Commit b0d6e44
[Backport] CVE-2021-30536: Out of bounds read in V8
Manual cherry-pick of patch originally reviewed on
https://chromium-review.googlesource.com/c/v8/v8/+/2800111:
[builtins][ia32] Create internal frame before throwing StackOverflow
... in CallBoundFunction builtin.
Bug: chromium:1194358
Change-Id: I8ddd4fff39cf399d4af332cff8eddc40e217cfdb
Auto-Submit: Igor Sheludko <ishell@chromium.org>
Reviewed-by: Leszek Swirski <leszeks@chromium.org>
Commit-Queue: Igor Sheludko <ishell@chromium.org>
Cr-Commit-Position: refs/heads/master@{#73775}
Reviewed-by: Allan Sandfeld Jensen <allan.jensen@qt.io>1 parent f41bb66 commit b0d6e44
1 file changed
+1
-0
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2255 | 2255 | | |
2256 | 2256 | | |
2257 | 2257 | | |
| 2258 | + | |
2258 | 2259 | | |
2259 | 2260 | | |
2260 | 2261 | | |
| |||
0 commit comments