Bug #69149 [Ver->Csd]: The PCRE extension crashes seeminglessly due to memory leaks or double free
Edit report at https://bugs.php.net/bug.php?id=69149&edit=1
ID: 69149
Updated by: ab@php.net
Reported by: gregory at luni dot fr
Summary: The PCRE extension crashes seeminglessly due to
memory leaks or double free
-Status: Verified
+Status: Closed
Type: Bug
Package: *Regular Expressions
Operating System: OSX, Linux
PHP Version: master-Git-2015-02-28 (Git)
-Assigned To:
+Assigned To: ab
Block user comment: N
Private report: N
New Comment:
This fixed with the upgrade to PCRE 8.37.
Previous Comments:
------------------------------------------------------------------------
[2015-03-05 09:14:13] hzmester at freemail dot hu
Fixed in PCRE r1530. I will port the patch to PCRE2 soon. Thank you for the report.
------------------------------------------------------------------------
[2015-03-04 18:47:25] hzmester at freemail dot hu
This is a valid bug and related to the alternative compiling again, but with recursion. E.g:
/(?:a|b|c|d|e)(?R)/ I try to fix it soon. Thank you for finding it.
------------------------------------------------------------------------
[2015-03-04 11:09:23] gregory at luni dot fr
This is what the php7 -i command returns about PCRE :
pcre
PCRE (Perl Compatible Regular Expressions) Support => enabled
PCRE Library Version => 8.36 2014-09-26
PCRE JIT Support => enabled
Directive => Local Value => Master Value
pcre.backtrack_limit => 1000000 => 1000000
pcre.jit => 1 => 1
pcre.recursion_limit => 100000 => 100000
The version is 8.36, maybe this bug wasn't fixed since 8.35.
------------------------------------------------------------------------
[2015-03-04 07:37:39] hzmester at freemail dot hu
Which pcre version? As far as I remember 8.35 has an alternative compiling bug.
------------------------------------------------------------------------
[2015-03-01 15:27:29] laruence@php.net
seems it's a bug in pcrelib .. anyway, must related to pcre jit we introduced recently.
php -d pcre.jit=0 runs fine..
==6629== Invalid write of size 8
==6629== at 0x4DEDE6: _pcre_jit_compile (pcre_jit_compile.c:10313)
==6629== by 0x4B532E: php_pcre_study (pcre_study.c:1585)
==6629== by 0x4E440D: pcre_get_compiled_regex_cache (php_pcre.c:420)
==6629== by 0x4E4F46: php_do_pcre_match (php_pcre.c:570)
==6629== by 0x4E6861: zif_preg_match (php_pcre.c:904)
==6629== by 0xA86BE2: ZEND_DO_ICALL_SPEC_HANDLER (zend_vm_execute.h:511)
==6629== by 0xA863E8: execute_ex (zend_vm_execute.h:352)
==6629== by 0xA86543: zend_execute (zend_vm_execute.h:381)
==6629== by 0xA36775: zend_execute_scripts (zend.c:1282)
==6629== by 0x9A8220: php_execute_script (main.c:2527)
==6629== by 0xAE349D: do_cli (php_cli.c:979)
==6629== by 0xAE452E: main (php_cli.c:1355)
==6629== Address 0x11a2bc88 is 24 bytes before a block of size 120 alloc'd
==6629== at 0x4A078B8: malloc (vg_replace_malloc.c:270)
==6629== by 0x4B701C: sljit_create_compiler (sljitLir.c:335)
==6629== by 0x4DD55B: _pcre_jit_compile (pcre_jit_compile.c:9964)
==6629== by 0x4B532E: php_pcre_study (pcre_study.c:1585)
==6629== by 0x4E440D: pcre_get_compiled_regex_cache (php_pcre.c:420)
==6629== by 0x4E4F46: php_do_pcre_match (php_pcre.c:570)
==6629== by 0x4E6861: zif_preg_match (php_pcre.c:904)
==6629== by 0xA86BE2: ZEND_DO_ICALL_SPEC_HANDLER (zend_vm_execute.h:511)
==6629== by 0xA863E8: execute_ex (zend_vm_execute.h:352)
==6629== by 0xA86543: zend_execute (zend_vm_execute.h:381)
==6629== by 0xA36775: zend_execute_scripts (zend.c:1282)
==6629== by 0x9A8220: php_execute_script (main.c:2527)
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=69149
--
Edit this bug report at https://bugs.php.net/bug.php?id=69149&edit=1
Thread (10 messages)