[webkit-changes] [WebKit/WebKit] e87ab3: jsc_fuz/wktr: null ptr deref in WebCore::writeReso...

lericaa noreply at github.com
Tue Jan 16 20:48:18 PST 2024


  Branch: refs/heads/main
  Home:   https://github.com/WebKit/WebKit
  Commit: e87ab3954b6a74b7528e7ec618033367c7f770ea
      https://github.com/WebKit/WebKit/commit/e87ab3954b6a74b7528e7ec618033367c7f770ea
  Author: Erica Li <lerica at apple.com>
  Date:   2024-01-16 (Tue, 16 Jan 2024)

  Changed paths:
    A LayoutTests/svg/css/svg-write-resources-null-maskImage-crash-expected.html
    A LayoutTests/svg/css/svg-write-resources-null-maskImage-crash.html
    M Source/WebCore/rendering/svg/SVGRenderTreeAsText.cpp

  Log Message:
  -----------
  jsc_fuz/wktr: null ptr deref in WebCore::writeResources(WTF::TextStream&, WebCore::RenderObject const&, WTF::OptionSet<WebCore::RenderAsTextFlag>) + 116 (SVGRenderTreeAsText.cpp:595)
https://bugs.webkit.org/show_bug.cgi?id=267528
rdar://120991613

Reviewed by Nikolas Zimmermann.

Add null check for maskImage in WebCore::writeResources also.

* LayoutTests/svg/css/svg-write-resources-null-maskImage-crash-expected.html: Added.
* LayoutTests/svg/css/svg-write-resources-null-maskImage-crash.html: Added.
* Source/WebCore/rendering/svg/SVGRenderTreeAsText.cpp:
(WebCore::writeResources):

Canonical link: https://commits.webkit.org/273111@main




More information about the webkit-changes mailing list