Sec Bug->Bug #68908 [Opn->Nab]: Invalid free in ext/opcache/zend_persist.c

From: Date: Sat, 24 Jan 2015 23:33:30 +0000
Subject: Sec Bug->Bug #68908 [Opn->Nab]: Invalid free in ext/opcache/zend_persist.c
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-190186@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68908&edit=1 ID: 68908 Updated by: stas@php.net Reported by: bugreports at internot dot info -Summary: Invalid free +Summary: Invalid free in ext/opcache/zend_persist.c -Status: Open +Status: Not a bug -Type: Security +Type: Bug Package: opcache Operating System: Linux Ubuntu 14.04 PHP Version: 5.5.21 Block user comment: N Private report: Y New Comment: But p is reset each loop iteration, so I don't see how the same p->pData from previous loop in line 82 can appear in line 79 in the next loop. Previous Comments: ------------------------------------------------------------------------ [2015-01-24 23:16:55] bugreports at internot dot info &p->pDataPtr is a non-heap object. ------------------------------------------------------------------------ [2015-01-24 22:41:41] stas@php.net Could you please explain what you mean? " a (void), which cannot hold memory" doesn't make much sense to me, sorry - p->pData is a pointer, and I don't see any problem with it in either line 79 or line 82. ------------------------------------------------------------------------ [2015-01-24 20:05:57] bugreports at internot dot info Description: ------------ Hi, In /ext/opcache/zend_persist.c: This is in a while() loop, so this is possible I think: 82 p->pData = &p->pDataPtr; 79 zend_accel_store(p->pData, el_size); which frees p->pData, but it is a (void), which cannot hold memory. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68908&edit=1

« previous php.bugs (#190186) next »