Fix fuzzer-found null deref in ChannelMac::SendMessageLocked() If the fuzzer creates a 0-sized null Channel::Message, accessing num_handles() goes through the message header, which won't exist. Switch to using the TakeHandles() vector instead. This is a somewhat artificial bug, but it is easy to fix. Bug: 978709 Change-Id: I7995fb9f809d0d623bece0ef238323a30ec90518 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/1732009 Reviewed-by: Ken Rockot <rockot@google.com> Commit-Queue: Robert Sesek <rsesek@chromium.org> Cr-Commit-Position: refs/heads/master@{#683620}
Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web.
The project's web site is https://www.chromium.org.
Documentation in the source is rooted in docs/README.md.
Learn how to Get Around the Chromium Source Code Directory Structure .