Bug #71278 [Nab]: libpcre3 causes PHP to crash if a crafted regex is supplied to preg_match

From: Date: Wed, 13 Jan 2016 23:58:37 +0000
Subject: Bug #71278 [Nab]: libpcre3 causes PHP to crash if a crafted regex is supplied to preg_match
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-198636@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71278&edit=1 ID: 71278 Updated by: stas@php.net Reported by: v dot bakaitis at gmail dot com Summary: libpcre3 causes PHP to crash if a crafted regex is supplied to preg_match Status: Not a bug Type: Bug Package: PCRE related Operating System: Any PHP Version: 5.6.16 Block user comment: N Private report: N New Comment: For the record, upstream bug is https://bugs.exim.org/show_bug.cgi?id=1770 We bundle PCRE however so we may need upgrade Previous Comments: ------------------------------------------------------------------------ [2016-01-06 04:42:35] pajoye@php.net Afair there are already reports about circular refs or reached stack limit leading to crash ------------------------------------------------------------------------ [2016-01-05 22:20:41] stas@php.net If it's a PCRE issue, maybe it should be reported upstream? ------------------------------------------------------------------------ [2016-01-05 07:16:33] pajoye@php.net Increase the process stack (config in apache or for the running process) and try again, or you can tweak the expression. You can find other reports here with a more detailed explanation about the issue and how to work around it (may not work tho' as it depends on the expression). However it is not something we can fix. Sorry. Classified as "not a bug" as not related to php anyway, but libpcre. ------------------------------------------------------------------------ [2016-01-05 02:52:04] v dot bakaitis at gmail dot com updated the title ------------------------------------------------------------------------ [2016-01-05 02:46:57] v dot bakaitis at gmail dot com Description: ------------ libpcre3 does not properly check for circular references when numbered patterns are used, e.g. /(((?3)))((?1))/ This results in the infinite loop in libpcre3 library that keeps on reading memory until it it eventually causes a segfault at pcre_compile,c:2338 Test script: --------------- <?php preg_match("/(((?3)))((?1))/", ""); ?> Expected result: ---------------- The condition is handled by PCRE and an error is returned by the library Actual result: -------------- Segmentation fault. The backtrace is not included due to it's size. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=71278&edit=1

« previous php.bugs (#198636) next »