Bug #69388 [Opn->Asn]: Use after free on recursieve calls to PHP compiler
| From: | dmitry@php.net | Date: | Mon, 06 Apr 2015 20:41:55 +0000 |
| Subject: | Bug #69388 [Opn->Asn]: Use after free on recursieve calls to PHP compiler | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-191860@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69388&edit=1
ID: 69388
Updated by: dmitry@php.net
Reported by: dmitry@php.net
Summary: Use after free on recursieve calls to PHP compiler
-Status: Open
+Status: Assigned
Type: Bug
Package: Scripting Engine problem
Operating System: *
PHP Version: master-Git-2015-04-06 (Git)
-Assigned To:
+Assigned To: nikic
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2015-04-06 20:41:14] dmitry@php.net
Description:
------------
The bug visible only with opcache disabled. PHP-5.5 and 5.6 are not affected.
Test script:
---------------
<?php
error_reporting(E_ALL | E_STRICT);
function handle_error($code, $message, $file, $line, $context) {
if (!function_exists("bla")) {
eval('function bla($s) {echo "$s\n";}');
}
bla($message);
}
set_error_handler('handle_error');
eval('namespace {use Exception;}');
Expected result:
----------------
The use statement with non-compound name 'Exception' has no effect
Actual result:
--------------
The use statement with non-compound name 'Exception' has no effect
==24404== Invalid read of size 4
==24404== at 0x85E9F42: _zend_is_inconsistent (zend_hash.c:44)
==24404== by 0x85EB22F: _zend_hash_add_or_update_i (zend_hash.c:475)
==24404== by 0x85EB522: _zend_hash_add (zend_hash.c:537)
==24404== by 0x85B6F4B: zend_hash_add_ptr (zend_hash.h:458)
==24404== by 0x85C2753: zend_compile_use (zend_compile.c:5188)
==24404== by 0x85C66B4: zend_compile_stmt (zend_compile.c:6726)
==24404== by 0x85C62E2: zend_compile_top_stmt (zend_compile.c:6630)
==24404== by 0x85C62C3: zend_compile_top_stmt (zend_compile.c:6625)
==24404== by 0x85C2C5D: zend_compile_namespace (zend_compile.c:5329)
==24404== by 0x85C66D4: zend_compile_stmt (zend_compile.c:6732)
==24404== by 0x85C62E2: zend_compile_top_stmt (zend_compile.c:6630)
==24404== by 0x85C62C3: zend_compile_top_stmt (zend_compile.c:6625)
==24404== Address 0x6d82b80 is 8 bytes inside a block of size 44 free'd
==24404== at 0x400826D: free (in /usr/lib/valgrind/vgpreload_memcheck-x86-linux.so)
==24404== by 0x85B6142: _efree (zend_alloc.c:2216)
==24404== by 0x85BA838: zend_reset_import_tables (zend_compile.c:1628)
==24404== by 0x85BA8D7: zend_end_namespace (zend_compile.c:1648)
==24404== by 0x85BA90F: zend_do_end_compilation (zend_compile.c:1659)
==24404== by 0x859E02B: compile_string (zend_language_scanner.l:753)
==24404== by 0x8627865: ZEND_INCLUDE_OR_EVAL_SPEC_CONST_HANDLER (zend_vm_execute.h:3364)
==24404== by 0x8621632: execute_ex (zend_vm_execute.h:394)
==24404== by 0x85CAEEA: zend_call_function (zend_execute_API.c:838)
==24404== by 0x85CA732: call_user_function_ex (zend_execute_API.c:661)
==24404== by 0x85DD295: zend_error (zend.c:1231)
==24404== by 0x85C24F2: zend_compile_use (zend_compile.c:5125)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69388&edit=1