Bug #70089 [NEW]: segfault in PHP 7 at ZEND_FETCH_DIM_W_SPEC_VAR_CONST_HANDLER ()

From: Date: Fri, 17 Jul 2015 05:14:33 +0000
Subject: Bug #70089 [NEW]: segfault in PHP 7 at ZEND_FETCH_DIM_W_SPEC_VAR_CONST_HANDLER ()
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-194503@lists.php.net to get a copy of this message
From:             brian dot carpenter at gmail dot com
Operating system: Debian 7
PHP version:      7.0Git-2015-07-17 (Git)
Package:          Reproducible crash
Bug Type:         Bug
Bug description:segfault in PHP 7 at ZEND_FETCH_DIM_W_SPEC_VAR_CONST_HANDLER ()

Description:
------------
While fuzzing PHP 7.0.0-dev (cli) (built: July 15 2015 16:00:56) with
AFL (http://lcamtuf.coredump.cx/afl/), I found this script that
segfaults at ZEND_FETCH_DIM_W_SPEC_VAR_CONST_HANDLER (). Most likely a
null ptr dereference.

Test script:
---------------
<?php
$a=ptr00tr();[];function ptr00tr(){for(;;){$o=chr(0)[0][]=0;}}

Expected result:
----------------
PHP 5.4.41-0+deb7u1 returns PHP Fatal error: Cannot use string offset as
an array in test00-min on line 2.

Actual result:
--------------
Program received signal SIGSEGV, Segmentation fault.
0x0000000001657b93 in ZEND_FETCH_DIM_W_SPEC_VAR_CONST_HANDLER ()
(gdb) bt
#0  0x0000000001657b93 in ZEND_FETCH_DIM_W_SPEC_VAR_CONST_HANDLER ()
#1  0x00000000015dc493 in execute_ex ()
#2  0x00000000017fdee5 in zend_execute ()
#3  0x000000000141373c in zend_execute_scripts ()
#4  0x00000000011bf190 in php_execute_script ()
#5  0x0000000001805679 in do_cli ()
    at /home/geeknik/php-src/sapi/cli/php_cli.c:971
#6  0x000000000043e2f1 in main ()
    at /home/geeknik/php-src/sapi/cli/php_cli.c:1338
(gdb) i r
rax            0x0	0
rbx            0x7ffff6013130	140737320661296
rcx            0x1	1
rdx            0x7ffff60554c0	140737320932544
rsi            0x7ffff6013140	140737320661312
rdi            0x4	4
rbp            0x7fffffffcfa0	0x7fffffffcfa0
rsp            0x7fffffffa920	0x7fffffffa920
r8             0x1fd37c0	33372096
r9             0x80	128
r10            0x0	0
r11            0x0	0
r12            0x7ffff60020f0	140737320591600
r13            0x1fd4820	33376288
r14            0x7ffff60130c0	140737320661184
r15            0x7ffff6086220	140737321132576
rip            0x1657b93	0x1657b93
<ZEND_FETCH_DIM_W_SPEC_VAR_CONST_HANDLER+1267>
eflags         0x10246	[ PF ZF IF RF ]
cs             0x33	51
ss             0x2b	43
ds             0x0	0
es             0x0	0
fs             0x0	0
gs             0x0	0

-- 
Edit bug report at https://bugs.php.net/bug.php?id=70089&edit=1
-- 
Try a snapshot (PHP 5.4):   https://bugs.php.net/fix.php?id=70089&r=trysnapshot54
Try a snapshot (PHP 5.5):   https://bugs.php.net/fix.php?id=70089&r=trysnapshot55
Try a snapshot (trunk):     https://bugs.php.net/fix.php?id=70089&r=trysnapshottrunk
Fixed in SVN:               https://bugs.php.net/fix.php?id=70089&r=fixed
Fixed in release:           https://bugs.php.net/fix.php?id=70089&r=alreadyfixed
Need backtrace:             https://bugs.php.net/fix.php?id=70089&r=needtrace
Need Reproduce Script:      https://bugs.php.net/fix.php?id=70089&r=needscript
Try newer version:          https://bugs.php.net/fix.php?id=70089&r=oldversion
Not developer issue:        https://bugs.php.net/fix.php?id=70089&r=support
Expected behavior:          https://bugs.php.net/fix.php?id=70089&r=notwrong
Not enough info:            https://bugs.php.net/fix.php?id=70089&r=notenoughinfo
Submitted twice:            https://bugs.php.net/fix.php?id=70089&r=submittedtwice
register_globals:           https://bugs.php.net/fix.php?id=70089&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=70089&r=php4
Daylight Savings:           https://bugs.php.net/fix.php?id=70089&r=dst
IIS Stability:              https://bugs.php.net/fix.php?id=70089&r=isapi
Install GNU Sed:            https://bugs.php.net/fix.php?id=70089&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=70089&r=float
No Zend Extensions:         https://bugs.php.net/fix.php?id=70089&r=nozend
MySQL Configuration Error:  https://bugs.php.net/fix.php?id=70089&r=mysqlcfg



Thread (3 messages)

« previous php.bugs (#194503) next »