Sec Bug->Bug #72870 [Opn]: segfault zend_object_handlers.c:1528 (zend_std_object_get_class)

From: Date: Wed, 17 Aug 2016 20:08:15 +0000
Subject: Sec Bug->Bug #72870 [Opn]: segfault zend_object_handlers.c:1528 (zend_std_object_get_class)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-203363@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72870&edit=1 ID: 72870 Updated by: stas@php.net Reported by: brian dot carpenter at gmail dot com Summary: segfault zend_object_handlers.c:1528 (zend_std_object_get_class) Status: Open -Type: Security +Type: Bug Package: Reproducible crash Operating System: Debian 8 PHP Version: 5.6.24 Block user comment: N Private report: Y Previous Comments: ------------------------------------------------------------------------ [2016-08-17 19:47:18] brian dot carpenter at gmail dot com Description: ------------ Fuzzing PHP 5.6.24 (x64) with American Fuzzy Lop, ASAN and libdislocator.so. Test script: --------------- <?php print_r(get_loaded_extensions());class SegfaultScenario{private$e;private$t;function __construct(){$this->e=$this;$this->ob0ect=new\stdClass;}public function __destruct(){// if(!$this->ob0ect)(0);var_dump($this);}}class SomeContainer{public function run(){new SegfaultScenario;}}$container=new SomeContainer();$container->run();gc_collect_cycles(); Expected result: ---------------- No crash. Actual result: -------------- geeknik@debian:~/php-tmp/crashers/070816$ ./php segfault_zend_std_object_get_class Array ( [0] => Core [1] => date [2] => ereg [3] => libxml [4] => pcre [5] => sqlite3 [6] => ctype [7] => dom [8] => fileinfo [9] => filter [10] => hash [11] => iconv [12] => json [13] => SPL [14] => PDO [15] => session [16] => posix [17] => Reflection [18] => standard [19] => SimpleXML [20] => pdo_sqlite [21] => Phar [22] => tokenizer [23] => xml [24] => xmlreader [25] => xmlwriter ) object(SegfaultScenario)#2 (3) { ["e":"SegfaultScenario":private]=> *RECURSION* ["t":"SegfaultScenario":private]=> NULL ["ob0ect"]=> ASAN:SIGSEGV ================================================================= ==96937==ERROR: AddressSanitizer: SEGV on unknown address 0x7f7effffffff (pc 0x00000168c99c bp 0x7ffe2bc7d470 sp 0x7ffe2bc7d2f0 T0) #0 0x168c99b in zend_std_object_get_class /home/geeknik/php-5.6.24/Zend/zend_object_handlers.c:1528:2 #1 0x15b4c5d in zend_get_class_entry /home/geeknik/php-5.6.24/Zend/zend_API.c:238:10 #2 0x167d188 in zend_std_get_debug_info /home/geeknik/php-5.6.24/Zend/zend_object_handlers.c:140:25 #3 0x12daacf in php_var_dump /home/geeknik/php-5.6.24/ext/standard/var.c:129:10 #4 0x12dbfae in php_object_property_dump /home/geeknik/php-5.6.24/ext/standard/var.c:82:2 #5 0x15f6298 in zend_hash_apply_with_arguments /home/geeknik/php-5.6.24/Zend/zend_hash.c:701:12 #6 0x12db3a4 in php_var_dump /home/geeknik/php-5.6.24/ext/standard/var.c:146:4 #7 0x12dc290 in zif_var_dump /home/geeknik/php-5.6.24/ext/standard/var.c:183:3 #8 0x184edb0 in zend_do_fcall_common_helper_SPEC /home/geeknik/php-5.6.24/Zend/zend_vm_execute.h:558:5 #9 0x17311d7 in ZEND_DO_FCALL_SPEC_CONST_HANDLER /home/geeknik/php-5.6.24/Zend/zend_vm_execute.h:2602:9 #10 0x16a332e in execute_ex /home/geeknik/php-5.6.24/Zend/zend_vm_execute.h:363:14 #11 0x16a52da in zend_execute /home/geeknik/php-5.6.24/Zend/zend_vm_execute.h:388:2 #12 0x15624f3 in zend_call_function /home/geeknik/php-5.6.24/Zend/zend_execute_API.c:829:4 #13 0x16298ce in zend_call_method /home/geeknik/php-5.6.24/Zend/zend_interfaces.c:97:12 #14 0x167a8c4 in zend_objects_destroy_object /home/geeknik/php-5.6.24/Zend/zend_objects.c:123:3 #15 0x16595ee in gc_collect_cycles /home/geeknik/php-5.6.24/Zend/zend_gc.c:811:6 #16 0x161a247 in zif_gc_collect_cycles /home/geeknik/php-5.6.24/Zend/zend_builtin_functions.c:361:2 #17 0x184edb0 in zend_do_fcall_common_helper_SPEC /home/geeknik/php-5.6.24/Zend/zend_vm_execute.h:558:5 #18 0x17311d7 in ZEND_DO_FCALL_SPEC_CONST_HANDLER /home/geeknik/php-5.6.24/Zend/zend_vm_execute.h:2602:9 #19 0x16a332e in execute_ex /home/geeknik/php-5.6.24/Zend/zend_vm_execute.h:363:14 #20 0x16a52da in zend_execute /home/geeknik/php-5.6.24/Zend/zend_vm_execute.h:388:2 #21 0x15b1cc1 in zend_execute_scripts /home/geeknik/php-5.6.24/Zend/zend.c:1341:4 #22 0x13be7f1 in php_execute_script /home/geeknik/php-5.6.24/main/main.c:2613:14 #23 0x1907aaa in do_cli /home/geeknik/php-5.6.24/sapi/cli/php_cli.c:994:5 #24 0x190474d in main /home/geeknik/php-5.6.24/sapi/cli/php_cli.c:1378:18 #25 0x7f7ed0130b44 in __libc_start_main /build/glibc-uPj9cH/glibc-2.19/csu/libc-start.c:287 #26 0x5095ac in _start (/home/geeknik/php-5.6.24/sapi/cli/php+0x5095ac) AddressSanitizer can not provide additional info. SUMMARY: AddressSanitizer: SEGV /home/geeknik/php-5.6.24/Zend/zend_object_handlers.c:1528 zend_std_object_get_class ==96937==ABORTING ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72870&edit=1

« previous php.bugs (#203363) next »