Bug #69619 [Opn->Fbk]: wrong argument for memcpy in from_zval_write_control
| From: | pollita@php.net | Date: | Sat, 30 May 2015 16:07:50 +0000 |
| Subject: | Bug #69619 [Opn->Fbk]: wrong argument for memcpy in from_zval_write_control | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-193014@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69619&edit=1
ID: 69619
Updated by: pollita@php.net
Reported by: herumi at nifty dot com
Summary: wrong argument for memcpy in from_zval_write_control
-Status: Open
+Status: Feedback
Type: Bug
Package: Sockets related
Operating System: all
PHP Version: 5.5.24
Block user comment: N
Private report: N
New Comment:
Looking at the code, your analysis certainly seems to be correct, and I'm happy enough to apply
the fix (including to prior supported branches), but I'd like to include a regression test. Do
you have some reproduce code for this?
I realize that the bug presents itself in the form of a leak, but developer builds usually have
--enable-debug turned on which produce leak warnings, so any repro which triggers the leak should
properly fail any test case which uses this code path.
Previous Comments:
------------------------------------------------------------------------
[2015-05-11 07:19:27] herumi at nifty dot com
Description:
------------
The code ext/sockets/conversion.c:914 in php-5.5.24
if (space_left < req_space) {
*control_buf = safe_erealloc(*control_buf, 2, req_space, *control_len);
*control_len += 2 * req_space;
memset(*control_buf, '\0', *control_len - *offset); // (A)
memcpy(&alloc->data, *control_buf, sizeof *control_buf); // (B)
}
Maybe th code (B) fill alloc->data with 8-byte zeros
because (A) fills *control_buf with zeros,
then the value of *control_buf is lost.
cf. https://github.com/php/php-src/blob/master/ext/sockets/conversions.c#L893
Is the correct code as the following?
memcpy(&alloc->data, control_buf, sizeof *control_buf);
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69619&edit=1