Bug #67917 [Opn->Csd]: Using GMP objects with overloaded operators can cause memory exhaustion.
| From: | nikic@php.net | Date: | Wed, 27 Aug 2014 20:17:03 +0000 |
| Subject: | Bug #67917 [Opn->Csd]: Using GMP objects with overloaded operators can cause memory exhaustion. | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-187303@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67917&edit=1
ID: 67917
Updated by: nikic@php.net
Reported by: leight+phpbugs at gmail dot com
Summary: Using GMP objects with overloaded operators can
cause memory exhaustion.
-Status: Open
+Status: Closed
Type: Bug
Package: GNU MP related
Operating System: Linux 3.14
PHP Version: 5.6Git-2014-08-27 (Git)
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of nikic
Revision: http://git.php.net/?p=php-src.git;a=commit;h=fc5f93166371d275b8982e14e0868b776c039d25
Log: Fix bug #67917 (gmp compound assignment operator leak)
Previous Comments:
------------------------------------------------------------------------
[2014-08-27 15:32:30] leight+phpbugs at gmail dot com
Description:
------------
PHP version was from a pull of the 5.6 branch this morning.
sapi/cli/php -v
PHP 5.6.1-dev (cli) (built: Aug 27 2014 11:35:34) (DEBUG)
Configured with --disable-all --enable-debug --enable-bcmath and --with-gmp
I believe there may be a refcount issue with either the shift-left-assign or or-assign operators. I
can reliably exhaust available memory with a function using these operators.
In the provided script import() works as intended and does not use the assign-ops, whereas import2()
uses assign-ops and causes memory exhaustion.
Test script:
---------------
function import($bin)
{
$c = unpack('C*', $bin);
$i = count($c);
$ret = gmp_init($c[$i--]);
while ($i > 0) {
$ret = ($ret << 8) | $c[$i--];
}
return $ret;
}
function import2($bin)
{
$c = unpack('C*', $bin);
$i = count($c);
$ret = gmp_init($c[$i--]);
while ($i > 0) {
$ret <<= 8;
$ret |= $c[$i--];
}
return $ret;
}
print "import 1 x 10000\n";
for ($i = 0; $i < 10000; $i++) {
import(str_repeat('a', 100));
}
print "import 2 x 10000\n";
for ($i = 0; $i < 10000; $i++) {
import2(str_repeat('a', 100));
}
Expected result:
----------------
import 1 x 10000
import 2 x 10000
Process finished with exit code 0
Actual result:
--------------
import 1 x 10000
import 2 x 10000
Fatal error: Allowed memory size of 134217728 bytes exhausted at gmp.c:384 (tried to allocate 48
bytes) in test.php on line 24
Process finished with exit code 255
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67917&edit=1