Closed Bug 1507696 Opened 2 years ago Closed 1 year ago
ANGLE crash in copy
Tex Sub Image from a 2d _array
Crash bug, passing -1 where we expect a small positive number. Hopefully just sec-dos. ANGLE is *full* of bugs in this code, it seems like. Also WebRender wants to use this codepath. Oops.
r12 has the UAF marker in it -- interesting. Does a UAF from passing a -1 make sense?
Quite possibly, yeah.
Attachment #9074364 - Flags: sec-approval? → sec-approval+
Status: ASSIGNED → RESOLVED
Closed: 1 year ago
Resolution: --- → FIXED
Comment on attachment 9074637 [details] [diff] [review] beta68 backport Fixes a webgl sec issue by cherry-picking an upstream fix. Approved for 68rc1.
Attachment #9074637 - Flags: approval-mozilla-beta? → approval-mozilla-beta+
Whiteboard: gfx-noted → gfx-noted[post-critsmash-triage]
Whiteboard: gfx-noted[post-critsmash-triage] → gfx-noted[post-critsmash-triage][adv-main68+]
You need to log in before you can comment on or make changes to this bug.