Sec Bug->Bug #72939 [Opn]: null ptr deref, segfault _zend_hash_index_update_or_next_insert
| From: | stas@php.net | Date: | Thu, 25 Aug 2016 21:09:06 +0000 |
| Subject: | Sec Bug->Bug #72939 [Opn]: null ptr deref, segfault _zend_hash_index_update_or_next_insert | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-203551@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72939&edit=1
ID: 72939
Updated by: stas@php.net
Reported by: brian dot carpenter at gmail dot com
Summary: null ptr deref, segfault
_zend_hash_index_update_or_next_insert
Status: Open
-Type: Security
+Type: Bug
Package: Reproducible crash
Operating System: Debian 8.5 x64
PHP Version: 5.6.25
Block user comment: N
Private report: Y
Previous Comments:
------------------------------------------------------------------------
[2016-08-25 09:23:34] brian dot carpenter at gmail dot com
Description:
------------
Fuzzing PHP 5.6.25 x64 w/ American Fuzzy Lop and ASAN.
Test script:
---------------
<?php class foo{function __wakeup(){$this->__0=0/error_log('');}function
_(){(y());}}var_dump(unserialize('a:2:{i:0;O:3:"foo":1:0s:3:"__0";R:1;}'));
Expected result:
----------------
No crash.
Actual result:
--------------
ASAN:SIGSEGV
=================================================================
==2814==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000000 (pc 0x0000018edcab sp
0x7ffde9624850 bp 0x7fea62c2ed20 T0)
#0 0x18edcaa in _zend_hash_index_update_or_next_insert /root/php-5.6.25/Zend/zend_hash.c:401
#1 0x44306d in process_nested_data /root/php-5.6.25/ext/standard/var_unserializer.c:336
#2 0x15203d4 in php_var_unserialize /root/php-5.6.25/ext/standard/var_unserializer.c:841
#3 0x14c9656 in zif_unserialize /root/php-5.6.25/ext/standard/var.c:964
#4 0x1e551b4 in zend_do_fcall_common_helper_SPEC /root/php-5.6.25/Zend/zend_vm_execute.h:558
#5 0x1a2c75b in execute_ex /root/php-5.6.25/Zend/zend_vm_execute.h:363
#6 0x1897c68 in zend_execute_scripts /root/php-5.6.25/Zend/zend.c:1341
#7 0x15d04ef in php_execute_script /root/php-5.6.25/main/main.c:2613
#8 0x1e5ede7 in do_cli /root/php-5.6.25/sapi/cli/php_cli.c:994
#9 0x4565d0 in main /root/php-5.6.25/sapi/cli/php_cli.c:1378
#10 0x7fea60753b44 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x21b44)
#11 0x45741e (/root/php-5.6.25/sapi/cli/php+0x45741e)
AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV /root/php-5.6.25/Zend/zend_hash.c:401
_zend_hash_index_update_or_next_insert
==2814==ABORTING
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72939&edit=1