Poison Arena zone pointer on free to highlight UAF crashes in crash data

RESOLVED FIXED in Firefox 68

Status

()

task
P1
normal
RESOLVED FIXED
Last month
13 days ago

People

(Reporter: jonco, Assigned: jonco)

Tracking

Trunk
mozilla69
Points:
---

Firefox Tracking Flags

(firefox68 fixed, firefox69 fixed)

Details

Attachments

(1 attachment)

Assignee

Description

Last month

As suggested by Steve in bug 1474623.

Attachment #9065463 - Attachment description: Bug 1552180 - Poison Arena's zone pointer on free r=sfink? → Bug 1552180 - Poison Arena's zone pointer on free r=sfink

Comment 2

Last month
Pushed by jcoppeard@mozilla.com:
https://hg.mozilla.org/integration/mozilla-inbound/rev/882b70f3e477
Poison Arena's zone pointer on free r=sfink

Comment 3

Last month
bugherder
Status: NEW → RESOLVED
Closed: Last month
Resolution: --- → FIXED
Target Milestone: --- → mozilla69

Is this something we should backport to 68 ahead of the next ESR?

Flags: needinfo?(jcoppeard)
Assignee

Comment 5

13 days ago

Comment on attachment 9065463 [details]
Bug 1552180 - Poison Arena's zone pointer on free r=sfink

Beta/Release Uplift Approval Request

  • User impact if declined: Requesting uplift because this may make help shed light on some types of crashes.
  • Is this code covered by automated tests?: Yes
  • Has the fix been verified in Nightly?: Yes
  • Needs manual test from QE?: No
  • If yes, steps to reproduce:
  • List of other uplifts needed: None
  • Risk to taking this patch: Low
  • Why is the change risky/not risky? (and alternatives if risky): This is a simple change and has baked on trunk for > 20 days.
  • String changes made/needed: None.
Flags: needinfo?(jcoppeard)
Attachment #9065463 - Flags: approval-mozilla-beta?

Comment on attachment 9065463 [details]
Bug 1552180 - Poison Arena's zone pointer on free r=sfink

approved for 68.0b10

Attachment #9065463 - Flags: approval-mozilla-beta? → approval-mozilla-beta+
You need to log in before you can comment on or make changes to this bug.