Closed Bug 1555838 (CVE-2019-5849) Opened 5 years ago Closed 5 years ago

Skia: OOB Read in ReflexHash::checkTriangle

Categories

(Core :: Graphics, defect, P2)

defect

Tracking

()

RESOLVED FIXED
mozilla69
Tracking Status
firefox-esr60 --- wontfix
firefox-esr68 --- wontfix
firefox68 --- wontfix
firefox69 --- fixed

People

(Reporter: dveditz, Assigned: lsalzman)

References

Details

(Keywords: csectype-bounds, sec-moderate, Whiteboard: [post-critsmash-triage][adv-main69+])

Attachments

(1 file)

A patch in Chrome for Skia went into the upcoming Chrome 76, described as "OOB Read in ReflexHash::checkTriangle" and medium security severity. The patch was elsewhere and I don't have a testcase that points to that location. Fixed in the following patch:

https://skia.googlesource.com/skia/+/a5ef39726a7b8e54d295aa8336e7d874bc33f436

Flags: needinfo?(lsalzman)
Priority: -- → P2
Flags: needinfo?(lsalzman)

I don't believe we use the shadow code affected by this patch, but just in case there is no harm in cherrypicking this.

There's a r+ patch which didn't land and no activity in this bug for 2 weeks.
:lsalzman, could you have a look please?
For more information, please visit auto_nag documentation.

Flags: needinfo?(lsalzman)
Flags: needinfo?(lsalzman)
Group: gfx-core-security → core-security-release
Status: NEW → RESOLVED
Closed: 5 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla69
Assignee: nobody → lsalzman
Flags: qe-verify-
Whiteboard: [post-critsmash-triage]

Is this something we need to backport to ESR68 for the 68.1esr release? Given the severity and where we are in the life cycle, I'm assuming we can skip ESR60.

Flags: needinfo?(lsalzman)

(In reply to Ryan VanderMeulen [:RyanVM] from comment #5)

Is this something we need to backport to ESR68 for the 68.1esr release? Given the severity and where we are in the life cycle, I'm assuming we can skip ESR60.

I believe we are safe for now if we don't backport, as we don't seem to be using this code.

Flags: needinfo?(lsalzman)

Google assigned CVE-2019-5849 to this Skia flaw.

Alias: CVE-2019-5849
Whiteboard: [post-critsmash-triage] → [post-critsmash-triage][adv-main69+]
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: