Closed
Bug 1713572
Opened 4 years ago
Closed 4 years ago
AddressSanitizer: heap-use-after-free [@ mozilla::ProfilerParentTracker::~ProfilerParentTracker] with READ of size 1
Categories
(Core :: Gecko Profiler, defect, P2)
Tracking
()
RESOLVED
DUPLICATE
of bug 1712253
| Tracking | Status | |
|---|---|---|
| firefox90 | --- | affected |
People
(Reporter: decoder, Assigned: mozbugz)
Details
(4 keywords)
Attachments
(1 file)
|
14.87 KB,
text/plain
|
Details |
The attached crash information was submitted via the ASan Nightly Reporter on mozilla-central-asan-nightly revision 90.0a1-20210522213852-https://hg.mozilla.org/mozilla-central/rev/060be6dd7a95f5b33a8a5a1a70bba25cc5acf4e7.
For detailed crash information, see attachment.
This issue was submitted anonymously.
| Reporter | ||
Comment 1•4 years ago
|
||
Updated•4 years ago
|
Component: General → Gecko Profiler
Comment 2•4 years ago
|
||
It looks like ProfilerParentTracker has a raw pointer to a ProfilerParent. Maybe there's some actor weak reference that could be used here?
Comment 3•4 years ago
|
||
This is a shutdown race involving the profiler, so I'll mark it sec-moderate.
Group: core-security → dom-core-security
Keywords: csectype-uaf,
sec-moderate
| Assignee | ||
Comment 4•4 years ago
|
||
Thank you for the report. Fortunately, we got a similar ASAN report (bug 1712253) and that has already fixed with a back-out of bug 1710015 in 90.0a1-20210524084213.
Assignee: nobody → gsquelart
Status: NEW → RESOLVED
Closed: 4 years ago
Priority: -- → P2
Resolution: --- → DUPLICATE
Updated•1 year ago
|
Group: dom-core-security
You need to log in
before you can comment on or make changes to this bug.
Description
•