Hi all,
This is just a quick heads-up to advise that I've found quite a nasty
bug in the Mozilla Javascript engine:

On systems running with a 48-bit VA, bit [47] is being incorrectly
masked out by the Javascript engine due to it being used internally
for tagging. This will cause random crashes (depending upon where mmap
returns memory).

In my case it even prevented the system from booting properly due to
polkitd crashing.

I would recommend anyone packaging the Mozilla Javascript engine to
keep an eye on this bug, I've flagged it as a "blocker".


cross-distro mailing list

Reply via email to