Sec Bug->Bug #72939 [Opn]: null ptr deref, segfault _zend_hash_index_update_or_next_insert

From: Date: Thu, 25 Aug 2016 21:09:06 +0000
Subject: Sec Bug->Bug #72939 [Opn]: null ptr deref, segfault _zend_hash_index_update_or_next_insert
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-203551@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72939&edit=1 ID: 72939 Updated by: stas@php.net Reported by: brian dot carpenter at gmail dot com Summary: null ptr deref, segfault _zend_hash_index_update_or_next_insert Status: Open -Type: Security +Type: Bug Package: Reproducible crash Operating System: Debian 8.5 x64 PHP Version: 5.6.25 Block user comment: N Private report: Y Previous Comments: ------------------------------------------------------------------------ [2016-08-25 09:23:34] brian dot carpenter at gmail dot com Description: ------------ Fuzzing PHP 5.6.25 x64 w/ American Fuzzy Lop and ASAN. Test script: --------------- <?php class foo{function __wakeup(){$this->__0=0/error_log('');}function _(){(y());}}var_dump(unserialize('a:2:{i:0;O:3:"foo":1:0s:3:"__0";R:1;}')); Expected result: ---------------- No crash. Actual result: -------------- ASAN:SIGSEGV ================================================================= ==2814==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000000 (pc 0x0000018edcab sp 0x7ffde9624850 bp 0x7fea62c2ed20 T0) #0 0x18edcaa in _zend_hash_index_update_or_next_insert /root/php-5.6.25/Zend/zend_hash.c:401 #1 0x44306d in process_nested_data /root/php-5.6.25/ext/standard/var_unserializer.c:336 #2 0x15203d4 in php_var_unserialize /root/php-5.6.25/ext/standard/var_unserializer.c:841 #3 0x14c9656 in zif_unserialize /root/php-5.6.25/ext/standard/var.c:964 #4 0x1e551b4 in zend_do_fcall_common_helper_SPEC /root/php-5.6.25/Zend/zend_vm_execute.h:558 #5 0x1a2c75b in execute_ex /root/php-5.6.25/Zend/zend_vm_execute.h:363 #6 0x1897c68 in zend_execute_scripts /root/php-5.6.25/Zend/zend.c:1341 #7 0x15d04ef in php_execute_script /root/php-5.6.25/main/main.c:2613 #8 0x1e5ede7 in do_cli /root/php-5.6.25/sapi/cli/php_cli.c:994 #9 0x4565d0 in main /root/php-5.6.25/sapi/cli/php_cli.c:1378 #10 0x7fea60753b44 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x21b44) #11 0x45741e (/root/php-5.6.25/sapi/cli/php+0x45741e) AddressSanitizer can not provide additional info. SUMMARY: AddressSanitizer: SEGV /root/php-5.6.25/Zend/zend_hash.c:401 _zend_hash_index_update_or_next_insert ==2814==ABORTING ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72939&edit=1

« previous php.bugs (#203551) next »