crash at [@ atidxx64.dll | CContext::TID3D11DeviceContext_ClearRenderTargetView_<T> ]
Categories
(Core :: Graphics, defect)
Tracking
()
People
(Reporter: alisyarief.404, Unassigned)
Details
(6 keywords, Whiteboard: [reporter-external] [client-bounty-form] [verif?])
Crash Data
Attachments
(4 files)
Crash report:
https://crash-stats.mozilla.org/report/index/0888fe14-6a0f-4407-9721-7031b0230616#tab-bugzilla
in Asan Error :
JavaScript error: resource://devtools/server/actors/resources/parent-process-document-event.js, line 90: TypeError: can't access property "innerWindowId", webProgress.browsingContext.currentWindowGlobal is null
Comment 1•2 years ago
|
||
The crash report is a null deref crash inside the graphics drivers, in the GPU process.
Do you have a test case that can be used to reproduce the issue?
Updated•2 years ago
|
Filing as security sensitive exploitable since the address indicates UAF:
Crash Reason EXCEPTION_ACCESS_VIOLATION_READ
Crash Address 0x0000000000000060
Thanks
Comment 5•2 years ago
|
||
Could you attach the output of about:support for your machine?
Updated•2 years ago
|
Comment 8•2 years ago
|
||
Thanks. I see that the driver is from 2022:
Driver Version: 31.0.12042.4
Driver Date: 10-19-2022
Would it be possible to try update the driver and see if the bug is still reproducible?
im testing in update driver
the bug not reproducible
But not all user update driver in PC/laptop
Thanks
| Reporter | ||
Comment 10•2 years ago
|
||
im check in second laptop driver is 2022 but not notification update driver in laptop
if default BYOD Laptop many driver amd or nvidia 2021 or 2022 which is still active
| Reporter | ||
Comment 11•2 years ago
|
||
Im testing in
Nightly Version : 116.0a1 (2023-06-18) (64-bit)
Eror : Crash Tab
Poc In Attachment
| Reporter | ||
Comment 12•2 years ago
|
||
Any update for this report ?
This finding is valid ?
Comment 13•2 years ago
|
||
The memtest.html is just exhausting memory, and something has to give on the system. It sounds like the new driver is different (maybe possibly better-behaved in this case), but that overall this is just something crashing in response to OOM, which is just a known DOS vector.
Updated•2 years ago
|
Updated•2 years ago
|
Updated•2 years ago
|
Updated•1 year ago
|
Description
•