Bug #68933 [NEW]: Invalid read of size 8 in zend_std_read_property
| From: | arjen at react dot com | Date: | Wed, 28 Jan 2015 13:04:33 +0000 |
| Subject: | Bug #68933 [NEW]: Invalid read of size 8 in zend_std_read_property | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-190265@lists.php.net to get a copy of this message | ||
From: arjen at react dot com
Operating system: Linux
PHP version: master-Git-2015-01-28 (Git)
Package: Scripting Engine problem
Bug Type: Bug
Bug description:Invalid read of size 8 in zend_std_read_property
Description:
------------
Running complete testsuite with valgrind (USE_ZEND_ALLOC=0 valgrind
--vgdb-error=1 --track-origins=yes --leak-check=full
php-src/sapi/cli/php testsuite.php) gives following error:
==27978== Invalid read of size 8
==27978== at 0x97C7E7: zend_std_read_property
(zend_object_handlers.c:540)
==27978== by 0x9ACB6A: ZEND_FETCH_OBJ_R_SPEC_VAR_CONST_HANDLER
(zend_vm_execute.h:13108)
==27978== by 0x98ED2A: execute_ex (zend_vm_execute.h:352)
==27978== by 0x98EE83: zend_execute (zend_vm_execute.h:381)
==27978== by 0x941C8C: zend_execute_scripts (zend.c:1271)
==27978== by 0x8B8BEA: php_execute_script (main.c:2554)
==27978== by 0x9E512E: do_cli (php_cli.c:982)
==27978== by 0x9E60D7: main (php_cli.c:1361)
==27978== Address 0xd34a220 is 480 bytes inside a block of size 576
free'd
==27978== at 0x4C2C29E: realloc (in
/usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==27978== by 0x9121D8: _erealloc (zend_alloc.c:2219)
==27978== by 0x9123D3: _safe_erealloc (zend_alloc.c:2257)
==27978== by 0x953B41: zend_hash_do_resize (zend_hash.c:573)
==27978== by 0x95296E: _zend_hash_add_or_update_i (zend_hash.c:299)
==27978== by 0x952BFF: _zend_hash_add_new (zend_hash.c:343)
==27978== by 0x97C54C: zend_get_property_guard
(zend_object_handlers.c:490)
==27978== by 0x97C73B: zend_std_read_property
(zend_object_handlers.c:532)
==27978== by 0x9ACB6A: ZEND_FETCH_OBJ_R_SPEC_VAR_CONST_HANDLER
(zend_vm_execute.h:13108)
==27978== by 0x98ED2A: execute_ex (zend_vm_execute.h:352)
==27978== by 0x92A5E8: zend_call_function (zend_execute_API.c:835)
==27978== by 0x965853: zend_call_method (zend_interfaces.c:101)
After this error another error is triggered and ends with a segfault:
==27978== Invalid write of size 8
==27978== at 0x97C7F5: zend_std_read_property
(zend_object_handlers.c:540)
==27978== by 0x9ACB6A: ZEND_FETCH_OBJ_R_SPEC_VAR_CONST_HANDLER
(zend_vm_execute.h:13108)
==27978== by 0x98ED2A: execute_ex (zend_vm_execute.h:352)
==27978== by 0x98EE83: zend_execute (zend_vm_execute.h:381)
==27978== by 0x941C8C: zend_execute_scripts (zend.c:1271)
==27978== by 0x8B8BEA: php_execute_script (main.c:2554)
==27978== by 0x9E512E: do_cli (php_cli.c:982)
==27978== by 0x9E60D7: main (php_cli.c:1361)
==27978== Address 0xd34a220 is 480 bytes inside a block of size 576
free'd
==27978== at 0x4C2C29E: realloc (in
/usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==27978== by 0x9121D8: _erealloc (zend_alloc.c:2219)
==27978== by 0x9123D3: _safe_erealloc (zend_alloc.c:2257)
==27978== by 0x953B41: zend_hash_do_resize (zend_hash.c:573)
==27978== by 0x95296E: _zend_hash_add_or_update_i (zend_hash.c:299)
==27978== by 0x952BFF: _zend_hash_add_new (zend_hash.c:343)
==27978== by 0x97C54C: zend_get_property_guard
(zend_object_handlers.c:490)
==27978== by 0x97C73B: zend_std_read_property
(zend_object_handlers.c:532)
==27978== by 0x9ACB6A: ZEND_FETCH_OBJ_R_SPEC_VAR_CONST_HANDLER
(zend_vm_execute.h:13108)
==27978== by 0x98ED2A: execute_ex (zend_vm_execute.h:352)
==27978== by 0x92A5E8: zend_call_function (zend_execute_API.c:835)
==27978== by 0x965853: zend_call_method (zend_interfaces.c:101)
==27978==
==27978== (action on error) vgdb me ...
==27978== Invalid read of size 1
==27978== at 0x41C7814: ???
==27978== by 0x4EF798: _pcre_jit_exec (pcre_jit_compile.c:10433)
==27978== by 0x4BC8A9: php_pcre_exec (pcre_exec.c:6487)
==27978== by 0x4F265F: php_pcre_match_impl (php_pcre.c:679)
==27978== by 0x4F225B: php_do_pcre_match (php_pcre.c:565)
==27978== by 0x4F3445: zif_preg_match (php_pcre.c:895)
==27978== by 0x98F788: ZEND_DO_FCALL_SPEC_HANDLER
(zend_vm_execute.h:596)
==27978== by 0x98ED2A: execute_ex (zend_vm_execute.h:352)
==27978== by 0x92A5E8: zend_call_function (zend_execute_API.c:835)
==27978== by 0x965853: zend_call_method (zend_interfaces.c:101)
==27978== by 0x965F20: zend_user_it_rewind (zend_interfaces.c:242)
==27978== by 0x9A823B: ZEND_FE_RESET_SPEC_VAR_HANDLER
(zend_vm_execute.h:11903)
==27978== Address 0xffffffffffffffc4 is not stack'd, malloc'd or
(recently) free'd
==27978==
==27978== (action on error) vgdb me ...
==27978== Continuing ...
==27978==
==27978== Process terminating with default action of signal 11
(SIGSEGV)
==27978== Access not within mapped region at address
0xFFFFFFFFFFFFFFC4
==27978== at 0x41C7814: ???
==27978== by 0x4EF798: _pcre_jit_exec (pcre_jit_compile.c:10433)
==27978== by 0x4BC8A9: php_pcre_exec (pcre_exec.c:6487)
==27978== by 0x4F265F: php_pcre_match_impl (php_pcre.c:679)
==27978== by 0x4F225B: php_do_pcre_match (php_pcre.c:565)
==27978== by 0x4F3445: zif_preg_match (php_pcre.c:895)
==27978== by 0x98F788: ZEND_DO_FCALL_SPEC_HANDLER
(zend_vm_execute.h:596)
==27978== by 0x98ED2A: execute_ex (zend_vm_execute.h:352)
==27978== by 0x92A5E8: zend_call_function (zend_execute_API.c:835)
==27978== by 0x965853: zend_call_method (zend_interfaces.c:101)
==27978== by 0x965F20: zend_user_it_rewind (zend_interfaces.c:242)
==27978== by 0x9A823B: ZEND_FE_RESET_SPEC_VAR_HANDLER
(zend_vm_execute.h:11903)
Test script:
---------------
No simple testcase available.
Expected result:
----------------
No memory errors or segfault.
--
Edit bug report at https://bugs.php.net/bug.php?id=68933&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=68933&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=68933&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=68933&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=68933&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=68933&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=68933&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=68933&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=68933&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=68933&r=support
Expected behavior: https://bugs.php.net/fix.php?id=68933&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=68933&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=68933&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=68933&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=68933&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=68933&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=68933&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=68933&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=68933&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=68933&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=68933&r=mysqlcfg