Closed Bug 1516179 Opened 7 years ago Closed 7 years ago

UAF (read) in mozilla::BackgroundHangAnnotators::GatherAnnotations()

Categories

(Core :: Performance: General, defect)

defect
Not set
normal

Tracking

()

RESOLVED FIXED
mozilla66
Tracking Status
firefox-esr60 --- wontfix
firefox64 --- wontfix
firefox65 --- wontfix
firefox66 --- fixed

People

(Reporter: jseward, Assigned: nika)

Details

(Keywords: csectype-uaf, sec-moderate, Whiteboard: [post-critsmash-triage][adv-main66+])

Attachments

(2 files)

I've noticed this several times in the past couple of weeks, when running Fx on Valgrind. I think it happens when a content process quits, but am not sure.
Flags: needinfo?(nika)
Attached file V complainage
Flags: needinfo?(nika)
This sounds like some kind of shutdown race so it doesn't sound too severe.
Assignee: nobody → nika
Group: core-security → core-security-release
Status: NEW → RESOLVED
Closed: 7 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla66

Is this something we should consider backporting or can it ride the trains?

Flags: needinfo?(nika)

Should be pretty harmless to backport, but it doesn't seem super bad, so can probably ride the trains.

Flags: needinfo?(nika)
Flags: qe-verify-
Whiteboard: [post-critsmash-triage]
Whiteboard: [post-critsmash-triage] → [post-critsmash-triage][adv-main66+]
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: