Bug #65927 [NEW]: _zend_mm_free_int caused access violation

From: Date: Fri, 18 Oct 2013 08:07:49 +0000
Subject: Bug #65927 [NEW]: _zend_mm_free_int caused access violation
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-182335@lists.php.net to get a copy of this message
From:             it dot vie at virtual-identity dot com
Operating system: Windows 2012
PHP version:      5.4.21
Package:          Reproducible crash
Bug Type:         Bug
Bug description:_zend_mm_free_int caused access violation

Description:
------------
We are using:
 * Windows 2012
 * httpd-2.4.4-win32
 * mod_fcgid-2.3.7-win32
 * php_sqlsrv_54_nts
 * php 5.4.21
 * drupal 7.x

The php-cgi.exe crashes on "high" load (20-50 r/sec) with an access
violation. I created a debugging output as shown on
"bugs-generating-backtrace-win32".

IMHO the 

#define ZEND_MM_IS_FREE_BLOCK(b)		(!((b)->info._size &
ZEND_MM_USED_BLOCK))

should check if b is a valid pointer or there should be more checks when
using ZEND_MM_IS_FREE_BLOCK, but I'm not a C pro :)

Can you help me with this issue?

Actual result:
--------------
php5!_zend_mm_free_int+57
[c:\php-sdk\php53dev\vc9\x86\php-5.3.24\zend\zend_alloc.c @ 2028]  
c:\php-sdk\php53dev\vc9\x86\php-5.3.24\zend\zend_alloc.c @ 2028 
php5!_efree+19 [c:\php-sdk\php53dev\vc9\x86\php-5.3.24\zend\zend_alloc.c
@ 2361 + a]   c:\php-sdk\php53dev\vc9\x86\php-5.3.24\zend\zend_alloc.c @
2361 + a 
php_pdo_sqlsrv_53_nts+6833 
...
...
...
sqlncli11!SNIPacketSetConnection+b4    
sqlncli11!Session::ProcessDataPacket+1ef    
sqlncli11!CCriticalSectionNT::Leave+d    
0x018e5c58    
ntdll!RtlpHeapFindListLookupEntry+40    
ntdll!RtlpFindEntry+49    
0x0673d4d0    
ntdll!RtlpAllocateHeap+6e6    
0x06720000    
ntdll!RtlAllocateHeap+2de    
php_pdo_sqlsrv_53_nts+12903    
ntdll!RtlpAllocateHeap+76d    
ntdll!RtlAllocateHeap+176    
ntdll!RtlpHeapFindListLookupEntry+40    
ntdll!RtlpFindEntry+49    
ntdll!RtlpFreeHeap+667    
0x067287c8    
ntdll!RtlpFreeHeap+667    
ntdll!RtlFreeHeap+206    
sqlncli11!CImpISOSHost_MPMemObj::OperatorDelete+1c    
sqlncli11!BATCHCTX::Release+a1 


-- 
Edit bug report at https://bugs.php.net/bug.php?id=65927&edit=1
-- 
Try a snapshot (PHP 5.4):   https://bugs.php.net/fix.php?id=65927&r=trysnapshot54
Try a snapshot (PHP 5.5):   https://bugs.php.net/fix.php?id=65927&r=trysnapshot55
Try a snapshot (trunk):     https://bugs.php.net/fix.php?id=65927&r=trysnapshottrunk
Fixed in SVN:               https://bugs.php.net/fix.php?id=65927&r=fixed
Fixed in release:           https://bugs.php.net/fix.php?id=65927&r=alreadyfixed
Need backtrace:             https://bugs.php.net/fix.php?id=65927&r=needtrace
Need Reproduce Script:      https://bugs.php.net/fix.php?id=65927&r=needscript
Try newer version:          https://bugs.php.net/fix.php?id=65927&r=oldversion
Not developer issue:        https://bugs.php.net/fix.php?id=65927&r=support
Expected behavior:          https://bugs.php.net/fix.php?id=65927&r=notwrong
Not enough info:            https://bugs.php.net/fix.php?id=65927&r=notenoughinfo
Submitted twice:            https://bugs.php.net/fix.php?id=65927&r=submittedtwice
register_globals:           https://bugs.php.net/fix.php?id=65927&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=65927&r=php4
Daylight Savings:           https://bugs.php.net/fix.php?id=65927&r=dst
IIS Stability:              https://bugs.php.net/fix.php?id=65927&r=isapi
Install GNU Sed:            https://bugs.php.net/fix.php?id=65927&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=65927&r=float
No Zend Extensions:         https://bugs.php.net/fix.php?id=65927&r=nozend
MySQL Configuration Error:  https://bugs.php.net/fix.php?id=65927&r=mysqlcfg



Thread (5 messages)

« previous php.bugs (#182335) next »