Req #68827 [Asn->Csd]: Double free with disabled ZMM

From: Date: Thu, 22 Jan 2015 09:04:02 +0000
Subject: Req #68827 [Asn->Csd]: Double free with disabled ZMM
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-190134@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68827&edit=1 ID: 68827 Updated by: ab@php.net Reported by: bugreports at internot dot info Summary: Double free with disabled ZMM -Status: Assigned +Status: Closed Type: Feature/Change Request Package: *General Issues Operating System: Linux Ubuntu 14.04 PHP Version: master-Git-2015-01-13 (Git) Assigned To: ab Block user comment: N Private report: N New Comment: Automatic comment on behalf of bugreports@internot.info Revision: http://git.php.net/?p=php-src.git;a=commit;h=91aa340180eccfc15d4a143b54d47b8120f898be Log: Fixed bug #68827 Double free with disabled ZMM Previous Comments: ------------------------------------------------------------------------ [2015-01-22 07:44:09] ab@php.net Looks like it's an issue in the PHP patch, the latest libmagic looks fine https://github.com/file/file/blob/master/src/apprentice.c#L1283 . Despite it's only an issue with disabled ZMM, worth fixing. Thanks. ------------------------------------------------------------------------ [2015-01-22 00:31:38] pajoye@php.net @stas as it is a fileinfo issue and should also reported there, we do bundle it, patched. So it affects PHP more directly too. We should apply the fix. ------------------------------------------------------------------------ [2015-01-14 23:19:54] stas@php.net This is a file from fileinfo library, so it may make sense to report the issue here; http://bugs.gw.com/my_view_page.php In this particular case return NULL may indeed be faster, but I don't see any security issue or PHP-related bug here. ------------------------------------------------------------------------ [2015-01-14 12:44:47] bugreports at internot dot info Ahh, I see! Well, then, this code: 2611 efree(map); 2612 goto error; should just be replaced with return NULL; since 'dbname', and 'stream' are not used at that stage. Thanks, ------------------------------------------------------------------------ [2015-01-14 12:33:10] tony2001@php.net That's correct, efree() doesn't modify the pointer. But it's already NULL at the time efree() is called, take a look at the if condition: if ((map = CAST(struct magic_map *, ecalloc(1, sizeof(*map)))) == NULL) { file_oomem(ms, sizeof(*map)); efree(map); goto error; } ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=68827 -- Edit this bug report at https://bugs.php.net/bug.php?id=68827&edit=1

« previous php.bugs (#190134) next »