Bug #66127 [NEW]: Segmentation fault with ArrayObject unset

From: Date: Wed, 20 Nov 2013 18:06:19 +0000
Subject: Bug #66127 [NEW]: Segmentation fault with ArrayObject unset
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-182870@lists.php.net to get a copy of this message
From: webm4st0r at gmail dot com Operating system: CentOS confirmed PHP version: 5.5.6 Package: Reproducible crash Bug Type: Bug Bug description:Segmentation fault with ArrayObject unset Description: ------------ This appears to have been introduced as the result of the patch to https://bugs.php.net/bug.php?id=52861. I ran into this issue while regression testing our application on PHP 5.5.5, and was able to create a short script to reproduce the segfault. Building PHP 5.4.13 with the patch for #52861 removed results in a successful execution and proper execution of the error handler. Build was on a clean version of the 5.4.13 distribution, with no configure options provided. gdb backtrace for PHP 5.4.13: #0 _zend_mm_alloc_int (heap=0xd2b290, size=32) at /root/build/php-5.4.13/Zend/zend_alloc.c:1906 #1 0x00000000006765ad in zend_error (type=1024, format=0xa7dee1 "%s") at /root/build/php-5.4.13/Zend/zend.c:1123 #2 0x0000000000687419 in zif_trigger_error (ht=<value optimized out>, return_value=0x7ffff7fe2290, return_value_ptr=<value optimized out>, this_ptr=<value optimized out>, return_value_used=<value optimized out>) at /root/build/php-5.4.13/Zend/zend_builtin_functions.c:1504 #3 0x00000000006ee76a in zend_do_fcall_common_helper_SPEC (execute_data=<value optimized out>) at /root/build/php-5.4.13/Zend/zend_vm_execute.h:642 #4 0x00000000006dbe60 in execute (op_array=0xe9ff50) at /root/build/php-5.4.13/Zend/zend_vm_execute.h:410 #5 0x000000000067616e in zend_execute_scripts (type=8, retval=0x0, file_count=3) at /root/build/php-5.4.13/Zend/zend.c:1315 #6 0x000000000061c17e in php_execute_script (primary_file=0x7fffffffe2b0) at /root/build/php-5.4.13/main/main.c:2492 #7 0x000000000071bbb3 in do_cli (argc=2, argv=0x7fffffffe6b8) at /root/build/php-5.4.13/sapi/cli/php_cli.c:988 #8 0x000000000071c2b4 in main (argc=2, argv=0x7fffffffe6b8) at /root/build/php-5.4.13/sapi/cli/php_cli.c:1364 gdb backtrace for PHP 5.5.6: #0 _zend_mm_alloc_int (heap=0xd9ed00, size=32) at /root/build/php-5.5.6/Zend/zend_alloc.c:1910 #1 0x0000000000691b9a in zend_error (type=1024, format=0xa6f4ec "%s") at /root/build/php-5.5.6/Zend/zend.c:1126 #2 0x00000000006a3c5b in zif_trigger_error (ht=<value optimized out>, return_value=0x7ffff7fe22d0, return_value_ptr=<value optimized out>, this_ptr=<value optimized out>, return_value_used=<value optimized out>) at /root/build/php-5.5.6/Zend/zend_builtin_functions.c:1521 #3 0x0000000000713da3 in zend_do_fcall_common_helper_SPEC (execute_data=<value optimized out>) at /root/build/php-5.5.6/Zend/zend_vm_execute.h:550 #4 0x0000000000705350 in execute_ex (execute_data=0x7ffff7fad310) at /root/build/php-5.5.6/Zend/zend_vm_execute.h:363 #5 0x0000000000691749 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at /root/build/php-5.5.6/Zend/zend.c:1320 #6 0x00000000006335b9 in php_execute_script (primary_file=0x7fffffffe2b0) at /root/build/php-5.5.6/main/main.c:2489 #7 0x0000000000741ccc in do_cli (argc=2, argv=0xd9ea20) at /root/build/php-5.5.6/sapi/cli/php_cli.c:994 #8 0x0000000000742468 in main (argc=2, argv=0xd9ea20) at /root/build/php-5.5.6/sapi/cli/php_cli.c:1378 Test script: --------------- <?php function crash() { set_error_handler(function () {}); $var = 1; trigger_error('error'); $var2 = $var; $var3 = $var; trigger_error('error'); } $items = new ArrayObject(); unset($items[0]); unset($items[0][0]); crash(); echo "Worked!\n"; Expected result: ---------------- Worked! Actual result: -------------- Segmentation fault (core dumped) -- Edit bug report at https://bugs.php.net/bug.php?id=66127&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=66127&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=66127&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=66127&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=66127&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=66127&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=66127&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=66127&r=needscript Try newer version: https://bugs.php.net/fix.php?id=66127&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=66127&r=support Expected behavior: https://bugs.php.net/fix.php?id=66127&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=66127&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=66127&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=66127&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=66127&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=66127&r=dst IIS Stability: https://bugs.php.net/fix.php?id=66127&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=66127&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=66127&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=66127&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=66127&r=mysqlcfg

« previous php.bugs (#182870) next »