Bug #68740 [Com]: null pointer deference

From: Date: Thu, 28 May 2015 20:37:28 +0000
Subject: Bug #68740 [Com]: null pointer deference
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-192980@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68740&edit=1 ID: 68740 Comment by: thoger at redhat dot com Reported by: bugreports at internot dot info Summary: null pointer deference Status: Closed Type: Bug Package: Regexps related Operating System: Linux Ubuntu 14.04 PHP Version: master-Git-2015-01-04 (Git) Assigned To: laruence Block user comment: N Private report: N New Comment: Is there any test case to trigger this crash? NULL dereference isinsets() can only happen if ncols is greater than 0. ncols is: 1276 register int ncols = (g->ncsets+(CHAR_BIT-1)) / CHAR_BIT; ncsets is initialized to 0: 141 g->ncsets = 0; and only changed in allocset(): 1003 register int no = p->g->ncsets++; Further on in allocset(): 1010 if (no >= p->ncsalloc) { /* need another column of space */ 1011 p->ncsalloc += CHAR_BIT; ... 1020 if (p->g->setbits == NULL) 1021 p->g->setbits = (uch *)malloc(nbytes); 1022 else { 1023 p->g->setbits = (uch *)realloc((unsigned char *)p->g->setbits, 1024 nbytes); ncsalloc is also initialized to 0 and only incremented in allocset(). Hence on the first allocset() call, the code to allocate setbits it reached. So isinsets() NULL dereference could only happen on failed malloc, and if subsequent SETERROR fails to halt processing as it's meant to. Is there some code path I'm overlooking? Previous Comments: ------------------------------------------------------------------------ [2015-04-06 05:49:13] stas@php.net Automatic comment on behalf of laruence Revision: http://git.php.net/?p=php-src.git;a=commit;h=9a404df382d041127eaa601b3113587df45d510d Log: Fixed bug #68740 (NULL Pointer Dereference) ------------------------------------------------------------------------ [2015-03-31 23:02:38] kaplan@php.net Automatic comment on behalf of laruence Revision: http://git.php.net/?p=php-src.git;a=commit;h=059e774db013a8fc31cf2dce0e4d051580bf9d30 Log: Fixed bug #68740 (NULL Pointer Dereference) ------------------------------------------------------------------------ [2015-03-31 23:02:34] kaplan@php.net Automatic comment on behalf of kaplanlior@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=a32c8ba719493fd2b4700c4f7db1ef130ceb7661 Log: Fixed bug #68739 (Missing break / control flow). Fixed bug #68740 (NULL Pointer Dereference). Fixed bug #68677 (Use After Free). ------------------------------------------------------------------------ [2015-03-31 22:56:47] kaplan@php.net Automatic comment on behalf of laruence Revision: http://git.php.net/?p=php-src.git;a=commit;h=059e774db013a8fc31cf2dce0e4d051580bf9d30 Log: Fixed bug #68740 (NULL Pointer Dereference) ------------------------------------------------------------------------ [2015-03-31 22:56:42] kaplan@php.net Automatic comment on behalf of kaplanlior@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=a32c8ba719493fd2b4700c4f7db1ef130ceb7661 Log: Fixed bug #68739 (Missing break / control flow). Fixed bug #68740 (NULL Pointer Dereference). Fixed bug #68677 (Use After Free). ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=68740 -- Edit this bug report at https://bugs.php.net/bug.php?id=68740&edit=1

« previous php.bugs (#192980) next »