Bug #67917 [Opn->Csd]: Using GMP objects with overloaded operators can cause memory exhaustion.

From: Date: Wed, 27 Aug 2014 20:17:03 +0000
Subject: Bug #67917 [Opn->Csd]: Using GMP objects with overloaded operators can cause memory exhaustion.
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-187303@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67917&edit=1 ID: 67917 Updated by: nikic@php.net Reported by: leight+phpbugs at gmail dot com Summary: Using GMP objects with overloaded operators can cause memory exhaustion. -Status: Open +Status: Closed Type: Bug Package: GNU MP related Operating System: Linux 3.14 PHP Version: 5.6Git-2014-08-27 (Git) Block user comment: N Private report: N New Comment: Automatic comment on behalf of nikic Revision: http://git.php.net/?p=php-src.git;a=commit;h=fc5f93166371d275b8982e14e0868b776c039d25 Log: Fix bug #67917 (gmp compound assignment operator leak) Previous Comments: ------------------------------------------------------------------------ [2014-08-27 15:32:30] leight+phpbugs at gmail dot com Description: ------------ PHP version was from a pull of the 5.6 branch this morning. sapi/cli/php -v PHP 5.6.1-dev (cli) (built: Aug 27 2014 11:35:34) (DEBUG) Configured with --disable-all --enable-debug --enable-bcmath and --with-gmp I believe there may be a refcount issue with either the shift-left-assign or or-assign operators. I can reliably exhaust available memory with a function using these operators. In the provided script import() works as intended and does not use the assign-ops, whereas import2() uses assign-ops and causes memory exhaustion. Test script: --------------- function import($bin) { $c = unpack('C*', $bin); $i = count($c); $ret = gmp_init($c[$i--]); while ($i > 0) { $ret = ($ret << 8) | $c[$i--]; } return $ret; } function import2($bin) { $c = unpack('C*', $bin); $i = count($c); $ret = gmp_init($c[$i--]); while ($i > 0) { $ret <<= 8; $ret |= $c[$i--]; } return $ret; } print "import 1 x 10000\n"; for ($i = 0; $i < 10000; $i++) { import(str_repeat('a', 100)); } print "import 2 x 10000\n"; for ($i = 0; $i < 10000; $i++) { import2(str_repeat('a', 100)); } Expected result: ---------------- import 1 x 10000 import 2 x 10000 Process finished with exit code 0 Actual result: -------------- import 1 x 10000 import 2 x 10000 Fatal error: Allowed memory size of 134217728 bytes exhausted at gmp.c:384 (tried to allocate 48 bytes) in test.php on line 24 Process finished with exit code 255 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=67917&edit=1

« previous php.bugs (#187303) next »