Bug #73210 [NEW]: Segfault with stmt read only cursor and get_result due to double closing
| From: | richard dot fussenegger at trivago dot com | Date: | Fri, 30 Sep 2016 11:28:07 +0000 |
| Subject: | Bug #73210 [NEW]: Segfault with stmt read only cursor and get_result due to double closing | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-204370@lists.php.net to get a copy of this message | ||
From: richard dot fussenegger at trivago dot com
Operating system: Irrelevant
PHP version: Irrelevant
Package: MySQLi related
Bug Type: Bug
Bug description:Segfault with stmt read only cursor and get_result due to double closing
Description:
------------
Getting the result of an executed prepared statement that uses a read
only cursor results in a segfault because the second close call tries to
free the internal result on null. It does not matter which is the first
or second close call since stmt gives result a pointer to the result,
the one that calls it first is the one that frees it and the other one
accesses null.
The access happens in mysqlnd_res::free_result_internal after the if
(result->conn) condition where result->conn->m is being called. The m
might already point to nowhere because the previous close call already
freed it.
Patch will be directly provided as GitHub PR.
Test script:
---------------
<?php
mysqli_report(MYSQLI_REPORT_ERROR | MYSQLI_REPORT_STRICT);
$mysqli = new mysqli('localhost', 'root', 'keines');
$stmt = $mysqli->prepare('SELECT 1 UNION SELECT 2 UNION SELECT 3');
$stmt->attr_set(MYSQLI_STMT_ATTR_CURSOR_TYPE,
MYSQLI_CURSOR_TYPE_READ_ONLY);
$stmt->execute();
$result = $stmt->get_result();
// call order does not matter {{{
$result->close();
$stmt->close();
// }}}
$mysqli->close();
Expected result:
----------------
Successful and graceful shutdown of PHP.
Actual result:
--------------
Segfault
--
Edit bug report at https://bugs.php.net/bug.php?id=73210&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=73210&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=73210&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=73210&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=73210&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=73210&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=73210&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=73210&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=73210&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=73210&r=support
Expected behavior: https://bugs.php.net/fix.php?id=73210&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=73210&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=73210&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=73210&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=73210&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=73210&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=73210&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=73210&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=73210&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=73210&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=73210&r=mysqlcfg