Bug 298606 (CVE-2025-43457)
| Summary: | Array allocation sinking should split allocations into two, an Array allocation and a Butterfly allocation | ||
|---|---|---|---|
| Product: | WebKit | Reporter: | Keith Miller <keith_miller> |
| Component: | JavaScriptCore | Assignee: | Keith Miller <keith_miller> |
| Status: | RESOLVED FIXED | ||
| Severity: | Normal | CC: | commit-queue, mcatanzaro, webkit-bug-importer |
| Priority: | P2 | Keywords: | InRadar |
| Version: | WebKit Nightly Build | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Bug Depends on: | 298671 | ||
| Bug Blocks: | |||
Keith Miller
...
| Attachments | ||
|---|---|---|
| Add attachment proposed patch, testcase, etc. |
Keith Miller
<rdar://problem/159207754>
Keith Miller
Pull request: https://github.com/WebKit/WebKit/pull/50502
EWS
Committed 299806@main (f014a3289076): <https://commits.webkit.org/299806@main>
Reviewed commits have been landed. Closing PR #50502 and removing active labels.
WebKit Commit Bot
Re-opened since this is blocked by bug 298671
Keith Miller
Pull request: https://github.com/WebKit/WebKit/pull/50661
EWS
Committed 300129@main (c3b478c1983f): <https://commits.webkit.org/300129@main>
Reviewed commits have been landed. Closing PR #50661 and removing active labels.
EWS
Committed 297297.440@safari-7622-branch (99f0be62c77c): <https://commits.webkit.org/297297.440@safari-7622-branch>
Reviewed commits have been landed. Closing PR #3668 and removing active labels.