Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(127)

Issue 2276053002: Fix use-after-free in the renderer process. (Closed)

Created:
4 years, 4 months ago by lfg
Modified:
4 years, 4 months ago
Reviewers:
Charlie Reis
CC:
chromium-reviews, nasko+codewatch_chromium.org, mlamouri+watch-content_chromium.org, jam, darin-cc_chromium.org, creis+watch_chromium.org, site-isolation-reviews_chromium.org
Base URL:
https://chromium.googlesource.com/chromium/src.git@master
Target Ref:
refs/pending/heads/master
Project:
chromium
Visibility:
Public.

Description

Fix use-after-free in the renderer process. If a frame that contains the focused plugin is destroyed, we leave a dangling pointer in the RenderWidget. BUG=640733 Committed: https://crrev.com/4eb5bd96518311cc565323e59f08c6cfc140dcae Cr-Commit-Position: refs/heads/master@{#414176}

Patch Set 1 #

Patch Set 2 : adding ifdef #

Total comments: 1
Unified diffs Side-by-side diffs Delta from patch set Stats (+5 lines, -0 lines) Patch
M content/renderer/render_frame_impl.cc View 1 1 chunk +5 lines, -0 lines 1 comment Download

Messages

Total messages: 25 (14 generated)
lfg
Charlie, please take a look.
4 years, 4 months ago (2016-08-24 17:51:51 UTC) #8
Charlie Reis
Thanks for catching this. I assume we don't have repro steps and you just found ...
4 years, 4 months ago (2016-08-24 20:38:44 UTC) #10
lfg
On 2016/08/24 20:38:44, Charlie Reis (OOO til 8-30) wrote: > Thanks for catching this. > ...
4 years, 4 months ago (2016-08-24 21:05:41 UTC) #14
lfg
On 2016/08/24 21:05:41, lfg wrote: > On 2016/08/24 20:38:44, Charlie Reis (OOO til 8-30) wrote: ...
4 years, 4 months ago (2016-08-24 21:06:13 UTC) #15
Charlie Reis
On 2016/08/24 21:05:41, lfg wrote: > On 2016/08/24 20:38:44, Charlie Reis (OOO til 8-30) wrote: ...
4 years, 4 months ago (2016-08-24 21:18:26 UTC) #16
lfg
On 2016/08/24 21:18:26, Charlie Reis (OOO til 8-30) wrote: > Is there any chance the ...
4 years, 4 months ago (2016-08-24 21:26:37 UTC) #17
Charlie Reis
On 2016/08/24 21:26:37, lfg wrote: > On 2016/08/24 21:18:26, Charlie Reis (OOO til 8-30) wrote: ...
4 years, 4 months ago (2016-08-24 22:19:05 UTC) #18
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/v2/patch-status/codereview.chromium.org/2276053002/20001
4 years, 4 months ago (2016-08-24 22:21:23 UTC) #20
EhsanK
On 2016/08/24 22:19:05, Charlie Reis (OOO til 8-30) wrote: > On 2016/08/24 21:26:37, lfg wrote: ...
4 years, 4 months ago (2016-08-24 22:35:52 UTC) #21
commit-bot: I haz the power
Committed patchset #2 (id:20001)
4 years, 4 months ago (2016-08-24 22:37:55 UTC) #23
commit-bot: I haz the power
4 years, 4 months ago (2016-08-24 22:40:03 UTC) #25
Message was sent while issue was closed.
Patchset 2 (id:??) landed as
https://crrev.com/4eb5bd96518311cc565323e59f08c6cfc140dcae
Cr-Commit-Position: refs/heads/master@{#414176}

Powered by Google App Engine
This is Rietveld 408576698