Bug 231975
| Summary: | JSGenericTypedArrayView<Adaptor>::set crashes if the length + objectOffset is > UINT32_MAX | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Product: | WebKit | Reporter: | Robin Morisset <rmorisset> | ||||||||||||||||
| Component: | JavaScriptCore | Assignee: | Robin Morisset <rmorisset> | ||||||||||||||||
| Status: | RESOLVED FIXED | ||||||||||||||||||
| Severity: | Normal | CC: | ews-watchlist, keith_miller, mark.lam, msaboff, saam, tzagallo, webkit-bug-importer, ysuzuki | ||||||||||||||||
| Priority: | P1 | Keywords: | InRadar | ||||||||||||||||
| Version: | WebKit Nightly Build | ||||||||||||||||||
| Hardware: | Unspecified | ||||||||||||||||||
| OS: | Unspecified | ||||||||||||||||||
| Bug Depends on: | 229353 | ||||||||||||||||||
| Bug Blocks: | |||||||||||||||||||
| Attachments: |
|
||||||||||||||||||
2021-10-19 13:17 PDT, Robin Morisset
2021-10-19 17:23 PDT, Robin Morisset
2021-10-21 17:09 PDT, Robin Morisset
rmorisset: commit-queue-
2021-10-22 14:01 PDT, Robin Morisset
2021-10-22 17:56 PDT, Robin Morisset
2021-10-22 19:03 PDT, Robin Morisset
2021-10-29 14:30 PDT, Robin Morisset