Bug #70327 [NEW]: segfault in xbuf_format_converter at spprintf.c:204

From: Date: Sat, 22 Aug 2015 17:25:50 +0000
Subject: Bug #70327 [NEW]: segfault in xbuf_format_converter at spprintf.c:204
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-195426@lists.php.net to get a copy of this message
From: brian dot carpenter at gmail dot com Operating system: Debian 7 PHP version: 7.0Git-2015-08-22 (Git) Package: Reproducible crash Bug Type: Bug Bug description:segfault in xbuf_format_converter at spprintf.c:204 Description: ------------ While fuzzing PHP 7.0.0-dev (cli) (built: Aug 19 2015 16:48:48) with AFL, I found this script that causes a segfault in xbuf_format_converter (spprintf.c:204). Test script: --------------- <?php function SG0s0G00000y0G0h(){($___=__FUNCTION__)&&!$_ and list($_)=array_values(array_filter($GLOBALS,$___))and 0?(0):((0));}SG0s0G00000y0G0h(); Expected result: ---------------- No crash. Actual result: -------------- The GDB output goes on infinitely: Program received signal SIGSEGV, Segmentation fault. 0x00000000011e3562 in xbuf_format_converter () (gdb) bt #0 0x00000000011e3562 in xbuf_format_converter () #1 0x00000000011e974c in vspprintf () #2 0x00000000011ca899 in php_error_cb () #3 0x000000000043e7f1 in zend_error_noreturn () at /home/geeknik/php-src/Zend/zend.c:1166 #4 0x00000000016419a5 in ZEND_BOOL_NOT_SPEC_CV_HANDLER () at /home/geeknik/php-src/Zend/zend_execute.c:252 #5 0x00000000015e3ec3 in execute_ex () at /home/geeknik/php-src/Zend/zend_vm_execute.h:406 #6 0x00000000013bdd02 in zend_call_function () #7 0x0000000000f7f413 in zif_array_filter () #8 0x0000000001634545 in ZEND_DO_ICALL_SPEC_HANDLER () at /home/geeknik/php-src/Zend/zend_vm_execute.h:577 #9 0x00000000015e3ec3 in execute_ex () at /home/geeknik/php-src/Zend/zend_vm_execute.h:406 #10 0x00000000013bdd02 in zend_call_function () #11 0x0000000000f7f413 in zif_array_filter () #12 0x0000000001634545 in ZEND_DO_ICALL_SPEC_HANDLER () at /home/geeknik/php-src/Zend/zend_vm_execute.h:577 #13 0x00000000015e3ec3 in execute_ex () at /home/geeknik/php-src/Zend/zend_vm_execute.h:406 #14 0x00000000013bdd02 in zend_call_function () #15 0x0000000000f7f413 in zif_array_filter () #16 0x0000000001634545 in ZEND_DO_ICALL_SPEC_HANDLER () valgrind -q ~/php-src/sapi/cli/php test00-min ==63869== Stack overflow in thread #1: can't grow stack to 0xffe801000 ==63869== ==63869== Process terminating with default action of signal 11 (SIGSEGV) ==63869== Access not within mapped region at address 0xFFE801EF8 ==63869== Stack overflow in thread #1: can't grow stack to 0xffe801000 ==63869== at 0x11E3562: xbuf_format_converter (spprintf.c:204) ==63869== If you believe this happened as a result of a stack ==63869== overflow in your program's main thread (unlikely but ==63869== possible), you can try to increase the size of the ==63869== main thread stack using the --main-stacksize= flag. ==63869== The main thread stack size used in this run was 8388608. ==63869== Stack overflow in thread #1: can't grow stack to 0xffe801000 ==63869== ==63869== Process terminating with default action of signal 11 (SIGSEGV) ==63869== Access not within mapped region at address 0xFFE801EE8 ==63869== Stack overflow in thread #1: can't grow stack to 0xffe801000 ==63869== at 0x4A22620: _vgnU_freeres (vg_preloaded.c:58) ==63869== If you believe this happened as a result of a stack ==63869== overflow in your program's main thread (unlikely but ==63869== possible), you can try to increase the size of the ==63869== main thread stack using the --main-stacksize= flag. ==63869== The main thread stack size used in this run was 8388608. Segmentation fault -- Edit bug report at https://bugs.php.net/bug.php?id=70327&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=70327&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=70327&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=70327&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=70327&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=70327&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=70327&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=70327&r=needscript Try newer version: https://bugs.php.net/fix.php?id=70327&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=70327&r=support Expected behavior: https://bugs.php.net/fix.php?id=70327&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=70327&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=70327&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=70327&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=70327&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=70327&r=dst IIS Stability: https://bugs.php.net/fix.php?id=70327&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=70327&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=70327&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=70327&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=70327&r=mysqlcfg

« previous php.bugs (#195426) next »