Closed Bug 967522 Opened 6 years ago Closed 6 years ago

Faulty crash: too big nsTArray<Animation> in PLayerTransactionParent::Read

Categories

(Core :: Graphics, defect)

x86_64
Linux
defect
Not set

Tracking

()

RESOLVED DUPLICATE of bug 967167

People

(Reporter: bjacob, Unassigned)

References

(Blocks 1 open bug)

Details

Attachments

(1 file)

Attached file Faulty session
Found by Christoph Diehl's "Faulty" fuzzer, see bug 777067
Summary: Faulty crash: nsTArrayInfallibleAllocator::SizeTooBig, in PLayerTransactionParent::Read → Faulty crash: too big nsTArray<Animation> in PLayerTransactionParent::Read
Status: NEW → RESOLVED
Closed: 6 years ago
Resolution: --- → DUPLICATE
Duplicate of bug: ipc-big-arrays
You need to log in before you can comment on or make changes to this bug.