Req #68827 [Nab->Opn]: Double free

From: Date: Thu, 22 Jan 2015 00:31:39 +0000
Subject: Req #68827 [Nab->Opn]: Double free
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-190124@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68827&edit=1 ID: 68827 Updated by: pajoye@php.net Reported by: bugreports at internot dot info Summary: Double free -Status: Not a bug +Status: Open Type: Feature/Change Request Package: *General Issues Operating System: Linux Ubuntu 14.04 PHP Version: master-Git-2015-01-13 (Git) Block user comment: N Private report: N New Comment: @stas as it is a fileinfo issue and should also reported there, we do bundle it, patched. So it affects PHP more directly too. We should apply the fix. Previous Comments: ------------------------------------------------------------------------ [2015-01-14 23:19:54] stas@php.net This is a file from fileinfo library, so it may make sense to report the issue here; http://bugs.gw.com/my_view_page.php In this particular case return NULL may indeed be faster, but I don't see any security issue or PHP-related bug here. ------------------------------------------------------------------------ [2015-01-14 12:44:47] bugreports at internot dot info Ahh, I see! Well, then, this code: 2611 efree(map); 2612 goto error; should just be replaced with return NULL; since 'dbname', and 'stream' are not used at that stage. Thanks, ------------------------------------------------------------------------ [2015-01-14 12:33:10] tony2001@php.net That's correct, efree() doesn't modify the pointer. But it's already NULL at the time efree() is called, take a look at the if condition: if ((map = CAST(struct magic_map *, ecalloc(1, sizeof(*map)))) == NULL) { file_oomem(ms, sizeof(*map)); efree(map); goto error; } ------------------------------------------------------------------------ [2015-01-14 12:17:16] bugreports at internot dot info 'map' is not NULL. efree(map) doesn't set map=NULL;. ------------------------------------------------------------------------ [2015-01-14 09:42:11] tony2001@php.net The lines in if (map == ..) won't be executed ever when using Zend memory manager, because it bails out immediately on OOM error, so the only way to get them executed is to disable Zend MM and go with system MM. man free says: If ptr is NULL, no operation is performed. apprentice_unmap(): if (map == NULL) return; So.. where is the problem here? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=68827 -- Edit this bug report at https://bugs.php.net/bug.php?id=68827&edit=1

« previous php.bugs (#190124) next »