Bug #73210 [NEW]: Segfault with stmt read only cursor and get_result due to double closing

From: Date: Fri, 30 Sep 2016 11:28:07 +0000
Subject: Bug #73210 [NEW]: Segfault with stmt read only cursor and get_result due to double closing
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204370@lists.php.net to get a copy of this message
From: richard dot fussenegger at trivago dot com Operating system: Irrelevant PHP version: Irrelevant Package: MySQLi related Bug Type: Bug Bug description:Segfault with stmt read only cursor and get_result due to double closing Description: ------------ Getting the result of an executed prepared statement that uses a read only cursor results in a segfault because the second close call tries to free the internal result on null. It does not matter which is the first or second close call since stmt gives result a pointer to the result, the one that calls it first is the one that frees it and the other one accesses null. The access happens in mysqlnd_res::free_result_internal after the if (result->conn) condition where result->conn->m is being called. The m might already point to nowhere because the previous close call already freed it. Patch will be directly provided as GitHub PR. Test script: --------------- <?php mysqli_report(MYSQLI_REPORT_ERROR | MYSQLI_REPORT_STRICT); $mysqli = new mysqli('localhost', 'root', 'keines'); $stmt = $mysqli->prepare('SELECT 1 UNION SELECT 2 UNION SELECT 3'); $stmt->attr_set(MYSQLI_STMT_ATTR_CURSOR_TYPE, MYSQLI_CURSOR_TYPE_READ_ONLY); $stmt->execute(); $result = $stmt->get_result(); // call order does not matter {{{ $result->close(); $stmt->close(); // }}} $mysqli->close(); Expected result: ---------------- Successful and graceful shutdown of PHP. Actual result: -------------- Segfault -- Edit bug report at https://bugs.php.net/bug.php?id=73210&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=73210&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=73210&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=73210&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=73210&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=73210&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=73210&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=73210&r=needscript Try newer version: https://bugs.php.net/fix.php?id=73210&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=73210&r=support Expected behavior: https://bugs.php.net/fix.php?id=73210&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=73210&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=73210&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=73210&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=73210&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=73210&r=dst IIS Stability: https://bugs.php.net/fix.php?id=73210&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=73210&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=73210&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=73210&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=73210&r=mysqlcfg

« previous php.bugs (#204370) next »