Closed Bug 987933 Opened 11 years ago Closed 10 years ago

OOM: inlineScriptedCall() forgets to check TypeSet::clone() return

Categories

(Core :: JavaScript Engine, defect)

x86_64
Linux
defect
Not set
normal

Tracking

()

RESOLVED WORKSFORME

People

(Reporter: sstangl, Unassigned)

References

(Blocks 1 open bug)

Details

(Keywords: sec-other)

Attachments

(1 file)

Simple thinko. Testcase from decoder (js__jit__MTypeBarrier__MTypeBarrier.txt). Probably not exploitable.
Setting to sec-other per comment 0. Feel free to adjust.
Keywords: sec-other
Comment on attachment 8396640 [details] [diff] [review] patch Apparently I requested review from myself on this patch? It's been fixed in the meantime.
Attachment #8396640 - Flags: review?
Status: NEW → RESOLVED
Closed: 10 years ago
Resolution: --- → WORKSFORME
Group: core-security → core-security-release
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: