Closed Bug 1718099 Opened 3 years ago Closed 3 years ago

AddressSanitizer: heap-use-after-free [@ GetMozContainer] with READ of size 8 on nsBaseWidget

Categories

(Core :: Widget: Gtk, defect)

x86_64
Linux
defect
Not set
critical

Tracking

()

RESOLVED DUPLICATE of bug 1716796
Tracking Status
firefox90 --- unaffected
firefox91 --- fixed

People

(Reporter: decoder, Unassigned)

Details

(Keywords: crash, csectype-uaf, regression)

Crash Data

Attachments

(1 file)

The attached crash information was submitted via the ASan Nightly Reporter on mozilla-central-asan-nightly revision 91.0a1-20210618092056-https://hg.mozilla.org/mozilla-central/rev/d70c3d846c395717c429cd3f3433457f5f92dced.

For detailed crash information, see attachment.

This was reported anonymously.

Component: General → Widget: Gtk
Crash Signature: [@ GetMozContainer][@ mozilla::widget::WindowSurfaceWayland::FlushPendingCommitsLocked]

Martin: you've been poking around in this file, possibly related to any recent changes?

Group: core-security → core-security-release
Flags: needinfo?(stransky)
Keywords: csectype-uaf

Dupe of 1716796.

Status: NEW → RESOLVED
Closed: 3 years ago
Flags: needinfo?(stransky)
Resolution: --- → DUPLICATE
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: