Closed Bug 1595467 Opened 5 years ago Closed 5 years ago

AddressSanitizer: heap-use-after-free [@ WaylandDMABufSurface::Resize] with READ of size 4

Categories

(Core :: Widget: Gtk, defect)

x86_64
Linux
defect
Not set
critical

Tracking

()

RESOLVED DUPLICATE of bug 1588579
Tracking Status
firefox72 --- fixed

People

(Reporter: decoder, Unassigned)

Details

(4 keywords, Whiteboard: [adv-main72-])

Attachments

(1 file)

The attached crash information was submitted via the ASan Nightly Reporter on mozilla-central-asan-nightly revision 72.0a1-20191108213609-https://hg.mozilla.org/mozilla-central/rev/f414b9e6d85710f92649566c1c6511265dadd476.

For detailed crash information, see attachment.

Flags: sec-bounty?
Group: core-security → layout-core-security

Martin, would you mind taking a look? Thanks.

Flags: needinfo?(stransky)

This looks like a dupe of Bug 1588579. Also mozilla::widget::WindowSurfaceWayland::GetWaylandBufferToDraw() is not present in recent codebase, see
https://dxr.mozilla.org/mozilla-central/source/widget/gtk/WindowSurfaceWayland.cpp#722

Flags: needinfo?(stransky)
Status: NEW → RESOLVED
Closed: 5 years ago
Resolution: --- → DUPLICATE
Flags: sec-bounty? → sec-bounty-
Whiteboard: [adv-main72-]
Group: layout-core-security → dom-core-security
Group: dom-core-security
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: