Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
[M110] login: Fix UAF by not disposing storage partition
> http://crrev.com/c/3691982's assumption that storage partitions of > previous gaia loads could be released when a new gaia load starts. > This assumption does not hold and there could be pending calls using > the partition even though the gaia webview has navigated away. This > causes UAF crashes. This CL stops the crash by stop disposing the > storage partitions and could be merged to release branches to stop > fire there. > > Note this regresses the memory leak in crbug/1308831. > > Bug: 1382971, 1308831 > Change-Id: I93764836ebbafd1f2c4b6906b8a1d2660e37cfc4 > Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/4140176 > Reviewed-by: Achuith Bhandarkar <achuith@chromium.org> > Commit-Queue: Xiyuan Xia <xiyuan@chromium.org> > Reviewed-by: Alexander Alekseev <alemate@chromium.org> > Cr-Commit-Position: refs/heads/main@{#1090590} (cherry picked from commit b1bce82) Change-Id: Ia547943e5064a976c07f672da57a71c226c770c1 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/4152810 Commit-Queue: Achuith Bhandarkar <achuith@chromium.org> Auto-Submit: Xiyuan Xia <xiyuan@chromium.org> Reviewed-by: Achuith Bhandarkar <achuith@chromium.org> Cr-Commit-Position: refs/branch-heads/5481@{#202} Cr-Branched-From: 130f3e4-refs/heads/main@{#1084008}
- Loading branch information