Bug #72944 [Opn->Fbk]: Null pointer deref in zval_delref_p

From: Date: Fri, 26 Aug 2016 10:34:15 +0000
Subject: Bug #72944 [Opn->Fbk]: Null pointer deref in zval_delref_p
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-203567@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72944&edit=1 ID: 72944 Updated by: ab@php.net Reported by: hanno at hboeck dot de Summary: Null pointer deref in zval_delref_p -Status: Open +Status: Feedback Type: Bug Package: Reproducible crash Operating System: Linux PHP Version: 7.0.10 Block user comment: N Private report: N New Comment: An empty page is shown in the posted link. Please post the PHP code. Thanks. Previous Comments: ------------------------------------------------------------------------ [2016-08-26 09:04:20] hanno at hboeck dot de Description: ------------ Attached file crashes when run with USE_ZEND_ALLOC=0 on an address sanitizer build. This does not happen on a non-asan-build, I don't know why. Script to reproduce: https://crashes.fuzzing-project.org/nullptr.php Asan error message / stack trace: ==5235==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000000 (pc 0x000000d74c90 sp 0x7ffef1db4a90 bp 0x7fe86bdec8f0 T0) #0 0xd74c8f in zval_delref_p /var/tmp/portage/dev-lang/php-7.0.10/work/sapis-build/cli/Zend/zend_types.h:827 #1 0xd74c8f in _zval_ptr_dtor_nogc /var/tmp/portage/dev-lang/php-7.0.10/work/sapis-build/cli/Zend/zend_variables.h:49 #2 0xd74c8f in ZEND_BW_AND_SPEC_TMPVAR_TMPVAR_HANDLER /var/tmp/portage/dev-lang/php-7.0.10/work/sapis-build/cli/Zend/zend_vm_execute.h:45077 #3 0xcf748d in execute_ex /var/tmp/portage/dev-lang/php-7.0.10/work/sapis-build/cli/Zend/zend_vm_execute.h:414 #4 0xe5c7bd in zend_execute /var/tmp/portage/dev-lang/php-7.0.10/work/sapis-build/cli/Zend/zend_vm_execute.h:458 #5 0xc1d5ba in zend_execute_scripts /var/tmp/portage/dev-lang/php-7.0.10/work/sapis-build/cli/Zend/zend.c:1427 #6 0xb068bf in php_execute_script /var/tmp/portage/dev-lang/php-7.0.10/work/sapis-build/cli/main/main.c:2494 #7 0xe60b1f in do_cli /var/tmp/portage/dev-lang/php-7.0.10/work/sapis-build/cli/sapi/cli/php_cli.c:974 #8 0x48428b in main /var/tmp/portage/dev-lang/php-7.0.10/work/sapis-build/cli/sapi/cli/php_cli.c:1344 #9 0x7fe8710f978f in __libc_start_main (/lib64/libc.so.6+0x2078f) #10 0x484a18 in _start (/usr/lib64/php7.0/bin/php+0x484a18) AddressSanitizer can not provide additional info. SUMMARY: AddressSanitizer: SEGV /var/tmp/portage/dev-lang/php-7.0.10/work/sapis-build/cli/Zend/zend_types.h:827 zval_delref_p ==5235==ABORTING ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72944&edit=1

« previous php.bugs (#203567) next »