Bug #69755 [Com]: 30 byte script causes php-cgi segfault in ZEND_CONCAT_SPEC_TMPVAR_CONST_HANDLER
| From: | brian dot carpenter at gmail dot com | Date: | Thu, 04 Jun 2015 02:22:14 +0000 |
| Subject: | Bug #69755 [Com]: 30 byte script causes php-cgi segfault in ZEND_CONCAT_SPEC_TMPVAR_CONST_HANDLER | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-193104@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69755&edit=1
ID: 69755
Comment by: brian dot carpenter at gmail dot com
Reported by: brian dot carpenter at gmail dot com
Summary: 30 byte script causes php-cgi segfault in
ZEND_CONCAT_SPEC_TMPVAR_CONST_HANDLER
Status: Open
Type: Bug
Package: Reproducible crash
Operating System: Debian 7
PHP Version: master-Git-2015-06-04 (Git)
Block user comment: N
Private report: N
New Comment:
This 11-byte example causes the same crash:
<?+"".W."";
Previous Comments:
------------------------------------------------------------------------
[2015-06-04 02:19:52] brian dot carpenter at gmail dot com
I was able to further reduce the test case to 27 bytes:
<?php
$j=c.(0);$q=<<<H
H
------------------------------------------------------------------------
[2015-06-04 02:14:57] brian dot carpenter at gmail dot com
Description:
------------
This bug was found with American Fuzzy Lop (http://lcamtuf.coredump.cx/afl/).
I pulled down the latest git source today, built it as follows (64-bit):
CC=afl-gcc ./configure
AFL_HARDEN=1 make -j8
System Info: Debian 3.2.68-1+deb7u1 x86_64, gcc 4.9.2, libc 2.13.38+deb7u8
Test script:
---------------
<?php
$j=t.(0);r();$q=<<<H
H;
Expected result:
----------------
No crash as in PHP 5.4.39-0+deb7u2 (cli) where it fails with the following message:
PHP Notice: Use of undefined constant t - assumed 't' in test on line2
PHP Fatal error: Call to undefined function r() in test on line 2
Actual result:
--------------
vex amd64->IR: unhandled instruction bytes: 0xF3 0x4D 0xF 0xBC 0xE4 0x45 0x1 0xC4
==27258== valgrind: Unrecognised instruction at address 0x13176da.
==27258== at 0x13176DA: zend_mm_alloc_pages (zend_alloc.c:483)
==27258== by 0x13194BC: zend_mm_alloc_small_slow (zend_alloc.c:1190)
==27258== by 0x155CFA3: virtual_cwd_startup (zend_virtual_cwd.c:431)
==27258== by 0x141079C: zend_startup (zend.c:640)
==27258== by 0x11C4C38: php_module_startup (main.c:2066)
==27258== by 0x181421C: php_cgi_startup (cgi_main.c:915)
==27258== by 0x43B45C: main (cgi_main.c:1894)
==27258== Your program just tried to execute an instruction that Valgrind
==27258== did not recognise. There are two possible reasons for this.
==27258== 1. Your program has a bug and erroneously jumped to a non-code
==27258== location. If you are running Memcheck and you just saw a
==27258== warning about a bad jump, it's probably your program's fault.
==27258== 2. The instruction is legitimate but Valgrind doesn't handle it,
==27258== i.e. it's Valgrind's fault. If you think this is the case or
==27258== you are not sure, please let us know and we'll try to fix it.
==27258== Either way, Valgrind will now raise a SIGILL signal which will
==27258== probably kill your program.
==27258==
==27258== Process terminating with default action of signal 4 (SIGILL)
==27258== Illegal opcode at address 0x13176DA
==27258== at 0x13176DA: zend_mm_alloc_pages (zend_alloc.c:483)
==27258== by 0x13194BC: zend_mm_alloc_small_slow (zend_alloc.c:1190)
==27258== by 0x155CFA3: virtual_cwd_startup (zend_virtual_cwd.c:431)
==27258== by 0x141079C: zend_startup (zend.c:640)
==27258== by 0x11C4C38: php_module_startup (main.c:2066)
==27258== by 0x181421C: php_cgi_startup (cgi_main.c:915)
==27258== by 0x43B45C: main (cgi_main.c:1894)
Illegal instruction
Program received signal SIGSEGV, Segmentation fault.
0x00000000016bd874 in ZEND_CONCAT_SPEC_TMPVAR_CONST_HANDLER ()
(gdb) bt
#0 0x00000000016bd874 in ZEND_CONCAT_SPEC_TMPVAR_CONST_HANDLER ()
#1 0x00000000015e0313 in execute_ex ()
#2 0x00000000017ff745 in zend_execute ()
#3 0x0000000001415a9c in zend_execute_scripts ()
#4 0x00000000011c8510 in php_execute_script ()
#5 0x00000000004426c1 in main () at /home/geeknik/php-src/sapi/cgi/cgi_main.c:2445
(gdb) i r
rax 0x7ffff6013030 140737320661040
rbx 0x7ffff60130b0 140737320661168
rcx 0x7ffff6000080 140737320583296
rdx 0x7ffff6076030 140737321066544
rsi 0x1c2dbc0 29547456
rdi 0x7ffff6063000 140737320988672
rbp 0x1 0x1
rsp 0x7fffffff93e0 0x7fffffff93e0
r8 0x6e696d2d303074 31078165068656756
r9 0x50 80
r10 0x7ffff60630a0 140737320988832
r11 0x7ffff6b54730 140737332463408
r12 0x7ffff60550a0 140737320931488
r13 0x0 0
r14 0x7ffff6013030 140737320661040
r15 0x7ffff6071100 140737321046272
rip 0x16bd874 0x16bd874 <ZEND_CONCAT_SPEC_TMPVAR_CONST_HANDLER+372>
eflags 0x10202 [ IF RF ]
cs 0x33 51
ss 0x2b 43
ds 0x0 0
es 0x0 0
fs 0x0 0
gs 0x0 0
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69755&edit=1