Bug #71539 [PATCH]: Memory error on $arr[$a] =& $arr[$b] if RHS rehashes

From: Date: Wed, 06 Jul 2016 19:05:47 +0000
Subject: Bug #71539 [PATCH]: Memory error on $arr[$a] =& $arr[$b] if RHS rehashes
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202103@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71539&edit=1 ID: 71539 Patch added by: dmitry@php.net Reported by: nikic@php.net Summary: Memory error on $arr[$a] =& $arr[$b] if RHS rehashes Status: Assigned Type: Bug Package: Scripting Engine problem PHP Version: 7.0.3 Assigned To: dmitry Block user comment: N Private report: N New Comment: The following patch has been added/updated: Patch Name: bug71539.diff Revision: 1467831947 URL: https://bugs.php.net/patch-display.php?bug=71539&patch=bug71539.diff&revision=1467831947 Previous Comments: ------------------------------------------------------------------------ [2016-07-06 14:33:19] dmitry@php.net The following patch has been added/updated: Patch Name: bug71539.diff Revision: 1467815599 URL: https://bugs.php.net/patch-display.php?bug=71539&patch=bug71539.diff&revision=1467815599 ------------------------------------------------------------------------ [2016-07-06 10:07:30] dmitry@php.net The following patch has been added/updated: Patch Name: bug71539.diff Revision: 1467799650 URL: https://bugs.php.net/patch-display.php?bug=71539&patch=bug71539.diff&revision=1467799650 ------------------------------------------------------------------------ [2016-03-19 14:23:12] nikic@php.net Related To: Bug #71850 ------------------------------------------------------------------------ [2016-02-06 15:55:55] nikic@php.net Description: ------------ Reproduce code: $array = []; $array[0] =& $array['']; The $array[''] is used to force a packed-to-hash conversion. Output: [Sat Feb 6 16:53:58 2016] Script: '/home/nikic/php-src/t203.php' /home/nikic/php-src/Zend/zend_execute.c(577) : Freeing 0x7FEE3D6010E0 (24 bytes), script=/home/nikic/php-src/t203.php === Total 1 memory leaks detected === First valgrind: ==30433== Invalid read of size 1 ==30433== at 0xB7EAAD: zval_get_type (zend_types.h:330) ==30433== by 0xBB80A5: ZEND_ASSIGN_REF_SPEC_VAR_VAR_HANDLER (zend_vm_execute.h:19702) ==30433== by 0xB88A6F: execute_ex (zend_vm_execute.h:422) ==30433== by 0xB88C71: zend_execute (zend_vm_execute.h:466) ==30433== by 0xB247EC: zend_execute_scripts (zend.c:1427) ==30433== by 0xA630F9: php_execute_script (main.c:2484) ==30433== by 0xC0783C: do_cli (php_cli.c:974) ==30433== by 0xC08CD1: main (php_cli.c:1345) ==30433== Address 0xf47b680 is 16 bytes inside a block of size 264 free'd ==30433== at 0x4C2BDEC: free (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so) ==30433== by 0xAE4EAD: _efree (zend_alloc.c:2453) ==30433== by 0xB379A8: zend_hash_packed_to_hash (zend_hash.c:220) ==30433== by 0xB3915C: _zend_hash_add_or_update_i (zend_hash.c:566) ==30433== by 0xB3951C: _zend_hash_add_new (zend_hash.c:640) ==30433== by 0xB852E5: zend_fetch_dimension_address_inner (zend_execute.c:1466) ==30433== by 0xB85AB4: zend_fetch_dimension_address (zend_execute.c:1681) ==30433== by 0xB861AE: zend_fetch_dimension_address_W (zend_execute.c:1772) ==30433== by 0xBDAB96: ZEND_FETCH_DIM_W_SPEC_CV_CONST_HANDLER (zend_vm_execute.h:36832) ==30433== by 0xB88A6F: execute_ex (zend_vm_execute.h:422) ==30433== by 0xB88C71: zend_execute (zend_vm_execute.h:466) ==30433== by 0xB247EC: zend_execute_scripts (zend.c:1427) The cause is the opcode sequence: @1 = FETCH_DIM_W $array 0 @2 = FETCH_DIM_W $array "" ASSIGN_REF @1 @2 Where the second FETCH_DIM_W will reallocate the backing array while @1 still holds a pointer into it. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=71539&edit=1

« previous php.bugs (#202103) next »