef45f9b7da in XREMain::XRE_mainStartup(bool*) /home/osboxes/mozilla-central/toolkit/xre/nsAppRunner.cpp:3960:35 #12 0x7fef45fae737 in XREMain::XRE_main(int, char**, mozilla::BootstrapConfig const&) /home/osboxes/mozilla-central/toolkit/xre/nsAppRunner.cpp:4896:12 #13 0x7fef45fb029a in XRE_main(int, char**, mozilla::BootstrapConfig const&) /home/osboxes/mozilla-central/toolkit/xre/nsAppRunner.cpp:5003:21 #14 0x51e145 in do_main(int, char**, char**) /home/osboxes/mozilla-central/browser/app/nsBrowserApp.cpp:231:22 #15 0x51e145 in main /home/osboxes/mozilla-central/browser/app/nsBrowserApp.cpp:304 #16 0x7fef5bb392e0 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x202e0) SUMMARY: AddressSanitizer: heap-use-after-free /home/osboxes/mozilla-central/toolkit/components/alerts/nsXULAlerts.cpp:148:55 in nsXULAlerts::ShowAlert(nsIAlertNotification*, nsIObserver*) Shadow bytes around the buggy address: 0x0c3a800477e0: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd 0x0c3a800477f0: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd 0x0c3a80047800: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd 0x0c3a80047810: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd 0x0c3a80047820: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd =>0x0c3a80047830: fd fd[fd]fd fd fd fd fd fd fd fd fd fd fd fd fd 0x0c3a80047840: fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd fd 0x0c3a80047850: fd fd fd fd fd fd fd fd fd fd fd fd fa fa fa fa 0x0c3a80047860: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa 0x0c3a80047870: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa 0x0c3a80047880: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa Shadow byte legend (one shadow byte represents 8 application bytes): Addressable: 00 Partially addressable: 01 02 03 04 05 06 07 Heap left redzone: fa Freed heap region: fd Stack left redzone: f1 Stack mid redzone: f2 Stack right redzone: f3 Stack after return: f5 Stack use after scope: f8 Global redzone: f9 Global init order: f6 Poisoned by user: f7 Container overflow: fc Array cookie: ac Intra object redzone: bb ASan internal: fe Left alloca redzone: ca Right alloca redzone: cb ==28575==ABORTING MS: 1 ChangeBinInt-; base unit: d6a57faa36c66875733fd8ba6e394b04f09dbcfe 0x72,0x0,0x0,0x0,0xff,0xff,0xff,0x7f,0xa2,0x0,0x2d,0x0,0x20,0x8,0x0,0x18,0x0,0x0,0x0,0x0,0x2d,0x0,0x0,0x8,0x0,0xe8,0xff,0xff,0xff,0x0,0x6f,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x6e,0x73,0x7f,0x0,0x0,0x0,0xff,0xff,0xff,0x7f,0x73,0x0,0x2d,0x49,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x7,0xc1,0xff,0xff,0x0,0x14,0x7f,0x0,0x0,0x0,0xff,0xff,0xff,0x7f,0x79,0x0,0x2d,0x0,0x0,0x0,0x0,0x0,0x1c,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xd7,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0x0,0x0,0x0,0x0,0x0,0x2,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x1,0x0,0xfb,0x87,0x89,0xff,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x41,0x0,0xa,0x0,0x0,0x0,0x0,0x0,0xff,0xff,0x1,0x60,0xa,0xab,0x0,0xf5,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0xff,0x72,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0,0x0, r\x00\x00\x00\xff\xff\xff\x7f\xa2\x00-\x00 \x08\x00\x18\x00\x00\x00\x00-\x00\x00\x08\x00\xe8\xff\xff\xff\x00o\x00\x00\x00\x00\x00\x00\x00ns\x7f\x00\x00\x00\xff\xff\xff\x7fs\x00-I\x00\x00\x00\x00\x00\x00\x00\x07\xc1\xff\xff\x00\x14\x7f\x00\x00\x00\xff\xff\xff\x7fy\x00-\x00\x00\x00\x00\x00\x1c\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\xd7\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\xfb\x87\x89\xff\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00A\x00\x0a\x00\x00\x00\x00\x00\xff\xff\x01`\x0a\xab\x00\xf5\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\xffr\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00 artifact_prefix='./'; Test unit written to ./crash-7ed05d227cda6049fdef8524ee0476a62ee38de1 Base64: cgAAAP///3+iAC0AIAgAGAAAAAAtAAAIAOj///8AbwAAAAAAAABuc38AAAD///9/cwAtSQAAAAAAAAAHwf//ABR/AAAA////f3kALQAAAAAAHAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA1wAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEAAAAAAAACAAAAAAAAAAAAAAAAAAABAPuHif8AAAAAAAAAAAAAAEEACgAAAAAA//8BYAqrAPUAAAAAAAAAAAAAAAAA/3IAAAAAAAAAAAAAAAAAAA==
Attached patch fuzzer.diffSplinter Review
Here's what the fuzzer looks like, the lifecycle bits are in ProtocolFuzzer.h, ProtocolFuzzer.cpp, and content_parent_ipc_libfuzz.cpp.
Ok, so what's happening is that a pending alert is queued in |mPendingPersistentAlerts|, and then the content process is destroyed -- and the ContentParent freed with it -- but the pending alert is left there, with the ContentParent referenced in mListenere. Then later on something touches the pending alerts and the UAF occurs. Since PendingAlert::mListener is an nsCOMPtr, it should keep the ContentParent alive, even if process dies. Does that sound correct? Is there code that clears out PendingAlerts from different ContentParents when a child process dies, or do they just sit there, pending, forever? My inclination is now that this is really a bug in the lifetime management in my fuzzer, but perhaps there's a memory leak if you've got a pending alert when your process dies.
Flags: needinfo?(agaynor)
I'm confident this is a false positive. Sorry about the noise!
Status: NEW → RESOLVED
Closed: 8 years ago
Flags: needinfo?(agaynor)
Resolution: --- → INVALID
Group: toolkit-core-security
Product: Toolkit → Toolkit Graveyard
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: