#15728: Crash on free in PainterAggInterface
---------------------------------+----------------------------
Reporter: humdinger | Owner: axeld
Type: bug | Status: new
Priority: normal | Milestone: Unscheduled
Component: Servers/app_server | Version: R1/Development
Resolution: | Keywords:
Blocked By: | Blocking: 16246
Platform: All |
---------------------------------+----------------------------
Comment (by waddlesplash):
Here's a crash I got yesterday, on (as you can see) hrev54390.
I read through the code again and I am pretty baffled as to how this is
occuring. Perhaps the "shape" pointer is garbage as this is a UaF somehow?
But then the ReleaseReference should have crashed. I also looked through
all other users of AlphaMask and all of them appear to be doing ref-
counting correctly, or using BReference...
--
Ticket URL: <https://dev.haiku-os.org/ticket/15728#comment:7>
Haiku <https://dev.haiku-os.org>
The Haiku operating system.