Closed Bug 1590068 Opened 5 years ago Closed 2 years ago

Land fuzzing target for StructuredCloneData

Categories

(Core :: DOM: Content Processes, enhancement, P2)

x86_64
Linux
enhancement

Tracking

()

RESOLVED FIXED
97 Branch
Tracking Status
firefox-esr91 --- wontfix
firefox72 --- wontfix
firefox95 --- wontfix
firefox96 --- wontfix
firefox97 --- fixed

People

(Reporter: decoder, Assigned: decoder)

References

Details

(Keywords: sec-want, Whiteboard: [post-critsmash-triage][adv-main97-])

Attachments

(1 file)

We are currently testing StructuredCloneReader in the JS engine, but it is also used outside of JS for IPC via StructuredCloneData. Bugs in the deserialization can result in exploitable sandbox escapes and/or parent crashes.

This bug is about adding a fuzzing target for StructuredCloneData outside of JS.

Depends on: 1590066
Component: IPC → DOM: Content Processes
Priority: -- → P2
Depends on: 1736046
Depends on: 1739366
Flags: qe-verify-
Whiteboard: [post-critsmash-triage]
Whiteboard: [post-critsmash-triage] → [post-critsmash-triage][adv-main97-]
Group: core-security-release
Depends on: 1790555
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: