Open Bug 1625187 Opened 4 years ago Updated 3 years ago

RustMozCrash through nsPlaceholderFrame::GetParentComputedStyleForOutOfFlow()

Categories

(Core :: Layout, defect, P3)

defect

Tracking

()

People

(Reporter: tarafans7, Unassigned)

References

(Depends on 1 open bug)

Details

Attachments

(2 files)

User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36

Steps to reproduce:

A bug found in Nightly by fuzzing. PoC and ASAN log are attached.
I used the official ASAN build on Mar 25 and reproduced with ffpuppet.

Reported by Wen Xu from sslab, gatech

Attached file PoC

This may be an intentional crash and not a security issue. Emilio, can you take a look?

Group: firefox-core-security → layout-core-security
Component: Untriaged → Layout
Flags: needinfo?(emilio)
Product: Firefox → Core

Yes. I don't think it's a security, issue, it's a rust panic due to ::first-line being broken.

Status: UNCONFIRMED → NEW
Depends on: 1465474
Ever confirmed: true
Flags: needinfo?(emilio)
Group: layout-core-security
Priority: -- → P3

Because this bug's Severity has not been changed from the default since it was filed, and it's Priority is P3 (Backlog,) indicating it has been triaged, the bug's Severity is being updated to S3 (normal.)

Severity: normal → S3
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: