• Ulan Degenbaev's avatar
    [heap] Fix an out-of-bounds access in the marking bitmap · 8e8a06fa
    Ulan Degenbaev authored
    Deserializer can trigger OOB read in the marking bitmap inside the
    RegisterDeserializedObjectsForBlackAllocation function. This happens
    for example if an internalized string is deserialized as the last object
    on a page and is the turned into a thin-string leaving a one-word filler
    at the end of the page. In such a case IsBlack(filler) will try to fetch
    a cell outside the marking bitmap.
    
    The fix is to increase the size of the marking bitmap by one cell, so
    that it is always safe to query markbits of any object on a page.
    
    Bug: chromium:978156
    Change-Id: If3c74e4f97d2caeb3c3f37a4147f38dea5f0e5a8
    Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/2152838
    Commit-Queue: Ulan Degenbaev <ulan@chromium.org>
    Reviewed-by: 's avatarDominik Inführ <dinfuehr@chromium.org>
    Cr-Commit-Position: refs/heads/master@{#67223}
    8e8a06fa
Name
Last commit
Last update
build_overrides Loading commit data...
custom_deps Loading commit data...
docs Loading commit data...
gni Loading commit data...
include Loading commit data...
infra Loading commit data...
samples Loading commit data...
src Loading commit data...
test Loading commit data...
testing Loading commit data...
third_party Loading commit data...
tools Loading commit data...
.clang-format Loading commit data...
.clang-tidy Loading commit data...
.editorconfig Loading commit data...
.flake8 Loading commit data...
.git-blame-ignore-revs Loading commit data...
.gitattributes Loading commit data...
.gitignore Loading commit data...
.gn Loading commit data...
.vpython Loading commit data...
.ycm_extra_conf.py Loading commit data...
AUTHORS Loading commit data...
BUILD.gn Loading commit data...
CODE_OF_CONDUCT.md Loading commit data...
COMMON_OWNERS Loading commit data...
DEPS Loading commit data...
ENG_REVIEW_OWNERS Loading commit data...
INFRA_OWNERS Loading commit data...
INTL_OWNERS Loading commit data...
LICENSE Loading commit data...
LICENSE.fdlibm Loading commit data...
LICENSE.strongtalk Loading commit data...
LICENSE.v8 Loading commit data...
LICENSE.valgrind Loading commit data...
MIPS_OWNERS Loading commit data...
OWNERS Loading commit data...
PPC_OWNERS Loading commit data...
PRESUBMIT.py Loading commit data...
README.md Loading commit data...
S390_OWNERS Loading commit data...
WATCHLISTS Loading commit data...
codereview.settings Loading commit data...