Closed Bug 1646104 Opened 5 years ago Closed 5 years ago

AddressSanitizer: heap-use-after-free [@ mozilla::a11y::DocAccessibleChild::GetNativeWindowHandle] with READ of size 8

Categories

(Core :: Disability Access APIs, defect)

x86_64
Windows
defect

Tracking

()

RESOLVED DUPLICATE of bug 1645067
Tracking Status
firefox79 --- fixed

People

(Reporter: decoder, Unassigned)

Details

(4 keywords)

Attachments

(1 file)

The attached crash information was submitted via the ASan Nightly Reporter on mozilla-central-asan-nightly revision 79.0a1-20200612094620-https://hg.mozilla.org/mozilla-central/rev/fea1e502ea281a9b86b821957e622f0b0d081ce7.

For detailed crash information, see attachment.

Flags: sec-bounty?
Group: core-security → dom-core-security

Jamie, could you please take a look? It looks like the code around the use was changed recently in bug 1644323.

It looks like that code is calling a method on a DocAccessibleChild from a runnable, and that DocAccessibleChild was freed. Before bug 1644323, that code called a method on BrowserChild, so maybe it is a regression.

Flags: needinfo?(jteh)
Keywords: csectype-uaf

This is a duplicate of bug 1645067, which I already fixed, but the fix landed just after the revision tested here.

Is it safe for me to close this as a dup?

Flags: needinfo?(jteh) → needinfo?(continuation)

Yes, duplicating it over is fine. I'll just do that. Thanks.

Status: NEW → RESOLVED
Closed: 5 years ago
Flags: needinfo?(continuation)
Resolution: --- → DUPLICATE

What was the first submission date for the ASAN report? It might be within the dupe window. (In the future, it would be good to include that in the private comment with the reporter.)

Flags: needinfo?(choller)

(In reply to Tom Ritter [:tjr] (ni for response to sec-[approval|rating|advisories|cve]) from comment #6)

What was the first submission date for the ASAN report? It might be within the dupe window. (In the future, it would be good to include that in the private comment with the reporter.)

First report was received at Fri, 12 Jun 2020 19:18:10 +0000.

Flags: needinfo?(choller)
Group: dom-core-security
Flags: sec-bounty? → sec-bounty-
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: