Sec Bug->Bug #68908 [Opn->Nab]: Invalid free in ext/opcache/zend_persist.c
| From: | stas@php.net | Date: | Sat, 24 Jan 2015 23:33:30 +0000 |
| Subject: | Sec Bug->Bug #68908 [Opn->Nab]: Invalid free in ext/opcache/zend_persist.c | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-190186@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68908&edit=1
ID: 68908
Updated by: stas@php.net
Reported by: bugreports at internot dot info
-Summary: Invalid free
+Summary: Invalid free in ext/opcache/zend_persist.c
-Status: Open
+Status: Not a bug
-Type: Security
+Type: Bug
Package: opcache
Operating System: Linux Ubuntu 14.04
PHP Version: 5.5.21
Block user comment: N
Private report: Y
New Comment:
But p is reset each loop iteration, so I don't see how the same p->pData from previous loop
in line 82 can appear in line 79 in the next loop.
Previous Comments:
------------------------------------------------------------------------
[2015-01-24 23:16:55] bugreports at internot dot info
&p->pDataPtr
is a non-heap object.
------------------------------------------------------------------------
[2015-01-24 22:41:41] stas@php.net
Could you please explain what you mean? " a (void), which cannot hold memory" doesn't
make much sense to me, sorry - p->pData is a pointer, and I don't see any problem with it in
either line 79 or line 82.
------------------------------------------------------------------------
[2015-01-24 20:05:57] bugreports at internot dot info
Description:
------------
Hi,
In /ext/opcache/zend_persist.c:
This is in a while() loop, so this is possible I think:
82 p->pData = &p->pDataPtr;
79 zend_accel_store(p->pData, el_size);
which frees p->pData, but it is a (void), which cannot hold memory.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68908&edit=1