Bug #69619 [Opn->Fbk]: wrong argument for memcpy in from_zval_write_control

From: Date: Sat, 30 May 2015 16:07:50 +0000
Subject: Bug #69619 [Opn->Fbk]: wrong argument for memcpy in from_zval_write_control
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-193014@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69619&edit=1 ID: 69619 Updated by: pollita@php.net Reported by: herumi at nifty dot com Summary: wrong argument for memcpy in from_zval_write_control -Status: Open +Status: Feedback Type: Bug Package: Sockets related Operating System: all PHP Version: 5.5.24 Block user comment: N Private report: N New Comment: Looking at the code, your analysis certainly seems to be correct, and I'm happy enough to apply the fix (including to prior supported branches), but I'd like to include a regression test. Do you have some reproduce code for this? I realize that the bug presents itself in the form of a leak, but developer builds usually have --enable-debug turned on which produce leak warnings, so any repro which triggers the leak should properly fail any test case which uses this code path. Previous Comments: ------------------------------------------------------------------------ [2015-05-11 07:19:27] herumi at nifty dot com Description: ------------ The code ext/sockets/conversion.c:914 in php-5.5.24 if (space_left < req_space) { *control_buf = safe_erealloc(*control_buf, 2, req_space, *control_len); *control_len += 2 * req_space; memset(*control_buf, '\0', *control_len - *offset); // (A) memcpy(&alloc->data, *control_buf, sizeof *control_buf); // (B) } Maybe th code (B) fill alloc->data with 8-byte zeros because (A) fills *control_buf with zeros, then the value of *control_buf is lost. cf. https://github.com/php/php-src/blob/master/ext/sockets/conversions.c#L893 Is the correct code as the following? memcpy(&alloc->data, control_buf, sizeof *control_buf); ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=69619&edit=1

« previous php.bugs (#193014) next »