Bug #72337 [NEW]: segfault in gdImageScaleBicubicFixed at gd_interpolation.c:1605

From: Date: Sun, 05 Jun 2016 21:12:40 +0000
Subject: Bug #72337 [NEW]: segfault in gdImageScaleBicubicFixed at gd_interpolation.c:1605
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201462@lists.php.net to get a copy of this message
From: brian dot carpenter at gmail dot com Operating system: Debian 8.2 x64 PHP version: 7.0Git-2016-06-05 (Git) Package: Reproducible crash Bug Type: Bug Bug description:segfault in gdImageScaleBicubicFixed at gd_interpolation.c:1605 Description: ------------ While fuzzing PHP 7.1.0-dev (cli) (built: Jun 1 2016 04:52:26) with American Fuzzy Lop, this test case was found to cause a segfault. Test script: --------------- <?php $img=imagecreatetruecolor(1,!0);imagescale($img,0,0,w^B); Expected result: ---------------- No crash. Actual result: -------------- Program received signal SIGSEGV, Segmentation fault. gdImageScaleBicubicFixed (src=0x7ffff5e77000, width=<optimized out>, height=<optimized out>) at /home/geeknik/php-src/ext/gd/libgd/gd_interpolation.c:1605 1605 c = src->tpixels[*(src_offset_y + _k)][*(src_offset_x + _k)]; (gdb) bt #0 gdImageScaleBicubicFixed (src=0x7ffff5e77000, width=<optimized out>, height=<optimized out>) at /home/geeknik/php-src/ext/gd/libgd/gd_interpolation.c:1605 #1 0x0000000000e675c5 in gdImageScale (src=src@entry=0x7ffff5e77000, new_width=new_width@entry=0, new_height=new_height@entry=0) at /home/geeknik/php-src/ext/gd/libgd/gd_interpolation.c:1651 #2 0x0000000000d74b26 in zif_imagescale (execute_data=<optimized out>, return_value=0x7fffffffacd0) at /home/geeknik/php-src/ext/gd/gd.c:4674 #3 0x00000000018d9c96 in ZEND_DO_ICALL_SPEC_RETVAL_UNUSED_HANDLER (execute_data=0x7ffff5e13030) at /home/geeknik/php-src/Zend/zend_vm_execute.h:616 #4 0x000000000187ba98 in execute_ex (ex=<optimized out>) at /home/geeknik/php-src/Zend/zend_vm_execute.h:429 #5 0x0000000001a7b73c in zend_execute (op_array=op_array@entry=0x7ffff5e7f000, return_value=return_value@entry=0x0) at /home/geeknik/php-src/Zend/zend_vm_execute.h:471 #6 0x0000000001684641 in zend_execute_scripts (type=type@entry=8, retval=retval@entry=0x0, file_count=file_count@entry=3) at /home/geeknik/php-src/Zend/zend.c:1427 #7 0x0000000001428538 in php_execute_script (primary_file=primary_file@entry=0x7fffffffd270) at /home/geeknik/php-src/main/main.c:2492 #8 0x0000000001a85d65 in do_cli (argc=2, argv=0x22359f0) at /home/geeknik/php-src/sapi/cli/php_cli.c:982 #9 0x00000000004561b5 in main (argc=2, argv=0x22359f0) at /home/geeknik/php-src/sapi/cli/php_cli.c:1352 (gdb) l 1600 if (f_fm1 > 0) f_d = gd_mulfx(f_fm1,gd_mulfx(f_fm1,f_fm1)); 1601 1602 f_RX = gd_divfx((f_a-gd_mulfx(f_4,f_b)+gd_mulfx(f_6,f_c)-gd_mulfx(f_4,f_d)),f_6); 1603 f_R = gd_mulfx(f_RY,f_RX); 1604 1605 c = src->tpixels[*(src_offset_y + _k)][*(src_offset_x + _k)]; 1606 f_rs = gd_itofx(gdTrueColorGetRed(c)); 1607 f_gs = gd_itofx(gdTrueColorGetGreen(c)); 1608 f_bs = gd_itofx(gdTrueColorGetBlue(c)); 1609 f_ba = gd_itofx(gdTrueColorGetAlpha(c)); ==18480== Conditional jump or move depends on uninitialised value(s) ==18480== at 0x1711BCE: zend_hash_find (zend_hash.c:494) ==18480== by 0x183905C: zend_do_inheritance (zend_inheritance.c:645) ==18480== by 0x16AB72A: zend_register_internal_class_ex (zend_API.c:2671) ==18480== by 0x176C46E: zend_register_default_exception (zend_exceptions.c:835) ==18480== by 0x18281C5: zend_register_default_classes (zend_default_classes.c:34) ==18480== by 0x173C3D9: zm_startup_core (zend_builtin_functions.c:391) ==18480== by 0x169C8C7: zend_startup_module_ex (zend_API.c:1838) ==18480== by 0x16FA6A5: zend_hash_apply (zend_hash.c:1533) ==18480== by 0x16A1355: zend_startup_modules (zend_API.c:1964) ==18480== by 0x1425D69: php_module_startup (main.c:2215) ==18480== by 0x1A81554: php_cli_startup (php_cli.c:423) ==18480== by 0x455607: main (php_cli.c:1332) ==18480== Uninitialised value was created by a stack allocation ==18480== at 0x4003208: dl_main (rtld.c:1666) ==18480== ==18480== Conditional jump or move depends on uninitialised value(s) ==18480== at 0x1711F6D: zend_hash_find (zend_hash.c:494) ==18480== by 0x183905C: zend_do_inheritance (zend_inheritance.c:645) ==18480== by 0x16AB72A: zend_register_internal_class_ex (zend_API.c:2671) ==18480== by 0x176C46E: zend_register_default_exception (zend_exceptions.c:835) ==18480== by 0x18281C5: zend_register_default_classes (zend_default_classes.c:34) ==18480== by 0x173C3D9: zm_startup_core (zend_builtin_functions.c:391) ==18480== by 0x169C8C7: zend_startup_module_ex (zend_API.c:1838) ==18480== by 0x16FA6A5: zend_hash_apply (zend_hash.c:1533) ==18480== by 0x16A1355: zend_startup_modules (zend_API.c:1964) ==18480== by 0x1425D69: php_module_startup (main.c:2215) ==18480== by 0x1A81554: php_cli_startup (php_cli.c:423) ==18480== by 0x455607: main (php_cli.c:1332) ==18480== Uninitialised value was created by a stack allocation ==18480== at 0x4003208: dl_main (rtld.c:1666) ==18480== ==18480== Conditional jump or move depends on uninitialised value(s) ==18480== at 0x1711BCE: zend_hash_find (zend_hash.c:494) ==18480== by 0x183905C: zend_do_inheritance (zend_inheritance.c:645) ==18480== by 0x16AB72A: zend_register_internal_class_ex (zend_API.c:2671) ==18480== by 0x176C8ED: zend_register_default_exception (zend_exceptions.c:853) ==18480== by 0x18281C5: zend_register_default_classes (zend_default_classes.c:34) ==18480== by 0x173C3D9: zm_startup_core (zend_builtin_functions.c:391) ==18480== by 0x169C8C7: zend_startup_module_ex (zend_API.c:1838) ==18480== by 0x16FA6A5: zend_hash_apply (zend_hash.c:1533) ==18480== by 0x16A1355: zend_startup_modules (zend_API.c:1964) ==18480== by 0x1425D69: php_module_startup (main.c:2215) ==18480== by 0x1A81554: php_cli_startup (php_cli.c:423) ==18480== by 0x455607: main (php_cli.c:1332) ==18480== Uninitialised value was created by a stack allocation ==18480== at 0x4003208: dl_main (rtld.c:1666) ==18480== ==18480== Conditional jump or move depends on uninitialised value(s) ==18480== at 0x1711F6D: zend_hash_find (zend_hash.c:494) ==18480== by 0x183905C: zend_do_inheritance (zend_inheritance.c:645) ==18480== by 0x16AB72A: zend_register_internal_class_ex (zend_API.c:2671) ==18480== by 0x176C8ED: zend_register_default_exception (zend_exceptions.c:853) ==18480== by 0x18281C5: zend_register_default_classes (zend_default_classes.c:34) ==18480== by 0x173C3D9: zm_startup_core (zend_builtin_functions.c:391) ==18480== by 0x169C8C7: zend_startup_module_ex (zend_API.c:1838) ==18480== by 0x16FA6A5: zend_hash_apply (zend_hash.c:1533) ==18480== by 0x16A1355: zend_startup_modules (zend_API.c:1964) ==18480== by 0x1425D69: php_module_startup (main.c:2215) ==18480== by 0x1A81554: php_cli_startup (php_cli.c:423) ==18480== by 0x455607: main (php_cli.c:1332) ==18480== Uninitialised value was created by a stack allocation ==18480== at 0x4003208: dl_main (rtld.c:1666) ==18480== ==18480== Conditional jump or move depends on uninitialised value(s) ==18480== at 0x1711BCE: zend_hash_find (zend_hash.c:494) ==18480== by 0x183905C: zend_do_inheritance (zend_inheritance.c:645) ==18480== by 0x16AB72A: zend_register_internal_class_ex (zend_API.c:2671) ==18480== by 0x176CAAF: zend_register_default_exception (zend_exceptions.c:857) ==18480== by 0x18281C5: zend_register_default_classes (zend_default_classes.c:34) ==18480== by 0x173C3D9: zm_startup_core (zend_builtin_functions.c:391) ==18480== by 0x169C8C7: zend_startup_module_ex (zend_API.c:1838) ==18480== by 0x16FA6A5: zend_hash_apply (zend_hash.c:1533) ==18480== by 0x16A1355: zend_startup_modules (zend_API.c:1964) ==18480== by 0x1425D69: php_module_startup (main.c:2215) ==18480== by 0x1A81554: php_cli_startup (php_cli.c:423) ==18480== by 0x455607: main (php_cli.c:1332) ==18480== Uninitialised value was created by a stack allocation ==18480== at 0x4003208: dl_main (rtld.c:1666) ==18480== ==18480== Conditional jump or move depends on uninitialised value(s) ==18480== at 0x1711F6D: zend_hash_find (zend_hash.c:494) ==18480== by 0x183905C: zend_do_inheritance (zend_inheritance.c:645) ==18480== by 0x16AB72A: zend_register_internal_class_ex (zend_API.c:2671) ==18480== by 0x176CAAF: zend_register_default_exception (zend_exceptions.c:857) ==18480== by 0x18281C5: zend_register_default_classes (zend_default_classes.c:34) ==18480== by 0x173C3D9: zm_startup_core (zend_builtin_functions.c:391) ==18480== by 0x169C8C7: zend_startup_module_ex (zend_API.c:1838) ==18480== by 0x16FA6A5: zend_hash_apply (zend_hash.c:1533) ==18480== by 0x16A1355: zend_startup_modules (zend_API.c:1964) ==18480== by 0x1425D69: php_module_startup (main.c:2215) ==18480== by 0x1A81554: php_cli_startup (php_cli.c:423) ==18480== by 0x455607: main (php_cli.c:1332) ==18480== Uninitialised value was created by a stack allocation ==18480== at 0x4003208: dl_main (rtld.c:1666) ==18480== ==18480== Conditional jump or move depends on uninitialised value(s) ==18480== at 0x1711BCE: zend_hash_find (zend_hash.c:494) ==18480== by 0x183905C: zend_do_inheritance (zend_inheritance.c:645) ==18480== by 0x16AB72A: zend_register_internal_class_ex (zend_API.c:2671) ==18480== by 0x176CC7E: zend_register_default_exception (zend_exceptions.c:861) ==18480== by 0x18281C5: zend_register_default_classes (zend_default_classes.c:34) ==18480== by 0x173C3D9: zm_startup_core (zend_builtin_functions.c:391) ==18480== by 0x169C8C7: zend_startup_module_ex (zend_API.c:1838) ==18480== by 0x16FA6A5: zend_hash_apply (zend_hash.c:1533) ==18480== by 0x16A1355: zend_startup_modules (zend_API.c:1964) ==18480== by 0x1425D69: php_module_startup (main.c:2215) ==18480== by 0x1A81554: php_cli_startup (php_cli.c:423) ==18480== by 0x455607: main (php_cli.c:1332) ==18480== Uninitialised value was created by a stack allocation ==18480== at 0x4003208: dl_main (rtld.c:1666) ==18480== ==18480== Conditional jump or move depends on uninitialised value(s) ==18480== at 0x1711F6D: zend_hash_find (zend_hash.c:494) ==18480== by 0x183905C: zend_do_inheritance (zend_inheritance.c:645) ==18480== by 0x16AB72A: zend_register_internal_class_ex (zend_API.c:2671) ==18480== by 0x176CC7E: zend_register_default_exception (zend_exceptions.c:861) ==18480== by 0x18281C5: zend_register_default_classes (zend_default_classes.c:34) ==18480== by 0x173C3D9: zm_startup_core (zend_builtin_functions.c:391) ==18480== by 0x169C8C7: zend_startup_module_ex (zend_API.c:1838) ==18480== by 0x16FA6A5: zend_hash_apply (zend_hash.c:1533) ==18480== by 0x16A1355: zend_startup_modules (zend_API.c:1964) ==18480== by 0x1425D69: php_module_startup (main.c:2215) ==18480== by 0x1A81554: php_cli_startup (php_cli.c:423) ==18480== by 0x455607: main (php_cli.c:1332) ==18480== Uninitialised value was created by a stack allocation ==18480== at 0x4003208: dl_main (rtld.c:1666) ==18480== ==18480== Conditional jump or move depends on uninitialised value(s) ==18480== at 0x1711BCE: zend_hash_find (zend_hash.c:494) ==18480== by 0x183905C: zend_do_inheritance (zend_inheritance.c:645) ==18480== by 0x16AB72A: zend_register_internal_class_ex (zend_API.c:2671) ==18480== by 0x176CE4A: zend_register_default_exception (zend_exceptions.c:865) ==18480== by 0x18281C5: zend_register_default_classes (zend_default_classes.c:34) ==18480== by 0x173C3D9: zm_startup_core (zend_builtin_functions.c:391) ==18480== by 0x169C8C7: zend_startup_module_ex (zend_API.c:1838) ==18480== by 0x16FA6A5: zend_hash_apply (zend_hash.c:1533) ==18480== by 0x16A1355: zend_startup_modules (zend_API.c:1964) ==18480== by 0x1425D69: php_module_startup (main.c:2215) ==18480== by 0x1A81554: php_cli_startup (php_cli.c:423) ==18480== by 0x455607: main (php_cli.c:1332) ==18480== Uninitialised value was created by a stack allocation ==18480== at 0x4003208: dl_main (rtld.c:1666) ==18480== ==18480== Conditional jump or move depends on uninitialised value(s) ==18480== at 0x1711F6D: zend_hash_find (zend_hash.c:494) ==18480== by 0x183905C: zend_do_inheritance (zend_inheritance.c:645) ==18480== by 0x16AB72A: zend_register_internal_class_ex (zend_API.c:2671) ==18480== by 0x176CE4A: zend_register_default_exception (zend_exceptions.c:865) ==18480== by 0x18281C5: zend_register_default_classes (zend_default_classes.c:34) ==18480== by 0x173C3D9: zm_startup_core (zend_builtin_functions.c:391) ==18480== by 0x169C8C7: zend_startup_module_ex (zend_API.c:1838) ==18480== by 0x16FA6A5: zend_hash_apply (zend_hash.c:1533) ==18480== by 0x16A1355: zend_startup_modules (zend_API.c:1964) ==18480== by 0x1425D69: php_module_startup (main.c:2215) ==18480== by 0x1A81554: php_cli_startup (php_cli.c:423) ==18480== by 0x455607: main (php_cli.c:1332) ==18480== Uninitialised value was created by a stack allocation ==18480== at 0x4003208: dl_main (rtld.c:1666) ==18480== ==18480== Conditional jump or move depends on uninitialised value(s) ==18480== at 0x1711BCE: zend_hash_find (zend_hash.c:494) ==18480== by 0x183905C: zend_do_inheritance (zend_inheritance.c:645) ==18480== by 0x16AB72A: zend_register_internal_class_ex (zend_API.c:2671) ==18480== by 0x17C3E3A: zend_register_generator_ce (zend_generators.c:1255) ==18480== by 0x173C3D9: zm_startup_core (zend_builtin_functions.c:391) ==18480== by 0x169C8C7: zend_startup_module_ex (zend_API.c:1838) ==18480== by 0x16FA6A5: zend_hash_apply (zend_hash.c:1533) ==18480== by 0x16A1355: zend_startup_modules (zend_API.c:1964) ==18480== by 0x1425D69: php_module_startup (main.c:2215) ==18480== by 0x1A81554: php_cli_startup (php_cli.c:423) ==18480== by 0x455607: main (php_cli.c:1332) ==18480== Uninitialised value was created by a stack allocation ==18480== at 0x4003208: dl_main (rtld.c:1666) ==18480== ==18480== Conditional jump or move depends on uninitialised value(s) ==18480== at 0x1711F6D: zend_hash_find (zend_hash.c:494) ==18480== by 0x183905C: zend_do_inheritance (zend_inheritance.c:645) ==18480== by 0x16AB72A: zend_register_internal_class_ex (zend_API.c:2671) ==18480== by 0x17C3E3A: zend_register_generator_ce (zend_generators.c:1255) ==18480== by 0x173C3D9: zm_startup_core (zend_builtin_functions.c:391) ==18480== by 0x169C8C7: zend_startup_module_ex (zend_API.c:1838) ==18480== by 0x16FA6A5: zend_hash_apply (zend_hash.c:1533) ==18480== by 0x16A1355: zend_startup_modules (zend_API.c:1964) ==18480== by 0x1425D69: php_module_startup (main.c:2215) ==18480== by 0x1A81554: php_cli_startup (php_cli.c:423) ==18480== by 0x455607: main (php_cli.c:1332) ==18480== Uninitialised value was created by a stack allocation ==18480== at 0x4003208: dl_main (rtld.c:1666) ==18480== ==18480== Use of uninitialised value of size 8 ==18480== at 0xE6685D: gdImageScaleBicubicFixed (gd_interpolation.c:1605) ==18480== by 0xD74B25: zif_imagescale (gd.c:4674) ==18480== by 0x18D9C95: ZEND_DO_ICALL_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:616) ==18480== by 0x187BA97: execute_ex (zend_vm_execute.h:429) ==18480== by 0x1A7B73B: zend_execute (zend_vm_execute.h:471) ==18480== by 0x1684640: zend_execute_scripts (zend.c:1427) ==18480== by 0x1428537: php_execute_script (main.c:2492) ==18480== by 0x1A85D64: do_cli (php_cli.c:982) ==18480== by 0x4561B4: main (php_cli.c:1352) ==18480== Uninitialised value was created by a stack allocation ==18480== at 0xE671D0: gdImageScale (gd_interpolation.c:1633) ==18480== ==18480== Use of uninitialised value of size 8 ==18480== at 0xE66896: gdImageScaleBicubicFixed (gd_interpolation.c:1605) ==18480== by 0xD74B25: zif_imagescale (gd.c:4674) ==18480== by 0x18D9C95: ZEND_DO_ICALL_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:616) ==18480== by 0x187BA97: execute_ex (zend_vm_execute.h:429) ==18480== by 0x1A7B73B: zend_execute (zend_vm_execute.h:471) ==18480== by 0x1684640: zend_execute_scripts (zend.c:1427) ==18480== by 0x1428537: php_execute_script (main.c:2492) ==18480== by 0x1A85D64: do_cli (php_cli.c:982) ==18480== by 0x4561B4: main (php_cli.c:1352) ==18480== Uninitialised value was created by a stack allocation ==18480== at 0xE65C70: gdImageScaleBicubicFixed (gd_interpolation.c:1397) ==18480== ==18480== Invalid read of size 4 ==18480== at 0xE66896: gdImageScaleBicubicFixed (gd_interpolation.c:1605) ==18480== by 0xD74B25: zif_imagescale (gd.c:4674) ==18480== by 0x18D9C95: ZEND_DO_ICALL_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:616) ==18480== by 0x187BA97: execute_ex (zend_vm_execute.h:429) ==18480== by 0x1A7B73B: zend_execute (zend_vm_execute.h:471) ==18480== by 0x1684640: zend_execute_scripts (zend.c:1427) ==18480== by 0x1428537: php_execute_script (main.c:2492) ==18480== by 0x1A85D64: do_cli (php_cli.c:982) ==18480== by 0x4561B4: main (php_cli.c:1352) ==18480== Address 0x40707201c is not stack'd, malloc'd or (recently) free'd -- Edit bug report at https://bugs.php.net/bug.php?id=72337&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=72337&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=72337&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=72337&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=72337&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=72337&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=72337&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=72337&r=needscript Try newer version: https://bugs.php.net/fix.php?id=72337&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=72337&r=support Expected behavior: https://bugs.php.net/fix.php?id=72337&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=72337&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=72337&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=72337&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=72337&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=72337&r=dst IIS Stability: https://bugs.php.net/fix.php?id=72337&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=72337&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=72337&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=72337&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=72337&r=mysqlcfg

« previous php.bugs (#201462) next »