[Webkit-unassigned] [Bug 185645] New: null pointer in JSC::jsSubstringOfResolved

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Tue May 15 01:16:52 PDT 2018


https://bugs.webkit.org/show_bug.cgi?id=185645

            Bug ID: 185645
           Summary: null pointer in JSC::jsSubstringOfResolved
           Product: WebKit
           Version: Safari 10
          Hardware: PC
                OS: iOS 11
            Status: NEW
          Severity: Trivial
          Priority: P2
         Component: JavaScriptCore
          Assignee: webkit-unassigned at lists.webkit.org
          Reporter: zhunkibatu at gmail.com

Created attachment 340396

  --> https://bugs.webkit.org/attachment.cgi?id=340396&action=review

poc.js

1   0x7f7beb34ef40 WTFCrash
2   0x7f7be93c88f9 JSC::jsSubstringOfResolved(JSC::VM&, JSC::GCDeferralContext*, JSC::JSString*, unsigned int, unsigned int)
3   0x7f7be9398ee3 JSC::RegExpObject::execInline(JSC::ExecState*, JSC::JSGlobalObject*, JSC::JSString*)
4   0x7f7ba1cfe185
Illegal instruction

-- 
You are receiving this mail because:
You are the assignee for the bug.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.webkit.org/pipermail/webkit-unassigned/attachments/20180515/12780255/attachment-0001.html>


More information about the webkit-unassigned mailing list