Bug #68740 [Com]: null pointer deference
| From: | thoger at redhat dot com | Date: | Thu, 28 May 2015 20:37:28 +0000 |
| Subject: | Bug #68740 [Com]: null pointer deference | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-192980@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68740&edit=1
ID: 68740
Comment by: thoger at redhat dot com
Reported by: bugreports at internot dot info
Summary: null pointer deference
Status: Closed
Type: Bug
Package: Regexps related
Operating System: Linux Ubuntu 14.04
PHP Version: master-Git-2015-01-04 (Git)
Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
Is there any test case to trigger this crash?
NULL dereference isinsets() can only happen if ncols is greater than 0. ncols is:
1276 register int ncols = (g->ncsets+(CHAR_BIT-1)) / CHAR_BIT;
ncsets is initialized to 0:
141 g->ncsets = 0;
and only changed in allocset():
1003 register int no = p->g->ncsets++;
Further on in allocset():
1010 if (no >= p->ncsalloc) { /* need another column of space */
1011 p->ncsalloc += CHAR_BIT;
...
1020 if (p->g->setbits == NULL)
1021 p->g->setbits = (uch *)malloc(nbytes);
1022 else {
1023 p->g->setbits = (uch *)realloc((unsigned char
*)p->g->setbits,
1024 nbytes);
ncsalloc is also initialized to 0 and only incremented in allocset(). Hence on the first allocset()
call, the code to allocate setbits it reached. So isinsets() NULL dereference could only happen on
failed malloc, and if subsequent SETERROR fails to halt processing as it's meant to. Is there
some code path I'm overlooking?
Previous Comments:
------------------------------------------------------------------------
[2015-04-06 05:49:13] stas@php.net
Automatic comment on behalf of laruence
Revision: http://git.php.net/?p=php-src.git;a=commit;h=9a404df382d041127eaa601b3113587df45d510d
Log: Fixed bug #68740 (NULL Pointer Dereference)
------------------------------------------------------------------------
[2015-03-31 23:02:38] kaplan@php.net
Automatic comment on behalf of laruence
Revision: http://git.php.net/?p=php-src.git;a=commit;h=059e774db013a8fc31cf2dce0e4d051580bf9d30
Log: Fixed bug #68740 (NULL Pointer Dereference)
------------------------------------------------------------------------
[2015-03-31 23:02:34] kaplan@php.net
Automatic comment on behalf of kaplanlior@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=a32c8ba719493fd2b4700c4f7db1ef130ceb7661
Log: Fixed bug #68739 (Missing break / control flow). Fixed bug #68740 (NULL Pointer Dereference).
Fixed bug #68677 (Use After Free).
------------------------------------------------------------------------
[2015-03-31 22:56:47] kaplan@php.net
Automatic comment on behalf of laruence
Revision: http://git.php.net/?p=php-src.git;a=commit;h=059e774db013a8fc31cf2dce0e4d051580bf9d30
Log: Fixed bug #68740 (NULL Pointer Dereference)
------------------------------------------------------------------------
[2015-03-31 22:56:42] kaplan@php.net
Automatic comment on behalf of kaplanlior@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=a32c8ba719493fd2b4700c4f7db1ef130ceb7661
Log: Fixed bug #68739 (Missing break / control flow). Fixed bug #68740 (NULL Pointer Dereference).
Fixed bug #68677 (Use After Free).
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68740
--
Edit this bug report at https://bugs.php.net/bug.php?id=68740&edit=1