[haiku-bugs] Re: [Haiku] #15728: Crash on free in PainterAggInterface

  • From: "Haiku" <trac@xxxxxxxxxxxx>
  • To: undisclosed-recipients: ;
  • Date: Sun, 05 Jul 2020 22:33:07 -0000

#15728: Crash on free in PainterAggInterface
---------------------------------+----------------------------
  Reporter:  humdinger           |      Owner:  axeld
      Type:  bug                 |     Status:  new
  Priority:  normal              |  Milestone:  Unscheduled
 Component:  Servers/app_server  |    Version:  R1/Development
Resolution:                      |   Keywords:
Blocked By:                      |   Blocking:  16246
  Platform:  All                 |
---------------------------------+----------------------------
Comment (by waddlesplash):

 Here's a crash I got yesterday, on (as you can see) hrev54390.

 I read through the code again and I am pretty baffled as to how this is
 occuring. Perhaps the "shape" pointer is garbage as this is a UaF somehow?
 But then the ReleaseReference should have crashed. I also looked through
 all other users of AlphaMask and all of them appear to be doing ref-
 counting correctly, or using BReference...
-- 
Ticket URL: <https://dev.haiku-os.org/ticket/15728#comment:7>
Haiku <https://dev.haiku-os.org>
The Haiku operating system.

Other related posts: