Bug #66751 [Opn]: php_strip_whitespace causes segmentation fault

From: Date: Mon, 24 Feb 2014 19:54:37 +0000
Subject: Bug #66751 [Opn]: php_strip_whitespace causes segmentation fault
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-184397@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66751&edit=1 ID: 66751 Updated by: krakjoe@php.net Reported by: yu at hoaxster dot net Summary: php_strip_whitespace causes segmentation fault Status: Open Type: Bug Package: *General Issues Operating System: OS X Mavericks PHP Version: 5.6.0alpha2 Block user comment: N Private report: N New Comment: This is a bit strange ... diff --git a/Zend/zend_highlight.c b/Zend/zend_highlight.c index e4f8d02..b961104 100644 --- a/Zend/zend_highlight.c +++ b/Zend/zend_highlight.c @@ -211,7 +211,8 @@ ZEND_API void zend_strip(TSRMLS_D) break; default: - efree(token.value.str.val); + if (token.value.str.len) + efree(token.value.str.val); break; } } You wouldn't think this is necessary, so I won't submit this as a patch ... Just a note really, I couldn't make this segfault but there is a call to efree an invalid pointer. /me leaves this for someone else who has more of a clue ... Previous Comments: ------------------------------------------------------------------------ [2014-02-21 12:01:16] yu at hoaxster dot net Description: ------------ php_strip_whitespace causes segmentation fault while parsing __CLASS__. Test script: --------------- # cat test.php <?php __CLASS__ ?> # php -r 'php_strip_whitespace(getcwd()."/test.php");' Actual result: -------------- [Fri Feb 21 20:57:50 2014] Script: '-' --------------------------------------- /var/tmp/php-build/source/5.6.0alpha2/Zend/zend_highlight.c(214) : Block 0x10781c048 status: Invalid pointer: ((size=0x0002b5a5) != (next.prev=0x444d4f4400000001)) Invalid pointer: ((prev=0x00000001) != (prev.size=0x0002b5a5)) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=66751&edit=1

« previous php.bugs (#184397) next »