mirror of
https://github.com/RGBCube/serenity
synced 2025-05-19 03:55:07 +00:00

If an exception occurs in a custom element constructor, we clear the reaction queue by destroying it, instead of emptying the Vector.3da6916383/Userland/Libraries/LibWeb/DOM/Element.cpp (L2033)
This causes a UAF here, as async upgrades (i.e. custom elements not created by document.createElement) are performed in this loop:3da6916383/Userland/Libraries/LibWeb/Bindings/MainThreadVM.cpp (L657)
Fixes crash when loading https://github.com/SerenityOS/serenity
2 lines
67 B
Text
2 lines
67 B
Text
Entered TestElement constructor, throwing.
|
|
PASS! (Didn't crash)
|