Commit 8b6c2cc
[Backport] CVE-2021-30536: Out of bounds read in V8
Cherry-pick of patch originally reviewed on
https://chromium-review.googlesource.com/c/v8/v8/+/2800111:
Create internal frame before throwing StackOverflow
... in CallBoundFunction builtin.
Bug: chromium:1194358
Change-Id: I8ddd4fff39cf399d4af332cff8eddc40e217cfdb
Auto-Submit: Igor Sheludko <ishell@chromium.org>
Reviewed-by: Leszek Swirski <leszeks@chromium.org>
Commit-Queue: Igor Sheludko <ishell@chromium.org>
Cr-Commit-Position: refs/heads/master@{#73775}
Reviewed-by: Michal Klocek <michal.klocek@qt.io>1 parent 5db4492 commit 8b6c2cc
1 file changed
+1
-0
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2522 | 2522 | | |
2523 | 2523 | | |
2524 | 2524 | | |
| 2525 | + | |
2525 | 2526 | | |
2526 | 2527 | | |
2527 | 2528 | | |
| |||
0 commit comments