Bug #68933 [Asn]: Invalid read of size 8 in zend_std_read_property
| From: | pajoye@php.net | Date: | Thu, 05 Feb 2015 02:08:00 +0000 |
| Subject: | Bug #68933 [Asn]: Invalid read of size 8 in zend_std_read_property | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-190469@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68933&edit=1
ID: 68933
Updated by: pajoye@php.net
Reported by: arjen at react dot com
Summary: Invalid read of size 8 in zend_std_read_property
Status: Assigned
Type: Bug
Package: Scripting Engine problem
Operating System: Linux
PHP Version: master-Git-2015-01-28 (Git)
-Assigned To: laruence
+Assigned To: ab
Block user comment: N
Private report: N
New Comment:
@anatol can you tale a look at it pls?
Previous Comments:
------------------------------------------------------------------------
[2015-02-04 13:13:48] arjen at react dot com
See https://github.com/php/php-src/pull/1047
------------------------------------------------------------------------
[2015-02-02 15:03:50] arjen at react dot com
Looks like the pcre memory error/segfault is fixed by upgrading the bundles pcre library to 8.36
(currently 8.35).
Could you upgrade the bundles pcre lib?
------------------------------------------------------------------------
[2015-02-02 09:00:27] arjen at react dot com
The error in zend_get_property_guard is fixed indeed!
pcre still crashes, but with a better message now:
vex amd64->IR: unhandled instruction bytes: 0x7 0x48 0xC1 0xE8 0x3 0x48 0xF 0xB6
vex amd64->IR: REX=0 REX.W=0 REX.R=0 REX.X=0 REX.B=0
vex amd64->IR: VEX=0 VEX.L=0 VEX.nVVVV=0x0 ESC=NONE
vex amd64->IR: PFX.66=0 PFX.F2=0 PFX.F3=0
==11776== Invalid read of size 4
==11776== at 0x41CD864: ???
==11776== by 0x4EFAF2: _pcre_jit_exec (pcre_jit_compile.c:10433)
==11776== by 0x4BCC03: php_pcre_exec (pcre_exec.c:6487)
==11776== by 0x4F29B9: php_pcre_match_impl (php_pcre.c:679)
==11776== by 0x4F25B5: php_do_pcre_match (php_pcre.c:565)
==11776== by 0x4F379F: zif_preg_match (php_pcre.c:895)
==11776== by 0x990F08: ZEND_DO_FCALL_SPEC_HANDLER (zend_vm_execute.h:596)
==11776== by 0x9904AA: execute_ex (zend_vm_execute.h:352)
==11776== by 0x92BD5F: zend_call_function (zend_execute_API.c:835)
==11776== by 0x966ED9: zend_call_method (zend_interfaces.c:101)
==11776== by 0x9675A6: zend_user_it_rewind (zend_interfaces.c:242)
==11776== by 0x9A99BB: ZEND_FE_RESET_SPEC_VAR_HANDLER (zend_vm_execute.h:11905)
==11776== Address 0xc5f13ad is 3 bytes before a block of size 4 alloc'd
==11776== at 0x4C29F90: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==11776== by 0x91385C: _emalloc (zend_alloc.c:2197)
==11776== by 0x92F164: init_op_array (zend_opcode.c:55)
==11776== by 0x920119: zend_compile_func_decl (zend_compile.c:4221)
==11776== by 0x926009: zend_compile_stmt (zend_compile.c:6241)
==11776== by 0x91EAA9: zend_compile_stmt_list (zend_compile.c:3791)
==11776== by 0x925ED2: zend_compile_stmt (zend_compile.c:6185)
==11776== by 0x92124D: zend_compile_class_decl (zend_compile.c:4627)
==11776== by 0x926047: zend_compile_stmt (zend_compile.c:6253)
==11776== by 0x925CB5: zend_compile_top_stmt (zend_compile.c:6163)
==11776== by 0x925C97: zend_compile_top_stmt (zend_compile.c:6158)
==11776== by 0x8F239F: compile_file (zend_language_scanner.l:598)
==11776==
==11776== Invalid read of size 4
==11776== at 0x41CD867: ???
==11776== by 0x4EFAF2: _pcre_jit_exec (pcre_jit_compile.c:10433)
==11776== by 0x4BCC03: php_pcre_exec (pcre_exec.c:6487)
==11776== by 0x4F29B9: php_pcre_match_impl (php_pcre.c:679)
==11776== by 0x4F25B5: php_do_pcre_match (php_pcre.c:565)
==11776== by 0x4F379F: zif_preg_match (php_pcre.c:895)
==11776== by 0x990F08: ZEND_DO_FCALL_SPEC_HANDLER (zend_vm_execute.h:596)
==11776== by 0x9904AA: execute_ex (zend_vm_execute.h:352)
==11776== by 0x92BD5F: zend_call_function (zend_execute_API.c:835)
==11776== by 0x966ED9: zend_call_method (zend_interfaces.c:101)
==11776== by 0x9675A6: zend_user_it_rewind (zend_interfaces.c:242)
==11776== by 0x9A99BB: ZEND_FE_RESET_SPEC_VAR_HANDLER (zend_vm_execute.h:11905)
==11776== Address 0xc5f13a7 is 9 bytes before a block of size 4 alloc'd
==11776== at 0x4C29F90: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
==11776== by 0x91385C: _emalloc (zend_alloc.c:2197)
==11776== by 0x92F164: init_op_array (zend_opcode.c:55)
==11776== by 0x920119: zend_compile_func_decl (zend_compile.c:4221)
==11776== by 0x926009: zend_compile_stmt (zend_compile.c:6241)
==11776== by 0x91EAA9: zend_compile_stmt_list (zend_compile.c:3791)
==11776== by 0x925ED2: zend_compile_stmt (zend_compile.c:6185)
==11776== by 0x92124D: zend_compile_class_decl (zend_compile.c:4627)
==11776== by 0x926047: zend_compile_stmt (zend_compile.c:6253)
==11776== by 0x925CB5: zend_compile_top_stmt (zend_compile.c:6163)
==11776== by 0x925C97: zend_compile_top_stmt (zend_compile.c:6158)
==11776== by 0x8F239F: compile_file (zend_language_scanner.l:598)
==11776==
==11776== valgrind: Unrecognised instruction at address 0x41cd86b.
==11776== at 0x41CD86B: ???
==11776== by 0x4EFAF2: _pcre_jit_exec (pcre_jit_compile.c:10433)
==11776== by 0x4BCC03: php_pcre_exec (pcre_exec.c:6487)
==11776== by 0x4F29B9: php_pcre_match_impl (php_pcre.c:679)
==11776== by 0x4F25B5: php_do_pcre_match (php_pcre.c:565)
==11776== by 0x4F379F: zif_preg_match (php_pcre.c:895)
==11776== by 0x990F08: ZEND_DO_FCALL_SPEC_HANDLER (zend_vm_execute.h:596)
==11776== by 0x9904AA: execute_ex (zend_vm_execute.h:352)
==11776== by 0x92BD5F: zend_call_function (zend_execute_API.c:835)
==11776== by 0x966ED9: zend_call_method (zend_interfaces.c:101)
==11776== by 0x9675A6: zend_user_it_rewind (zend_interfaces.c:242)
==11776== by 0x9A99BB: ZEND_FE_RESET_SPEC_VAR_HANDLER (zend_vm_execute.h:11905)
But most of the times:
==12443== Invalid read of size 1
==12443== at 0x41C7814: ???
==12443== by 0x4EFAF2: _pcre_jit_exec (pcre_jit_compile.c:10433)
==12443== by 0x4BCC03: php_pcre_exec (pcre_exec.c:6487)
==12443== by 0x4F29B9: php_pcre_match_impl (php_pcre.c:679)
==12443== by 0x4F25B5: php_do_pcre_match (php_pcre.c:565)
==12443== by 0x4F379F: zif_preg_match (php_pcre.c:895)
==12443== by 0x990F08: ZEND_DO_FCALL_SPEC_HANDLER (zend_vm_execute.h:596)
==12443== by 0x9904AA: execute_ex (zend_vm_execute.h:352)
==12443== by 0x92BD5F: zend_call_function (zend_execute_API.c:835)
==12443== by 0x966ED9: zend_call_method (zend_interfaces.c:101)
==12443== by 0x9675A6: zend_user_it_rewind (zend_interfaces.c:242)
==12443== by 0x9A99BB: ZEND_FE_RESET_SPEC_VAR_HANDLER (zend_vm_execute.h:11905)
==12443== Address 0xffffffffffffffc4 is not stack'd, malloc'd or (recently) free'd
==12443==
==12443==
==12443== Process terminating with default action of signal 11 (SIGSEGV)
==12443== Access not within mapped region at address 0xFFFFFFFFFFFFFFC4
==12443== at 0x41C7814: ???
==12443== by 0x4EFAF2: _pcre_jit_exec (pcre_jit_compile.c:10433)
==12443== by 0x4BCC03: php_pcre_exec (pcre_exec.c:6487)
==12443== by 0x4F29B9: php_pcre_match_impl (php_pcre.c:679)
==12443== by 0x4F25B5: php_do_pcre_match (php_pcre.c:565)
==12443== by 0x4F379F: zif_preg_match (php_pcre.c:895)
==12443== by 0x990F08: ZEND_DO_FCALL_SPEC_HANDLER (zend_vm_execute.h:596)
==12443== by 0x9904AA: execute_ex (zend_vm_execute.h:352)
==12443== by 0x92BD5F: zend_call_function (zend_execute_API.c:835)
==12443== by 0x966ED9: zend_call_method (zend_interfaces.c:101)
==12443== by 0x9675A6: zend_user_it_rewind (zend_interfaces.c:242)
==12443== by 0x9A99BB: ZEND_FE_RESET_SPEC_VAR_HANDLER (zend_vm_execute.h:11905)
------------------------------------------------------------------------
[2015-01-31 15:55:29] laruence@php.net
could you verify the pcre segfaults still there?
------------------------------------------------------------------------
[2015-01-31 10:17:03] laruence@php.net
the first part must be fixed in: https://github.com/php/php-src/commit/1a60175e2595a24ebc3b6d80a112d574c6c98f58
thanks
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68933
--
Edit this bug report at https://bugs.php.net/bug.php?id=68933&edit=1