Bug #68396 [Fbk->NoF]: iconv null pointer write with zend_mm

From: Date: Sun, 21 Aug 2016 04:22:24 +0000
Subject: Bug #68396 [Fbk->NoF]: iconv null pointer write with zend_mm
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-203434@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68396&edit=1 ID: 68396 Updated by: php-bugs@lists.php.net Reported by: mattficken@php.net Summary: iconv null pointer write with zend_mm -Status: Feedback +Status: No Feedback Type: Bug Package: CGI/CLI related Operating System: Windows PHP Version: 5.5.18 Assigned To: cmb Private report: N New Comment: No feedback was provided. The bug is being suspended because we assume that you are no longer experiencing the problem. If this is not the case and you are able to provide the information that was requested earlier, please do so and change the status of the bug back to "Re-Opened". Thank you. Previous Comments: ------------------------------------------------------------------------ [2016-08-08 12:22:39] cmb@php.net I'm afraid this issue can't be resolved without a reproduce script or at the very least a more meaningful stack backtrace. Can you still get one, Matt? ------------------------------------------------------------------------ [2014-11-11 09:04:39] mattficken@php.net Description: ------------ Actually PHP Version: 5.5.13 <could be any more recent version> Event: NULL_CLASS_PTR_WRITE 0xc0000005 in php5.dll SAPI: php-cgi.exe OS: Windows 7.0, 8.0, mostly French and Chinese LCIDs The fact it happens in 5 different threads suggests it may not be fault of iconv ext, instead could be some other threading/mm issue in core providing iconv an invalid pointer which it uses at the the right/wrong time to cause crash. Stack traces of user-mode application crashes on Windows can (with user consent) be reported to Microsoft (see Windows Error Reporting and Watson). This bug is based on one of those reports. Note: can request additional information including memory dumps to help investigate this issue further. Watson #73491156297 Actual result: -------------- NOTE: aaaaaaaa indicates NULL, indicates either stack corruption or some frames missing due to dump -> minidump conversion Thread 0 01bd84ac aaaaaaaa php5!_zend_mm_free_int+0x2ae [c:\php-sdk\php55\vc11\x86\php-5.5.13\zend\zend_alloc.c @ 2110] 01bd84b0 01000000 0xaaaaaaaa 01bd84b4 aaaaaaaa iconv+0x20000 01bd84b8 aaaaaaaa 0xaaaaaaaa 01bd84bc 00000000 0xaaaaaaaa Thread 1 01bd84ac aaaaaaaa php5!_zend_mm_free_int+0x2ae [c:\php-sdk\php55\vc11\x86\php-5.5.13\zend\zend_alloc.c @ 2110] 01bd84b0 01000000 0xaaaaaaaa 01bd84b4 aaaaaaaa iconv+0x20000 01bd84b8 aaaaaaaa 0xaaaaaaaa 01bd84bc 00000000 0xaaaaaaaa Thread 2 01bd84ac aaaaaaaa php5!_zend_mm_free_int+0x2ae [c:\php-sdk\php55\vc11\x86\php-5.5.13\zend\zend_alloc.c @ 2110] 01bd84b0 01000000 0xaaaaaaaa 01bd84b4 aaaaaaaa iconv+0x20000 01bd84b8 aaaaaaaa 0xaaaaaaaa 01bd84bc 00000000 0xaaaaaaaa Thread 3 01bd84ac aaaaaaaa php5!_zend_mm_free_int+0x2ae [c:\php-sdk\php55\vc11\x86\php-5.5.13\zend\zend_alloc.c @ 2110] 01bd84b0 01000000 0xaaaaaaaa 01bd84b4 aaaaaaaa iconv+0x20000 01bd84b8 aaaaaaaa 0xaaaaaaaa 01bd84bc 00000000 0xaaaaaaaa Thread 4 01bd84ac aaaaaaaa php5!_zend_mm_free_int+0x2ae [c:\php-sdk\php55\vc11\x86\php-5.5.13\zend\zend_alloc.c @ 2110] 01bd84b0 01000000 0xaaaaaaaa 01bd84b4 aaaaaaaa iconv+0x20000 01bd84b8 aaaaaaaa 0xaaaaaaaa 01bd84bc 00000000 0xaaaaaaaa Thread 5 01bd84ac aaaaaaaa php5!_zend_mm_free_int+0x2ae [c:\php-sdk\php55\vc11\x86\php-5.5.13\zend\zend_alloc.c @ 2110] 01bd84b0 01000000 0xaaaaaaaa 01bd84b4 aaaaaaaa iconv+0x20000 01bd84b8 aaaaaaaa 0xaaaaaaaa 01bd84bc 00000000 0xaaaaaaaa ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68396&edit=1

« previous php.bugs (#203434) next »