Bug #71278 [Nab]: libpcre3 causes PHP to crash if a crafted regex is supplied to preg_match
| From: | stas@php.net | Date: | Wed, 13 Jan 2016 23:58:37 +0000 |
| Subject: | Bug #71278 [Nab]: libpcre3 causes PHP to crash if a crafted regex is supplied to preg_match | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-198636@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71278&edit=1
ID: 71278
Updated by: stas@php.net
Reported by: v dot bakaitis at gmail dot com
Summary: libpcre3 causes PHP to crash if a crafted regex is
supplied to preg_match
Status: Not a bug
Type: Bug
Package: PCRE related
Operating System: Any
PHP Version: 5.6.16
Block user comment: N
Private report: N
New Comment:
For the record, upstream bug is https://bugs.exim.org/show_bug.cgi?id=1770
We bundle PCRE however so we may need upgrade
Previous Comments:
------------------------------------------------------------------------
[2016-01-06 04:42:35] pajoye@php.net
Afair there are already reports about circular refs or reached stack limit leading to crash
------------------------------------------------------------------------
[2016-01-05 22:20:41] stas@php.net
If it's a PCRE issue, maybe it should be reported upstream?
------------------------------------------------------------------------
[2016-01-05 07:16:33] pajoye@php.net
Increase the process stack (config in apache or for the running process) and try again, or you can
tweak the expression. You can find other reports here with a more detailed explanation about the
issue and how to work around it (may not work tho' as it depends on the expression).
However it is not something we can fix. Sorry.
Classified as "not a bug" as not related to php anyway, but libpcre.
------------------------------------------------------------------------
[2016-01-05 02:52:04] v dot bakaitis at gmail dot com
updated the title
------------------------------------------------------------------------
[2016-01-05 02:46:57] v dot bakaitis at gmail dot com
Description:
------------
libpcre3 does not properly check for circular references when numbered patterns are used, e.g.
/(((?3)))((?1))/
This results in the infinite loop in libpcre3 library that keeps on reading memory until it it
eventually causes a segfault at pcre_compile,c:2338
Test script:
---------------
<?php preg_match("/(((?3)))((?1))/", ""); ?>
Expected result:
----------------
The condition is handled by PCRE and an error is returned by the library
Actual result:
--------------
Segmentation fault. The backtrace is not included due to it's size.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=71278&edit=1