Bug #71197 [Asn]: 2 more segfaults in PHP's range() function

From: Date: Tue, 22 Dec 2015 16:39:01 +0000
Subject: Bug #71197 [Asn]: 2 more segfaults in PHP's range() function
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-198148@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71197&edit=1 ID: 71197 Updated by: tpunt@php.net Reported by: tpunt@php.net Summary: 2 more segfaults in PHP's range() function Status: Assigned Type: Bug Package: Reproducible crash Operating System: Mac OS X Yosemite PHP Version: 7.0.1 Assigned To: tpunt Block user comment: N Private report: N New Comment: PR: https://github.com/php/php-src/pull/1690 Previous Comments: ------------------------------------------------------------------------ [2015-12-22 15:58:07] tpunt@php.net Description: ------------ The segfaults are caused by precision loss of large longs being converted to doubles when the step parameter is a double. The for loops continue infinitely since the step being added/subtracted upon each iteration is too small to be represented accurately as a double. The attached patch adds another condition to each of the for loops by ensuring that the number of iterations in the loop are less than the size of the range (__calc_size). This prevents both loops from continuing until segfaulting, however doesn't give an accurate result (due to __calc_size being incorrect because of aforementioned precision loss). Test script: --------------- var_dump(count(range(PHP_INT_MIN, PHP_INT_MIN + 513, .01))); var_dump(count(range(PHP_INT_MIN + 513, PHP_INT_MIN, .01))); Expected result: ---------------- // A completely correct output would be: int(51400) int(51400) Actual result: -------------- Segmentation fault: 11 Segmentation fault: 11 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=71197&edit=1

« previous php.bugs (#198148) next »