Bug #68933 [Asn->Csd]: Invalid read of size 8 in zend_std_read_property

From: Date: Fri, 06 Feb 2015 10:35:36 +0000
Subject: Bug #68933 [Asn->Csd]: Invalid read of size 8 in zend_std_read_property
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-190485@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68933&edit=1 ID: 68933 Updated by: ab@php.net Reported by: arjen at react dot com Summary: Invalid read of size 8 in zend_std_read_property -Status: Assigned +Status: Closed Type: Bug Package: Scripting Engine problem Operating System: Linux PHP Version: master-Git-2015-01-28 (Git) Assigned To: ab Block user comment: N Private report: N New Comment: Ok, looks fine so I've merged it. With the the second part of this ticket is done, thus closing. Btw. wondering whether we should already start with intergating PCRE2 into master. Previous Comments: ------------------------------------------------------------------------ [2015-02-05 02:07:59] pajoye@php.net @anatol can you tale a look at it pls? ------------------------------------------------------------------------ [2015-02-04 13:13:48] arjen at react dot com See https://github.com/php/php-src/pull/1047 ------------------------------------------------------------------------ [2015-02-02 15:03:50] arjen at react dot com Looks like the pcre memory error/segfault is fixed by upgrading the bundles pcre library to 8.36 (currently 8.35). Could you upgrade the bundles pcre lib? ------------------------------------------------------------------------ [2015-02-02 09:00:27] arjen at react dot com The error in zend_get_property_guard is fixed indeed! pcre still crashes, but with a better message now: vex amd64->IR: unhandled instruction bytes: 0x7 0x48 0xC1 0xE8 0x3 0x48 0xF 0xB6 vex amd64->IR: REX=0 REX.W=0 REX.R=0 REX.X=0 REX.B=0 vex amd64->IR: VEX=0 VEX.L=0 VEX.nVVVV=0x0 ESC=NONE vex amd64->IR: PFX.66=0 PFX.F2=0 PFX.F3=0 ==11776== Invalid read of size 4 ==11776== at 0x41CD864: ??? ==11776== by 0x4EFAF2: _pcre_jit_exec (pcre_jit_compile.c:10433) ==11776== by 0x4BCC03: php_pcre_exec (pcre_exec.c:6487) ==11776== by 0x4F29B9: php_pcre_match_impl (php_pcre.c:679) ==11776== by 0x4F25B5: php_do_pcre_match (php_pcre.c:565) ==11776== by 0x4F379F: zif_preg_match (php_pcre.c:895) ==11776== by 0x990F08: ZEND_DO_FCALL_SPEC_HANDLER (zend_vm_execute.h:596) ==11776== by 0x9904AA: execute_ex (zend_vm_execute.h:352) ==11776== by 0x92BD5F: zend_call_function (zend_execute_API.c:835) ==11776== by 0x966ED9: zend_call_method (zend_interfaces.c:101) ==11776== by 0x9675A6: zend_user_it_rewind (zend_interfaces.c:242) ==11776== by 0x9A99BB: ZEND_FE_RESET_SPEC_VAR_HANDLER (zend_vm_execute.h:11905) ==11776== Address 0xc5f13ad is 3 bytes before a block of size 4 alloc'd ==11776== at 0x4C29F90: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==11776== by 0x91385C: _emalloc (zend_alloc.c:2197) ==11776== by 0x92F164: init_op_array (zend_opcode.c:55) ==11776== by 0x920119: zend_compile_func_decl (zend_compile.c:4221) ==11776== by 0x926009: zend_compile_stmt (zend_compile.c:6241) ==11776== by 0x91EAA9: zend_compile_stmt_list (zend_compile.c:3791) ==11776== by 0x925ED2: zend_compile_stmt (zend_compile.c:6185) ==11776== by 0x92124D: zend_compile_class_decl (zend_compile.c:4627) ==11776== by 0x926047: zend_compile_stmt (zend_compile.c:6253) ==11776== by 0x925CB5: zend_compile_top_stmt (zend_compile.c:6163) ==11776== by 0x925C97: zend_compile_top_stmt (zend_compile.c:6158) ==11776== by 0x8F239F: compile_file (zend_language_scanner.l:598) ==11776== ==11776== Invalid read of size 4 ==11776== at 0x41CD867: ??? ==11776== by 0x4EFAF2: _pcre_jit_exec (pcre_jit_compile.c:10433) ==11776== by 0x4BCC03: php_pcre_exec (pcre_exec.c:6487) ==11776== by 0x4F29B9: php_pcre_match_impl (php_pcre.c:679) ==11776== by 0x4F25B5: php_do_pcre_match (php_pcre.c:565) ==11776== by 0x4F379F: zif_preg_match (php_pcre.c:895) ==11776== by 0x990F08: ZEND_DO_FCALL_SPEC_HANDLER (zend_vm_execute.h:596) ==11776== by 0x9904AA: execute_ex (zend_vm_execute.h:352) ==11776== by 0x92BD5F: zend_call_function (zend_execute_API.c:835) ==11776== by 0x966ED9: zend_call_method (zend_interfaces.c:101) ==11776== by 0x9675A6: zend_user_it_rewind (zend_interfaces.c:242) ==11776== by 0x9A99BB: ZEND_FE_RESET_SPEC_VAR_HANDLER (zend_vm_execute.h:11905) ==11776== Address 0xc5f13a7 is 9 bytes before a block of size 4 alloc'd ==11776== at 0x4C29F90: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==11776== by 0x91385C: _emalloc (zend_alloc.c:2197) ==11776== by 0x92F164: init_op_array (zend_opcode.c:55) ==11776== by 0x920119: zend_compile_func_decl (zend_compile.c:4221) ==11776== by 0x926009: zend_compile_stmt (zend_compile.c:6241) ==11776== by 0x91EAA9: zend_compile_stmt_list (zend_compile.c:3791) ==11776== by 0x925ED2: zend_compile_stmt (zend_compile.c:6185) ==11776== by 0x92124D: zend_compile_class_decl (zend_compile.c:4627) ==11776== by 0x926047: zend_compile_stmt (zend_compile.c:6253) ==11776== by 0x925CB5: zend_compile_top_stmt (zend_compile.c:6163) ==11776== by 0x925C97: zend_compile_top_stmt (zend_compile.c:6158) ==11776== by 0x8F239F: compile_file (zend_language_scanner.l:598) ==11776== ==11776== valgrind: Unrecognised instruction at address 0x41cd86b. ==11776== at 0x41CD86B: ??? ==11776== by 0x4EFAF2: _pcre_jit_exec (pcre_jit_compile.c:10433) ==11776== by 0x4BCC03: php_pcre_exec (pcre_exec.c:6487) ==11776== by 0x4F29B9: php_pcre_match_impl (php_pcre.c:679) ==11776== by 0x4F25B5: php_do_pcre_match (php_pcre.c:565) ==11776== by 0x4F379F: zif_preg_match (php_pcre.c:895) ==11776== by 0x990F08: ZEND_DO_FCALL_SPEC_HANDLER (zend_vm_execute.h:596) ==11776== by 0x9904AA: execute_ex (zend_vm_execute.h:352) ==11776== by 0x92BD5F: zend_call_function (zend_execute_API.c:835) ==11776== by 0x966ED9: zend_call_method (zend_interfaces.c:101) ==11776== by 0x9675A6: zend_user_it_rewind (zend_interfaces.c:242) ==11776== by 0x9A99BB: ZEND_FE_RESET_SPEC_VAR_HANDLER (zend_vm_execute.h:11905) But most of the times: ==12443== Invalid read of size 1 ==12443== at 0x41C7814: ??? ==12443== by 0x4EFAF2: _pcre_jit_exec (pcre_jit_compile.c:10433) ==12443== by 0x4BCC03: php_pcre_exec (pcre_exec.c:6487) ==12443== by 0x4F29B9: php_pcre_match_impl (php_pcre.c:679) ==12443== by 0x4F25B5: php_do_pcre_match (php_pcre.c:565) ==12443== by 0x4F379F: zif_preg_match (php_pcre.c:895) ==12443== by 0x990F08: ZEND_DO_FCALL_SPEC_HANDLER (zend_vm_execute.h:596) ==12443== by 0x9904AA: execute_ex (zend_vm_execute.h:352) ==12443== by 0x92BD5F: zend_call_function (zend_execute_API.c:835) ==12443== by 0x966ED9: zend_call_method (zend_interfaces.c:101) ==12443== by 0x9675A6: zend_user_it_rewind (zend_interfaces.c:242) ==12443== by 0x9A99BB: ZEND_FE_RESET_SPEC_VAR_HANDLER (zend_vm_execute.h:11905) ==12443== Address 0xffffffffffffffc4 is not stack'd, malloc'd or (recently) free'd ==12443== ==12443== ==12443== Process terminating with default action of signal 11 (SIGSEGV) ==12443== Access not within mapped region at address 0xFFFFFFFFFFFFFFC4 ==12443== at 0x41C7814: ??? ==12443== by 0x4EFAF2: _pcre_jit_exec (pcre_jit_compile.c:10433) ==12443== by 0x4BCC03: php_pcre_exec (pcre_exec.c:6487) ==12443== by 0x4F29B9: php_pcre_match_impl (php_pcre.c:679) ==12443== by 0x4F25B5: php_do_pcre_match (php_pcre.c:565) ==12443== by 0x4F379F: zif_preg_match (php_pcre.c:895) ==12443== by 0x990F08: ZEND_DO_FCALL_SPEC_HANDLER (zend_vm_execute.h:596) ==12443== by 0x9904AA: execute_ex (zend_vm_execute.h:352) ==12443== by 0x92BD5F: zend_call_function (zend_execute_API.c:835) ==12443== by 0x966ED9: zend_call_method (zend_interfaces.c:101) ==12443== by 0x9675A6: zend_user_it_rewind (zend_interfaces.c:242) ==12443== by 0x9A99BB: ZEND_FE_RESET_SPEC_VAR_HANDLER (zend_vm_execute.h:11905) ------------------------------------------------------------------------ [2015-01-31 15:55:29] laruence@php.net could you verify the pcre segfaults still there? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=68933 -- Edit this bug report at https://bugs.php.net/bug.php?id=68933&edit=1

« previous php.bugs (#190485) next »