Bug #70239 [Ana->Csd]: Creating a huge array doesn't result in exhausted, but segfault

From: Date: Fri, 14 Aug 2015 12:35:15 +0000
Subject: Bug #70239 [Ana->Csd]: Creating a huge array doesn't result in exhausted, but segfault
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-195207@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70239&edit=1 ID: 70239 Updated by: ab@php.net Reported by: sjon at hortensius dot net Summary: Creating a huge array doesn't result in exhausted, but segfault -Status: Analyzed +Status: Closed Type: Bug Package: Reproducible crash PHP Version: 7.0.0beta3 Assigned To: ab Block user comment: N Private report: N New Comment: Automatic comment on behalf of ab Revision: http://git.php.net/?p=php-src.git;a=commit;h=01ee09f3f70284183679d403d2a2ae1928689573 Log: Fixed bug #70239 Creating a huge array doesn't result in exhausted, but segfault Previous Comments: ------------------------------------------------------------------------ [2015-08-11 14:06:25] laruence@php.net hmm, actually, this is the same as the previously one. (uint32)((double)(very big value)) result in zero... ------------------------------------------------------------------------ [2015-08-11 13:35:54] sjon at hortensius dot net I don't know what is considered *infinite* in php, but the same thing happens with large numbers like PHP_INT_MAX/2, see http://3v4l.org/BSYs8 ------------------------------------------------------------------------ [2015-08-11 13:30:59] laruence@php.net a fix could be: $ git diff diff --git a/ext/standard/array.c b/ext/standard/array.c index 7ef9d73..8745149 100644 --- a/ext/standard/array.c +++ b/ext/standard/array.c @@ -1739,6 +1739,11 @@ double_str: high = zval_get_double(zhigh); i = 0; + if (zend_isinf(high) || zend_isinf(low)) { + php_error_docref(NULL, E_WARNING, "Range is too big"); + RETURN_FALSE; + } + Z_TYPE_INFO(tmp) = IS_DOUBLE; if (low > high) { /* Negative steps */ if (low - high < step || step <= 0) { but I am not sure what the proper error message should be? ------------------------------------------------------------------------ [2015-08-11 12:25:31] sjon at hortensius dot net Description: ------------ This only started happening in php-7, before that it would work better Test script: --------------- from http://3v4l.org/ToUVn <?php range(0, pow(2.0, 100000000)); Expected result: ---------------- Fatal error: Allowed memory size of xxx bytes exhausted (tried to allocate 32 bytes) in /in/ToUVn on line 2 Process exited with code 255. Actual result: -------------- Process exited with code 139. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70239&edit=1

« previous php.bugs (#195207) next »