Bug #70239 [Ana->Csd]: Creating a huge array doesn't result in exhausted, but segfault
| From: | ab@php.net | Date: | Fri, 14 Aug 2015 12:35:15 +0000 |
| Subject: | Bug #70239 [Ana->Csd]: Creating a huge array doesn't result in exhausted, but segfault | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-195207@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70239&edit=1
ID: 70239
Updated by: ab@php.net
Reported by: sjon at hortensius dot net
Summary: Creating a huge array doesn't result in exhausted,
but segfault
-Status: Analyzed
+Status: Closed
Type: Bug
Package: Reproducible crash
PHP Version: 7.0.0beta3
Assigned To: ab
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of ab
Revision: http://git.php.net/?p=php-src.git;a=commit;h=01ee09f3f70284183679d403d2a2ae1928689573
Log: Fixed bug #70239 Creating a huge array doesn't result in exhausted, but segfault
Previous Comments:
------------------------------------------------------------------------
[2015-08-11 14:06:25] laruence@php.net
hmm, actually, this is the same as the previously one. (uint32)((double)(very big value)) result in
zero...
------------------------------------------------------------------------
[2015-08-11 13:35:54] sjon at hortensius dot net
I don't know what is considered *infinite* in php, but the same thing happens with large
numbers like PHP_INT_MAX/2, see http://3v4l.org/BSYs8
------------------------------------------------------------------------
[2015-08-11 13:30:59] laruence@php.net
a fix could be:
$ git diff
diff --git a/ext/standard/array.c b/ext/standard/array.c
index 7ef9d73..8745149 100644
--- a/ext/standard/array.c
+++ b/ext/standard/array.c
@@ -1739,6 +1739,11 @@ double_str:
high = zval_get_double(zhigh);
i = 0;
+ if (zend_isinf(high) || zend_isinf(low)) {
+ php_error_docref(NULL, E_WARNING, "Range is too big");
+ RETURN_FALSE;
+ }
+
Z_TYPE_INFO(tmp) = IS_DOUBLE;
if (low > high) { /* Negative steps */
if (low - high < step || step <= 0) {
but I am not sure what the proper error message should be?
------------------------------------------------------------------------
[2015-08-11 12:25:31] sjon at hortensius dot net
Description:
------------
This only started happening in php-7, before that it would work better
Test script:
---------------
from http://3v4l.org/ToUVn
<?php
range(0, pow(2.0, 100000000));
Expected result:
----------------
Fatal error: Allowed memory size of xxx bytes exhausted (tried to allocate 32 bytes) in /in/ToUVn on
line 2
Process exited with code 255.
Actual result:
--------------
Process exited with code 139.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70239&edit=1