Bug #69897 [NEW]: segfault when manually constructing SQLite3Result
| From: | sjon at hortensius dot net | Date: | Mon, 22 Jun 2015 08:40:28 +0000 |
| Subject: | Bug #69897 [NEW]: segfault when manually constructing SQLite3Result | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-193748@lists.php.net to get a copy of this message | ||
From: sjon at hortensius dot net
Operating system: archlinux
PHP version: 7.0.0alpha1
Package: SQLite related
Bug Type: Bug
Bug description:segfault when manually constructing SQLite3Result
Description:
------------
SQLite3Result has a private constructor, calling it yields a correct
error-message:
Fatal error: Uncaught EngineException: Call to private
SQLite3Result::__construct() from invalid context in /in/G7TZg:3
But it also results in a segfault.
Test script:
---------------
From http://3v4l.org/G7TZg
<?php
$foo = new SQLite3Result();
Expected result:
----------------
Fatal error only
Actual result:
--------------
==19072== Invalid read of size 4
==19072== at 0x4FAFC9: php_sqlite3_result_object_free_storage
(sqlite3.c:2106)
==19072== by 0x990233: zend_objects_store_free_object_storage
(zend_objects_API.c:102)
==19072== by 0x92DDDB: shutdown_executor (zend_execute_API.c:341)
==19072== by 0x9462F3: zend_deactivate (zend.c:964)
==19072== by 0x8B765C: php_request_shutdown (main.c:1814)
==19072== by 0xA05233: do_cli (php_cli.c:1135)
==19072== by 0xA0591B: main (php_cli.c:1334)
==19072== Address 0x20 is not stack'd, malloc'd or (recently) free'd
==19072==
==19072==
==19072== Process terminating with default action of signal 11
(SIGSEGV)
==19072== Access not within mapped region at address 0x20
==19072== at 0x4FAFC9: php_sqlite3_result_object_free_storage
(sqlite3.c:2106)
==19072== by 0x990233: zend_objects_store_free_object_storage
(zend_objects_API.c:102)
==19072== by 0x92DDDB: shutdown_executor (zend_execute_API.c:341)
==19072== by 0x9462F3: zend_deactivate (zend.c:964)
==19072== by 0x8B765C: php_request_shutdown (main.c:1814)
==19072== by 0xA05233: do_cli (php_cli.c:1135)
==19072== by 0xA0591B: main (php_cli.c:1334)
==19072== If you believe this happened as a result of a stack
==19072== overflow in your program's main thread (unlikely but
==19072== possible), you can try to increase the size of the
==19072== main thread stack using the --main-stacksize= flag.
==19072== The main thread stack size used in this run was 8388608.
--
Edit bug report at https://bugs.php.net/bug.php?id=69897&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=69897&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=69897&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=69897&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=69897&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=69897&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=69897&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=69897&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=69897&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=69897&r=support
Expected behavior: https://bugs.php.net/fix.php?id=69897&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=69897&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=69897&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=69897&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=69897&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=69897&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=69897&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=69897&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=69897&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=69897&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=69897&r=mysqlcfg