Bug 267112

Summary: GC can run during B3::generate now, causing UAF in patchpoints
Product: WebKit Reporter: Justin Michaud <justin_michaud>
Component: JavaScriptCoreAssignee: Justin Michaud <justin_michaud>
Status: RESOLVED FIXED    
Severity: Normal CC: webkit-bug-importer
Priority: P2 Keywords: InRadar
Version: WebKit Nightly Build   
Hardware: Unspecified   
OS: Unspecified   

Justin Michaud
Reported 2024-01-04 17:45:46 PST
GC can run during B3::generate now, causing UAF in patchpoints
Attachments
Justin Michaud
Comment 1 2024-01-04 17:45:56 PST
Justin Michaud
Comment 2 2024-01-04 18:15:53 PST
EWS
Comment 3 2024-01-05 15:21:30 PST
Committed 272710@main (cae26b36ccb9): <https://commits.webkit.org/272710@main> Reviewed commits have been landed. Closing PR #22414 and removing active labels.
Note You need to log in before you can comment on or make changes to this bug.