OSV-2021-503

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/skia/OSV-2021-503.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2021-503
Published
2021-03-07T00:00:48.743475Z
Modified
2022-04-13T03:04:33.774982Z
Summary
Use-after-poison in std::__1::unique_ptr<SkSL::Expression, std::__1::default_delete<SkSL::Expression
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=31765

Crash type: Use-after-poison READ 8
Crash state:
std::__1::unique_ptr&lt;SkSL::Expression, std::__1::default_delete&lt;SkSL::Expression
SkSL::DefinitionMap::getKnownDefinition
SkSL::VariableReference::constantPropagate
References

Affected packages

OSS-Fuzz / skia

Package

Name
skia
Purl
pkg:generic/skia

Affected ranges

Type
GIT
Repo
https://skia.googlesource.com/skia.git
Events

Affected versions

canvaskit/0.*

canvaskit/0.24.0
canvaskit/0.25.0

Ecosystem specific

{
    "severity": "HIGH",
    "introduced_range": "1d62221553b70cbfd3df37c411d5e1951192d6cb:75b7606c0fe1b0dbb253d9e0a1c5f14b963ed0ad"
}