Sec Bug->Bug #68906 [Nab]: Use after free

From: Date: Sat, 24 Jan 2015 21:47:59 +0000
Subject: Sec Bug->Bug #68906 [Nab]: Use after free
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-190183@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68906&edit=1 ID: 68906 Updated by: stas@php.net Reported by: bugreports at internot dot info Summary: Use after free Status: Not a bug -Type: Security +Type: Bug Package: opcache Operating System: Linux Ubuntu 14.04 PHP Version: 5.5.21 Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2015-01-24 21:47:52] stas@php.net I don't see any issue there - zend_shared_alloc_register_xlat_entry() does not dereference the pointer, only uses its value. ------------------------------------------------------------------------ [2015-01-24 19:58:32] bugreports at internot dot info Description: ------------ Hi, In /ext/opcache/zend_shared_alloc.c: 'source' is freed: 350 interned_efree((char*)source); 351 } but then used: 352 zend_shared_alloc_register_xlat_entry(source, retval); thanks ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68906&edit=1

« previous php.bugs (#190183) next »