Bug #70327 [NEW]: segfault in xbuf_format_converter at spprintf.c:204
| From: | brian dot carpenter at gmail dot com | Date: | Sat, 22 Aug 2015 17:25:50 +0000 |
| Subject: | Bug #70327 [NEW]: segfault in xbuf_format_converter at spprintf.c:204 | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-195426@lists.php.net to get a copy of this message | ||
From: brian dot carpenter at gmail dot com
Operating system: Debian 7
PHP version: 7.0Git-2015-08-22 (Git)
Package: Reproducible crash
Bug Type: Bug
Bug description:segfault in xbuf_format_converter at spprintf.c:204
Description:
------------
While fuzzing PHP 7.0.0-dev (cli) (built: Aug 19 2015 16:48:48) with
AFL, I found this script that causes a segfault in xbuf_format_converter
(spprintf.c:204).
Test script:
---------------
<?php
function SG0s0G00000y0G0h(){($___=__FUNCTION__)&&!$_ and
list($_)=array_values(array_filter($GLOBALS,$___))and
0?(0):((0));}SG0s0G00000y0G0h();
Expected result:
----------------
No crash.
Actual result:
--------------
The GDB output goes on infinitely:
Program received signal SIGSEGV, Segmentation fault.
0x00000000011e3562 in xbuf_format_converter ()
(gdb) bt
#0 0x00000000011e3562 in xbuf_format_converter ()
#1 0x00000000011e974c in vspprintf ()
#2 0x00000000011ca899 in php_error_cb ()
#3 0x000000000043e7f1 in zend_error_noreturn ()
at /home/geeknik/php-src/Zend/zend.c:1166
#4 0x00000000016419a5 in ZEND_BOOL_NOT_SPEC_CV_HANDLER ()
at /home/geeknik/php-src/Zend/zend_execute.c:252
#5 0x00000000015e3ec3 in execute_ex ()
at /home/geeknik/php-src/Zend/zend_vm_execute.h:406
#6 0x00000000013bdd02 in zend_call_function ()
#7 0x0000000000f7f413 in zif_array_filter ()
#8 0x0000000001634545 in ZEND_DO_ICALL_SPEC_HANDLER ()
at /home/geeknik/php-src/Zend/zend_vm_execute.h:577
#9 0x00000000015e3ec3 in execute_ex ()
at /home/geeknik/php-src/Zend/zend_vm_execute.h:406
#10 0x00000000013bdd02 in zend_call_function ()
#11 0x0000000000f7f413 in zif_array_filter ()
#12 0x0000000001634545 in ZEND_DO_ICALL_SPEC_HANDLER ()
at /home/geeknik/php-src/Zend/zend_vm_execute.h:577
#13 0x00000000015e3ec3 in execute_ex ()
at /home/geeknik/php-src/Zend/zend_vm_execute.h:406
#14 0x00000000013bdd02 in zend_call_function ()
#15 0x0000000000f7f413 in zif_array_filter ()
#16 0x0000000001634545 in ZEND_DO_ICALL_SPEC_HANDLER ()
valgrind -q ~/php-src/sapi/cli/php test00-min
==63869== Stack overflow in thread #1: can't grow stack to 0xffe801000
==63869==
==63869== Process terminating with default action of signal 11
(SIGSEGV)
==63869== Access not within mapped region at address 0xFFE801EF8
==63869== Stack overflow in thread #1: can't grow stack to 0xffe801000
==63869== at 0x11E3562: xbuf_format_converter (spprintf.c:204)
==63869== If you believe this happened as a result of a stack
==63869== overflow in your program's main thread (unlikely but
==63869== possible), you can try to increase the size of the
==63869== main thread stack using the --main-stacksize= flag.
==63869== The main thread stack size used in this run was 8388608.
==63869== Stack overflow in thread #1: can't grow stack to 0xffe801000
==63869==
==63869== Process terminating with default action of signal 11
(SIGSEGV)
==63869== Access not within mapped region at address 0xFFE801EE8
==63869== Stack overflow in thread #1: can't grow stack to 0xffe801000
==63869== at 0x4A22620: _vgnU_freeres (vg_preloaded.c:58)
==63869== If you believe this happened as a result of a stack
==63869== overflow in your program's main thread (unlikely but
==63869== possible), you can try to increase the size of the
==63869== main thread stack using the --main-stacksize= flag.
==63869== The main thread stack size used in this run was 8388608.
Segmentation fault
--
Edit bug report at https://bugs.php.net/bug.php?id=70327&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=70327&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=70327&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=70327&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=70327&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=70327&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=70327&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=70327&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=70327&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=70327&r=support
Expected behavior: https://bugs.php.net/fix.php?id=70327&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=70327&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=70327&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=70327&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=70327&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=70327&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=70327&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=70327&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=70327&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=70327&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=70327&r=mysqlcfg