Bug #72413 [Opn->Ver]: mysqlnd segfault (fetch_row second parameter typemismatch)
| From: | laruence@php.net | Date: | Sun, 19 Jun 2016 13:22:46 +0000 |
| Subject: | Bug #72413 [Opn->Ver]: mysqlnd segfault (fetch_row second parameter typemismatch) | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-201731@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72413&edit=1
ID: 72413
Updated by: laruence@php.net
Reported by: martin dot koegler at brz dot gv dot at
Summary: mysqlnd segfault (fetch_row second parameter
typemismatch)
-Status: Open
+Status: Verified
Type: Bug
-Package: mysqlnd_uh
+Package: *General Issues
Operating System: Linux
PHP Version: 5.6.22
-Assigned To:
+Assigned To: mysql
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2016-06-15 14:47:49] martin dot koegler at brz dot gv dot at
Description:
------------
If the MYSQLI_CURSOR_TYPE_READ_ONLY option is active on a mysqli statement,
mysqlnd_fetch_stmt_row_cursor is selected as row fetch method.
mysqlnd_fetch_stmt_row_cursor expects a MYSQLND_STMT passed as "param" parameter.
mysqlnd_res::fetch_into passes a zval as this parameter, which yields to a crash.
Test script:
---------------
<?php
$link1=mysqli_connect(....);
$SQL="SELECT 1";
$stmt=$link1->prepare($SQL);
$stmt->attr_set(MYSQLI_STMT_ATTR_CURSOR_TYPE, MYSQLI_CURSOR_TYPE_READ_ONLY);
$stmt->execute();
$res = $stmt->get_result();
while($res->fetch_row());
?>
Expected result:
----------------
No segfault
Actual result:
--------------
Segfault in
1022 SET_CLIENT_ERROR(*stmt->conn->error_info, CR_COMMANDS_OUT_OF_SYNC,
UNKNOWN_SQLSTATE,
mysqlnd_fetch_stmt_row_cursor at ext/mysqlnd/mysqlnd_ps.c:1022
php_mysqlnd_res_fetch_into_pub at ext/mysqlnd/mysqlnd_result.c:1823
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72413&edit=1