Bug #69897 [Opn->Ver]: segfault when manually constructing SQLite3Result
| From: | kalle@php.net | Date: | Mon, 22 Jun 2015 09:09:27 +0000 |
| Subject: | Bug #69897 [Opn->Ver]: segfault when manually constructing SQLite3Result | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-193750@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69897&edit=1
ID: 69897
Updated by: kalle@php.net
Reported by: sjon at hortensius dot net
Summary: segfault when manually constructing SQLite3Result
-Status: Open
+Status: Verified
Type: Bug
Package: SQLite related
-Operating System: archlinux
+Operating System: *
PHP Version: 7.0.0alpha1
Block user comment: N
Private report: N
New Comment:
Confirmed on Windows too
Previous Comments:
------------------------------------------------------------------------
[2015-06-22 08:40:26] sjon at hortensius dot net
Description:
------------
SQLite3Result has a private constructor, calling it yields a correct error-message:
Fatal error: Uncaught EngineException: Call to private SQLite3Result::__construct() from invalid
context in /in/G7TZg:3
But it also results in a segfault.
Test script:
---------------
From http://3v4l.org/G7TZg
<?php
$foo = new SQLite3Result();
Expected result:
----------------
Fatal error only
Actual result:
--------------
==19072== Invalid read of size 4
==19072== at 0x4FAFC9: php_sqlite3_result_object_free_storage (sqlite3.c:2106)
==19072== by 0x990233: zend_objects_store_free_object_storage (zend_objects_API.c:102)
==19072== by 0x92DDDB: shutdown_executor (zend_execute_API.c:341)
==19072== by 0x9462F3: zend_deactivate (zend.c:964)
==19072== by 0x8B765C: php_request_shutdown (main.c:1814)
==19072== by 0xA05233: do_cli (php_cli.c:1135)
==19072== by 0xA0591B: main (php_cli.c:1334)
==19072== Address 0x20 is not stack'd, malloc'd or (recently) free'd
==19072==
==19072==
==19072== Process terminating with default action of signal 11 (SIGSEGV)
==19072== Access not within mapped region at address 0x20
==19072== at 0x4FAFC9: php_sqlite3_result_object_free_storage (sqlite3.c:2106)
==19072== by 0x990233: zend_objects_store_free_object_storage (zend_objects_API.c:102)
==19072== by 0x92DDDB: shutdown_executor (zend_execute_API.c:341)
==19072== by 0x9462F3: zend_deactivate (zend.c:964)
==19072== by 0x8B765C: php_request_shutdown (main.c:1814)
==19072== by 0xA05233: do_cli (php_cli.c:1135)
==19072== by 0xA0591B: main (php_cli.c:1334)
==19072== If you believe this happened as a result of a stack
==19072== overflow in your program's main thread (unlikely but
==19072== possible), you can try to increase the size of the
==19072== main thread stack using the --main-stacksize= flag.
==19072== The main thread stack size used in this run was 8388608.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69897&edit=1