Bug #71778 [NEW]: zend_std_get_method() inconsistently increments the method_name refcount

From: Date: Thu, 10 Mar 2016 22:26:13 +0000
Subject: Bug #71778 [NEW]: zend_std_get_method() inconsistently increments the method_name refcount
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-199744@lists.php.net to get a copy of this message
From: aharvey Operating system: Irrelevant PHP version: 7.0Git-2016-03-10 (Git) Package: Scripting Engine problem Bug Type: Bug Bug description:zend_std_get_method() inconsistently increments the method_name refcount Description: ------------ I'll file a PR for this shortly. zend_std_get_method() doesn't increment the refcount on the given method_name zend_string (which is good) _except_ when the method is resolved via __call (which is bad). This is due to https://github.com/php/php-src/blob/741bfe3932de28c20f401cc7e0447fffb2bea7d6/Zend/zend_object_handlers.c#L1065-L1069, which calls zend_string_copy() in normal operation. This makes it very easy to leak the string, since a possible pattern might be: method_name = zend_string_init(name, name_len); func = Z_OBJ_HT_P(obj)->get_method(&Z_OBJ_P(obj), method_name, NULL); zend_string_release(method_name); For non-__call classes, method_name is freed at this point. For __call classes, not so much. Obviously another option here is to use zend_string_free(), but I think it'd be considerably better if we just didn't ever increment the refcount. -- Edit bug report at https://bugs.php.net/bug.php?id=71778&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=71778&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=71778&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=71778&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=71778&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=71778&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=71778&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=71778&r=needscript Try newer version: https://bugs.php.net/fix.php?id=71778&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=71778&r=support Expected behavior: https://bugs.php.net/fix.php?id=71778&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=71778&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=71778&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=71778&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=71778&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=71778&r=dst IIS Stability: https://bugs.php.net/fix.php?id=71778&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=71778&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=71778&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=71778&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=71778&r=mysqlcfg

« previous php.bugs (#199744) next »