WebKit Bugzilla
New
Browse
Log In
×
Sign in with GitHub
or
Remember my login
Create Account
·
Forgot Password
Forgotten password account recovery
NEW
165964
Possible nullptr dereference in FrameView::updateScrollCorner
https://bugs.webkit.org/show_bug.cgi?id=165964
Summary
Possible nullptr dereference in FrameView::updateScrollCorner
Brent Fulgham
Reported
2016-12-16 11:29:29 PST
It is possible for 'renderer' to be null, but still have a valid cornerStyle: 1. If the document has no body, and the root element has no style, but we do have an owning iframe/frame element, we set a cornerStyle (but do not set the renderer). 2. Later, if no 'm_scrollCorner' member exists, we attempt to create one by accessing the renderer's document, generating a nullptr dereference.
Attachments
Add attachment
proposed patch, testcase, etc.
Note
You need to
log in
before you can comment on or make changes to this bug.
Top of Page
Format For Printing
XML
Clone This Bug