https://bugs.documentfoundation.org/show_bug.cgi?id=168703

--- Comment #15 from Patrick (volunteer) <[email protected]> ---
(In reply to Xisco FaulĂ­ from comment #13)
> macOS 26 only ?

I have a wild theory: macOS Tahoe reuses deleted memory more aggressively than
previous macOS versions.

I don't have any good data, but from my crash log in attachment #203187, this
bug looks like a "use after free" bug to me.

I saw the same "use after free" on macOS Tahoe in tdf#168526 as well. My theory
is that macOS Tahoe is reallocating deleted memory much faster than before and
so deleted pointers in Writer get overwritten by whatever code that gets
allocated the deleted memory very soon after deletion.

Not sure how the Writer developers can prevent this other than implementing
some sort of "is this pointer still alive" code so that a pointer can be
checked before use.

-- 
You are receiving this mail because:
You are the assignee for the bug.

Reply via email to