Closed Bug 1535610 Opened 5 years ago Closed 5 years ago

SUMMARY: AddressSanitizer: heap-use-after-free /builds/worker/workspace/build/src/obj-firefox/dist/include/nsWrapperCache.h:162:12 in GetWrapperMaybeDead

Categories

(Core :: CSS Parsing and Computation, defect)

defect
Not set
critical

Tracking

()

RESOLVED DUPLICATE of bug 1535612

People

(Reporter: jkratzer, Unassigned)

References

(Blocks 1 open bug)

Details

(Keywords: crash, csectype-uaf, testcase)

Attachments

(1 file)

Testcase found while fuzzing mozilla-central rev 4d62ab0e31fd.

A build with --enable-fuzzing is required in order to to reproduce this issue.

Group: core-security

Marking as s-s until bug 1535612 is fixed.

Status: NEW → RESOLVED
Closed: 5 years ago
Resolution: --- → DUPLICATE
Attached file testcase.html
Group: core-security
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: