Bug #71778 [NEW]: zend_std_get_method() inconsistently increments the method_name refcount
| From: | aharvey@php.net | Date: | Thu, 10 Mar 2016 22:26:13 +0000 |
| Subject: | Bug #71778 [NEW]: zend_std_get_method() inconsistently increments the method_name refcount | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-199744@lists.php.net to get a copy of this message | ||
From: aharvey
Operating system: Irrelevant
PHP version: 7.0Git-2016-03-10 (Git)
Package: Scripting Engine problem
Bug Type: Bug
Bug description:zend_std_get_method() inconsistently increments the method_name refcount
Description:
------------
I'll file a PR for this shortly.
zend_std_get_method() doesn't increment the refcount on the given
method_name zend_string (which is good) _except_ when the method is
resolved via __call (which is bad). This is due to
https://github.com/php/php-src/blob/741bfe3932de28c20f401cc7e0447fffb2bea7d6/Zend/zend_object_handlers.c#L1065-L1069,
which calls zend_string_copy() in normal operation.
This makes it very easy to leak the string, since a possible pattern
might be:
method_name = zend_string_init(name, name_len);
func = Z_OBJ_HT_P(obj)->get_method(&Z_OBJ_P(obj), method_name, NULL);
zend_string_release(method_name);
For non-__call classes, method_name is freed at this point. For __call
classes, not so much. Obviously another option here is to use
zend_string_free(), but I think it'd be considerably better if we just
didn't ever increment the refcount.
--
Edit bug report at https://bugs.php.net/bug.php?id=71778&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=71778&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=71778&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=71778&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=71778&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=71778&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=71778&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=71778&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=71778&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=71778&r=support
Expected behavior: https://bugs.php.net/fix.php?id=71778&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=71778&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=71778&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=71778&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=71778&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=71778&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=71778&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=71778&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=71778&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=71778&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=71778&r=mysqlcfg