#39046 [Asn->WFx]: double free on circular references (PHP 4 only!)

From: Date: Fri, 11 Jul 2008 21:24:15 +0000
Subject: #39046 [Asn->WFx]: double free on circular references (PHP 4 only!)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-126537@lists.php.net to get a copy of this message
ID: 39046 Updated by: jani@php.net Reported By: checat at yandex dot ru -Status: Assigned +Status: Wont fix Bug Type: Reproducible crash Operating System: RHEL4 PHP Version: 4.4.4 Assigned To: derick New Comment: We are sorry, but we can not support PHP 4 related problems anymore. Momentum is gathering for PHP 6, and we think supporting PHP 4 will lead to a waste of resources which we want to put into getting PHP 6 ready. Previous Comments: ------------------------------------------------------------------------ [2006-10-05 11:31:13] derick@php.net We still need to address segfaults in 4.4. ------------------------------------------------------------------------ [2006-10-05 11:15:50] tony2001@php.net Circular references is the easiest way one can shoot his own leg. Upgrade to PHP5, which doesn't segfault. ------------------------------------------------------------------------ [2006-10-05 11:13:09] checat at yandex dot ru To have "double free" bug, one needs to wrap my test case into a function. ------------------------------------------------------------------------ [2006-10-05 11:07:47] checat at yandex dot ru Description: ------------ When freeing array variables with multiple references, variables which should still be accessible via other reference may be unexpectedly freed. Depending of the code it may produce data corruption, glibc-detected memory corruption or segfault. Reproduce code: --------------- <?php $root=array('id'=>'1', 'parent_id'=>NULL); $child1 = array('id'=>'2', 'parent_id'=>'1'); // build tree with references up and down $root['childs'] = array(); $child1['parent'] = & $root; $child1['parent']['childs'][] = & $child1; $child1['childs'] = array(); print_r($root['childs'][0]['childs']); unset($child1); print_r($root['childs'][0]['childs']); ?> Expected result: ---------------- Array ( ) Array ( ) Actual result: -------------- CGI: Array ( ) Array ( ) Segmentation fault Apache2/prefork/mod_php: no output, Segmentation fault in log ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=39046&edit=1

« previous php.bugs (#126537) next »