Changeset 121160 in webkit
- Timestamp:
- Jun 25, 2012 9:30:49 AM (12 years ago)
- Location:
- trunk/Source/WebKit/chromium
- Files:
-
- 2 edited
Legend:
- Unmodified
- Added
- Removed
-
trunk/Source/WebKit/chromium/ChangeLog
r121129 r121160 1 2012-06-25 Kinuko Yasuda <kinuko@chromium.org> 2 3 Heap-use-after-free in WebKit::MainThreadFileSystemCallbacks 4 https://bugs.webkit.org/show_bug.cgi?id=87019 5 6 Reviewed by David Levin. 7 8 Should not access the CallbacksBridge's member field after it's freed. 9 10 * src/WorkerFileSystemCallbacksBridge.cpp: 11 (WebKit::WorkerFileSystemCallbacksBridge::cleanUpAfterCallback): 12 1 13 2012-06-24 Luke Macpherson <macpherson@chromium.org> 2 14 -
trunk/Source/WebKit/chromium/src/WorkerFileSystemCallbacksBridge.cpp
r112576 r121160 188 188 m_callbacksOnWorkerThread = 0; 189 189 if (m_workerContextObserver) { 190 deletem_workerContextObserver;190 WorkerFileSystemContextObserver* observer = m_workerContextObserver; 191 191 m_workerContextObserver = 0; 192 // The next line may delete this. 193 delete observer; 192 194 } 193 195 }
Note: See TracChangeset
for help on using the changeset viewer.