Closed Bug 1845348 Opened 1 year ago Closed 1 year ago

Crash in [@ nsCOMPtr<T>::~nsCOMPtr | mozilla::SegmentedVector<T>::SegmentImpl<T>::PopLast]

Categories

(Core :: XPCOM, defect)

Unspecified
All
defect

Tracking

()

RESOLVED DUPLICATE of bug 1045992

People

(Reporter: aryx, Unassigned)

Details

(Keywords: crash)

Crash Data

Crash signature new in Firefox 115, ~150 crashes from ~100 installations. Some have the use-after-free address. A search for SegmentVector did not find any bugs for similar signatures.

Crash report: https://crash-stats.mozilla.org/report/index/488e3789-da2c-4e39-b9b1-e868a0230725

Reason: EXCEPTION_ACCESS_VIOLATION_READ

Top 10 frames of crashing thread:

0  xul.dll  nsCOMPtr<nsISupports>::~nsCOMPtr  xpcom/base/nsCOMPtr.h:340
0  xul.dll  mozilla::SegmentedVector<nsCOMPtr<nsISupports>, 4096, mozilla::MallocAllocPolicy>::SegmentImpl<508>::PopLast  mfbt/SegmentedVector.h:107
0  xul.dll  mozilla::SegmentedVector<nsCOMPtr<nsISupports>, 4096, mozilla::MallocAllocPolicy>::PopLastN  mfbt/SegmentedVector.h:262
0  xul.dll  mozilla::dom::DeferredFinalizerImpl<nsISupports>::DeferredFinalize  dom/bindings/BindingUtils.h:2804
1  xul.dll  mozilla::IncrementalFinalizeRunnable::ReleaseNow  xpcom/base/CycleCollectedJSRuntime.cpp:1716
2  xul.dll  mozilla::IncrementalFinalizeRunnable::Run  xpcom/base/CycleCollectedJSRuntime.cpp:1753
3  xul.dll  mozilla::RunnableTask::Run  xpcom/threads/TaskController.cpp:555
3  xul.dll  mozilla::TaskController::DoExecuteNextTaskOnlyMainThreadInternal  xpcom/threads/TaskController.cpp:879
4  xul.dll  mozilla::TaskController::ExecuteNextTaskOnlyMainThreadInternal  xpcom/threads/TaskController.cpp:702
4  xul.dll  mozilla::TaskController::ProcessPendingMTTask  xpcom/threads/TaskController.cpp:491

I filed bug 1845173 about improving the signature for these crashes.

Group: core-security
Status: NEW → RESOLVED
Closed: 1 year ago
Duplicate of bug: 1045992
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.