Chrome · V8
CVE-2025-1914
OOB in V8
Overview
High
Severity
—
CVSS
No
Exploited ITW
Fixed
Fix Status
Changed Functions
| Function | Change | Notes |
|---|---|---|
ifsrc/numbers/conversions.cc |
modified |
Files Changed
src/numbers/conversions.cc
Patch
From 00b8fba79ed2d14ec8e7fb1e2bcc38f3d59afaef Mon Sep 17 00:00:00 2001 From: Leszek Swirski <[email protected]> Date: Thu, 20 Feb 2025 14:19:24 +0100 Subject: [PATCH] [conversions] Check for denormal flushing in DoubleToRadixString Explicitly check the denormal flushing flag in DoubleToRadixString, to avoid the compiler optimizing away checks against zero. Bug: 382005099 Fixed: 397731718 Change-Id: If9298e68827bf2e5a1fd987b04b2536bf937a19f Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/6286167 Commit-Queue: Leszek Swirski <[email protected]> Auto-Submit: Leszek Swirski <[email protected]> Reviewed-by: Jakob Kummerow <[email protected]> Cr-Commit-Position: refs/heads/main@{#98833} --- diff --git a/src/numbers/conversions.cc b/src/numbers/conversions.cc index 95e0036..c8534b7 100644 --- a/src/numbers/conversions.cc +++ b/src/numbers/conversions.cc @@ -1251,11 +1251,19 @@ double fraction = value - integer; // We only compute fractional digits up to the input double's precision. double delta = 0.5 * (base::Double(value).NextDouble() - value); - delta = std::max(base::Double(0.0).NextDouble(), delta); - // Delta should always be greater than zero, so long as we're not flushing - // denormals to zero. - DCHECK_IMPLIES(!(delta > 0.0), base::FPU::GetFlushDenormals()); - if (delta > 0.0 && fraction >= delta) { + bool delta_is_positive = true; + // If the delta rounded down to zero, use the minimum (denormal) delta + // value. Be careful around denormal flushing when doing so. + if (delta <= 0) { + if (base::FPU::GetFlushDenormals()) { + // We're flushing the delta value to zero, so the loop below won't + // make progress. Skip it instead. + delta_is_positive = false; + } else { + delta = base::Double(0.0).NextDouble(); + } + } + if (delta_is_positive && fraction >= delta) { // Insert decimal point. buffer[fraction_cursor++] = '.'; do {
Loading diff…
Original Bug Report
reported by [email protected]
Debug check failed: index < length_ (2200 vs. 2200).
The issue 395329242 that we previously reported has been merged into issue 394644268.
However, even after applying the patch for issue 394644268 (https://chromium-review.googlesource.com/c/v8/v8/+/6236978),, the DCHECK can still be triggered in the latest d8 (#98715).
Therefore, we kindly request you to investigate this issue further.
References
On This Page