OSV-2022-327
Dashboard / Vulnerabilities / OSV-2022-327
OSV-2022-327
Summary: Stack-use-after-return in QSemaphore::release
Details: OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=46525 The issue already existed before oss-fuzz could reproduce it. oss-fuzz found it after qdrawhelper routines were made multithreaded. There might be ways to trigger the issue before that. ``` Crash type: Stack-use-after-return WRITE 8 Crash state: QSemaphore::release std::__1::__function::__func<void handleSpans<BlendSrcGeneric> FunctionRunnable::run ```
References: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=46525, https://bugreports.qt.io/browse/QTBUG-102484, https://codereview.qt-project.org/c/qt/qtbase/+/406260, https://codereview.qt-project.org/c/qt/qtbase/+/406261, https://codereview.qt-project.org/c/qt/qtbase/+/405857
Affected packages
Package
Name: qt
Purl: pkg:generic/qt
Affected ranges
Type: GIT
Events:
