Bug #72143 [Csd]: preg_replace uses int instead of size_t on zend_string_allocs
| From: | krakjoe@php.net | Date: | Sat, 14 May 2016 07:22:31 +0000 |
| Subject: | Bug #72143 [Csd]: preg_replace uses int instead of size_t on zend_string_allocs | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-201089@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72143&edit=1
ID: 72143
Updated by: krakjoe@php.net
Reported by: burmartke at gmail dot com
Summary: preg_replace uses int instead of size_t on
zend_string_allocs
Status: Closed
Type: Bug
Package: PCRE related
Operating System: Ubuntu 16.04 LTS
PHP Version: 7.0.6
-Assigned To:
+Assigned To: krakjoe
Block user comment: N
Private report: N
New Comment:
Thanks.
I didn't add a test, this is an obvious programming error, and it's unreasonable to create
tests that allocate that much memory, I think.
Previous Comments:
------------------------------------------------------------------------
[2016-05-14 07:21:45] krakjoe@php.net
Automatic comment on behalf of krakjoe
Revision: http://git.php.net/?p=php-src.git;a=commit;h=fb951553be0175712f4b757e05004110d7421e04
Log: fix #72143 (preg_replace uses int instead of size_t on zend_string_allocs)
------------------------------------------------------------------------
[2016-05-14 07:21:35] krakjoe@php.net
Automatic comment on behalf of krakjoe
Revision: http://git.php.net/?p=php-src.git;a=commit;h=90f46f2c5bdd3ab0e5dbc3aec1b3294ea1981abe
Log: fix #72143 (preg_replace uses int instead of size_t on zend_string_allocs)
------------------------------------------------------------------------
[2016-05-03 12:53:02] burmartke at gmail dot com
Description:
------------
preg_replace() declares its alloc_len as an int, and zend_string_(re)alloc() expects a size_t, so
when it tries to allocate a string >= 0x40000000 it gets sign-extended and the alloc fails.
Test script:
---------------
<?php
error_log( "++++++++++++++++++++++++++begin " );
$str = str_repeat( 'a', 0x40000000 ) . 'b';
$len = strlen( $str );
error_log( "len=$len (0x" . dechex( $len ) . ")" . ", 18446744071562068000
(0x" . dechex( 18446744071562068000 ) . ")" );
$out = preg_replace( '/b/', '', $str );
error_log( "++++++++++++++++++++++++++end " );
Expected result:
----------------
A successful replace.
++++++++++++++++++++++++++begin
len=1073741825 (0x40000001), 18446744071562068000 (0xffffffff80000000)
++++++++++++++++++++++++++end
Actual result:
--------------
Either a PHP Fatal error: Out of memory (allocated 1075843072) (tried to allocate
18446744071562068000 bytes) or a segmentation fault.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72143&edit=1