Bug #68252 [NEW]: segfault in Zend/zend_hash.c in function _zend_hash_del_el

From: Date: Fri, 17 Oct 2014 14:07:52 +0000
Subject: Bug #68252 [NEW]: segfault in Zend/zend_hash.c in function _zend_hash_del_el
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-188167@lists.php.net to get a copy of this message
From: bugs at milos dot nz Operating system: Linux 3.16 (Gentoo) PHP version: master-Git-2014-10-17 (Git) Package: Reproducible crash Bug Type: Bug Bug description:segfault in Zend/zend_hash.c in function _zend_hash_del_el Description: ------------ WordPress sites with certain plugins enabled cause a segmentation fault. Several different sites with different plugins cause this and the segmentation fault is the same. I have not encountered the issue with any isolated PHP script so I cannot currently be more specific than this. Commenting out most of the _zend_hash_del_el() function resolves the issue, however this must either reduce performance, cause memory leaks or other anomalies, so if anything this is a temporary workaround: static zend_always_inline void _zend_hash_del_el(HashTable *ht, uint32_t idx, Bucket *p) { Bucket *prev = NULL; /*if (!(ht->u.flags & HASH_FLAG_PACKED)) { uint32_t nIndex = p->h & ht->nTableMask; uint32_t i = ht->arHash[nIndex]; if (i != idx) { prev = ht->arData + i; while (Z_NEXT(prev->val) != idx) { i = Z_NEXT(prev->val); prev = ht->arData + i; } } }*/ _zend_hash_del_el_ex(ht, idx, p, prev); } Test script: --------------- I am not able to identify exactly what code causes the segmentation fault so cannot provide a test script at this current point in time, but the segmentation fault is 100% reproducible on my system. Expected result: ---------------- No segmentation fault. Actual result: -------------- Program received signal SIGSEGV, Segmentation fault. _zend_hash_del_el (p=0x7fffeff117b0, idx=1725, ht=0xf81890) at /root/tmp/php-src/Zend/zend_hash.c:658 658 while (Z_NEXT(prev->val) != idx) { (gdb) bt #0 _zend_hash_del_el (p=0x7fffeff117b0, idx=1725, ht=0xf81890) at /root/tmp/php-src/Zend/zend_hash.c:658 #1 zend_hash_apply_deleter (ht=ht@entry=0xf81890, idx=idx@entry=1725, p=p@entry=0x7fffeff117b0) at /root/tmp/php-src/Zend/zend_hash.c:973 #2 0x000000000074b0a9 in zend_hash_reverse_apply (ht=0xf81890, apply_func=apply_func@entry=0x729ee0 <clean_non_persistent_function>) at /root/tmp/php-src/Zend/zend_hash.c:1133 #3 0x000000000072a6b8 in shutdown_executor () at /root/tmp/php-src/Zend/zend_execute_API.c:347 #4 0x000000000073ac17 in zend_deactivate () at /root/tmp/php-src/Zend/zend.c:883 #5 0x00000000006dface in php_request_shutdown (dummy=dummy@entry=0x0) at /root/tmp/php-src/main/main.c:1859 #6 0x0000000000484214 in main (argc=2, argv=0x7fffffffe078) at /root/tmp/php-src/sapi/cgi/cgi_main.c:2515 (gdb) print prev $1 = (Bucket *) 0x801feff03ff0 (gdb) print prev->val Cannot access memory at address 0x801feff04000 (gdb) print idx $2 = 1725 The issue is apparently here: 658: while (Z_NEXT(prev->val) != idx) { However, I am not sure if the fault lies in _zend_hash_del_el() itself or if _zend_hash_del_el() is being called with incorrect arguments. An identical segmentation fault occurs when calling this WordPress index.php script through apache2 with PHP as a SAPI module. The master PHP branch was compiled with the following options: './configure' '--prefix=/root/tmp/usr' '--build=x86_64-pc-linux-gnu' '--host=x86_64-pc-linux-gnu' '--mandir=/usr/share/man' '--infodir=/usr/share/info' '--datadir=/usr/share' '--sysconfdir=/etc' '--localstatedir=/var/lib' '--prefix=/usr/lib64/php7.0' '--mandir=/usr/lib64/php7.0/man' '--infodir=/usr/lib64/php7.0/info' '--libdir=/usr/lib64/php7.0/lib' '--with-libdir=lib64' '--without-pear' '--disable-maintainer-zts' '--enable-bcmath' '--with-bz2=/usr' '--enable-calendar' '--enable-ctype' '--with-curl=/usr' '--enable-dom' '--without-enchant' '--disable-exif' '--enable-fileinfo' '--enable-filter' '--disable-ftp' '--with-gettext=/usr' '--without-gmp' '--enable-hash' '--with-mhash=/usr' '--with-iconv' '--enable-intl' '--enable-ipv6' '--enable-json' '--without-kerberos' '--enable-libxml' '--with-libxml-dir=/usr' '--enable-mbstring' '--with-mcrypt=/usr' '--without-mssql' '--with-onig=/usr' '--with-openssl=/usr' '--with-openssl-dir=/usr' '--disable-pcntl' '--enable-phar' '--enable-pdo' '--enable-opcache' '--without-pgsql' '--enable-posix' '--with-pspell=/usr' '--without-recode' '--enable-simplexml' '--disable-shmop' '--without-snmp' '--disable-soap' '--enable-sockets' '--without-sqlite3' '--without-sybase-ct' '--disable-sysvmsg' '--disable-sysvsem' '--disable-sysvshm' '--without-fpm-systemd' '--without-tidy' '--enable-tokenizer' '--disable-wddx' '--enable-xml' '--enable-xmlreader' '--enable-xmlwriter' '--without-xmlrpc' '--without-xsl' '--enable-zip' '--with-zlib=/usr' '--disable-debug' '--enable-dba' '--without-cdb' '--with-db4=/usr' '--disable-flatfile' '--with-gdbm=/usr' '--disable-inifile' '--without-qdbm' '--with-freetype-dir=/usr' '--with-t1lib=/usr' '--disable-gd-jis-conv' '--with-jpeg-dir=/usr' '--with-png-dir=/usr' '--without-xpm-dir' '--without-vpx-dir' '--with-gd' '--with-imap=/usr' '--with-imap-ssl=/usr' '--with-mysql=/usr' '--with-mysqli=/usr/bin/mysql_config' '--with-mysql-sock=/var/run/mysqld/mysqld.sock' '--without-pdo-dblib' '--with-pdo-mysql=/usr' '--without-pdo-pgsql' '--without-pdo-sqlite' '--without-pdo-odbc' '--with-readline=/usr' '--without-libedit' '--without-mm' '--with-pic' '--with-pcre-regex=/usr' '--with-pcre-dir=/usr' '--with-config-file-path=/root/tmp/usr/etc' '--disable-embed' '--enable-cli' '--enable-cgi' '--enable-fpm' '--with-apxs2=/usr/sbin/apxs2' 'build_alias=x86_64-pc-linux-gnu' 'host_alias=x86_64-pc-linux-gnu' -- Edit bug report at https://bugs.php.net/bug.php?id=68252&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=68252&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=68252&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=68252&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=68252&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=68252&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=68252&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=68252&r=needscript Try newer version: https://bugs.php.net/fix.php?id=68252&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=68252&r=support Expected behavior: https://bugs.php.net/fix.php?id=68252&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=68252&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=68252&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=68252&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=68252&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=68252&r=dst IIS Stability: https://bugs.php.net/fix.php?id=68252&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=68252&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=68252&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=68252&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=68252&r=mysqlcfg

« previous php.bugs (#188167) next »