• Ulan Degenbaev's avatar
    [heap] Fix an out-of-bounds access in the marking bitmap · 8e8a06fa
    Ulan Degenbaev authored
    Deserializer can trigger OOB read in the marking bitmap inside the
    RegisterDeserializedObjectsForBlackAllocation function. This happens
    for example if an internalized string is deserialized as the last object
    on a page and is the turned into a thin-string leaving a one-word filler
    at the end of the page. In such a case IsBlack(filler) will try to fetch
    a cell outside the marking bitmap.
    
    The fix is to increase the size of the marking bitmap by one cell, so
    that it is always safe to query markbits of any object on a page.
    
    Bug: chromium:978156
    Change-Id: If3c74e4f97d2caeb3c3f37a4147f38dea5f0e5a8
    Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/2152838
    Commit-Queue: Ulan Degenbaev <ulan@chromium.org>
    Reviewed-by: 's avatarDominik Inführ <dinfuehr@chromium.org>
    Cr-Commit-Position: refs/heads/master@{#67223}
    8e8a06fa
Name
Last commit
Last update
..
api Loading commit data...
asmjs Loading commit data...
assembler Loading commit data...
base Loading commit data...
codegen Loading commit data...
compiler Loading commit data...
compiler-dispatcher Loading commit data...
date Loading commit data...
diagnostics Loading commit data...
execution Loading commit data...
heap Loading commit data...
interpreter Loading commit data...
libplatform Loading commit data...
logging Loading commit data...
numbers Loading commit data...
objects Loading commit data...
parser Loading commit data...
profiler Loading commit data...
regress Loading commit data...
strings Loading commit data...
tasks Loading commit data...
torque Loading commit data...
utils Loading commit data...
wasm Loading commit data...
zone Loading commit data...
BUILD.gn Loading commit data...
DEPS Loading commit data...
run-all-unittests.cc Loading commit data...
test-helpers.cc Loading commit data...
test-helpers.h Loading commit data...
test-utils.cc Loading commit data...
test-utils.h Loading commit data...
testcfg.py Loading commit data...
unittests.status Loading commit data...