Chromium: https://code.google.com/p/chromium/issues/detail?id=84018 Repro: <body onload="f()"></body> <script> function f() { var oImg = new Image(); document.open(); oImg.innerHTML = "<summary>"; document.insertBefore(oImg.lastChild, null); } </script> id: chrome.dll!WebCore::HTMLSummaryElement::isMainSummary ReadAV@NULL (2d237efc21d08331051148bfdb203706) description: Attempt to read from unallocated NULL pointer+0x8 in chrome.dll!WebCore::HTMLSummaryElement::isMainSummary application: Chromium 13.0.777.0 stack: chrome.dll!WebCore::HTMLSummaryElement::isMainSummary chrome.dll!WebCore::DetailsMarkerControl::rendererIsNeeded chrome.dll!WebCore::NodeRendererFactory::createRendererAndStyle chrome.dll!WebCore::NodeRendererFactory::createRendererIfNeeded chrome.dll!WebCore::Node::createRendererIfNeeded chrome.dll!WebCore::Element::attach chrome.dll!WebCore::ContainerNode::attach chrome.dll!WebCore::ShadowRoot::attach chrome.dll!WebCore::Element::attach chrome.dll!WebCore::Element::recalcStyle chrome.dll!WebCore::Document::recalcStyle chrome.dll!WebCore::Document::updateStyleIfNeeded chrome.dll!WebCore::Document::implicitClose chrome.dll!WebCore::FrameLoader::checkCompleted chrome.dll!WebCore::FrameLoader::finishedParsing chrome.dll!WebCore::Document::finishedParsing chrome.dll!WebCore::HTMLDocumentParser::prepareToStopParsing chrome.dll!WebCore::DocumentWriter::endIfNotLoadingMainResource chrome.dll!WebCore::FrameLoader::finishedLoading chrome.dll!WebCore::MainResourceLoader::didFinishLoading chrome.dll!WebCore::ResourceLoader::didFinishLoading chrome.dll!WebCore::ResourceHandleInternal::didFinishLoading chrome.dll!webkit_glue::WebURLLoaderImpl::Context::OnCompletedRequest chrome.dll!ResourceDispatcher::OnRequestComplete chrome.dll!IPC::MessageWithTuple<...>::Dispatch<ResourceDispatcher,ResourceDispatcher,void chrome.dll!ResourceDispatcher::DispatchMessageW chrome.dll!ResourceDispatcher::OnMessageReceived chrome.dll!ChildThread::OnMessageReceived chrome.dll!RunnableMethod<DetectTabLanguageFunction,void chrome.dll!`anonymous namespace'::TaskClosureAdapter::Run ...
Created attachment 95114 [details] Patch
Comment on attachment 95114 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=95114&action=review > LayoutTests/ChangeLog:5 > + WebCore::HTMLSummaryElement::isMainSummary ReadAV@NULL nit: ReadAV@NULL is not normal English.
Committed r87480: <http://trac.webkit.org/changeset/87480>
Revision r87480 cherry-picked into qtwebkit-2.2 with commit 27ca4d8 <http://gitorious.org/webkit/qtwebkit/commit/27ca4d8>