Closed Bug 1757715 Opened 3 years ago Closed 3 years ago

AddressSanitizer: heap-use-after-free [@ OnNonDOMMutationRenderingChange] with WRITE of size 1 through SVG

Categories

(Core :: SVG, defect)

x86_64
Linux
defect

Tracking

()

RESOLVED DUPLICATE of bug 1736243

People

(Reporter: decoder, Unassigned)

Details

(4 keywords)

Attachments

(1 file)

The attached crash information was submitted via the ASan Nightly Reporter on mozilla-central-asan-nightly revision 95.0a1-20211017092521-https://hg.mozilla.org/mozilla-central/rev/650d84a601ba81d47e31d8fcb66a6d84642ae00d.

For detailed crash information, see attachment.

I received this report a few days ago, but the version used here is very old (Nightly from October last year). Since this is a use-after-free, it might still be worth checking if this is fixed.

Possible duplicate of bug 1736243?

Group: core-security → dom-core-security
Flags: needinfo?(emilio)

Yes, almost surely.

Status: NEW → RESOLVED
Closed: 3 years ago
Flags: needinfo?(emilio)
Resolution: --- → DUPLICATE
Group: dom-core-security
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: