Bug #72982 [Com]: Memory leak in zend_accel_blacklist_update_regexp() function

From: Date: Mon, 03 Oct 2016 09:34:49 +0000
Subject: Bug #72982 [Com]: Memory leak in zend_accel_blacklist_update_regexp() function
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204418@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72982&edit=1 ID: 72982 Comment by: aaron at serendipity dot cx Reported by: irishbughunting at gmail dot com Summary: Memory leak in zend_accel_blacklist_update_regexp() function Status: Closed Type: Bug Package: Regexps related Operating System: Any PHP Version: 7.0.10 Block user comment: N Private report: N New Comment: The fix appears to be committed to the 7.1.0rcX series but not the 7.0.x series. Should it be backported? Previous Comments: ------------------------------------------------------------------------ [2016-09-01 04:11:54] laruence@php.net Automatic comment on behalf of laruence@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=1ee41683dc361a8d1bd0048f2218d24207b5e872 Log: Fixed bug #72982 (Memory leak in zend_accel_blacklist_update_regexp() function) ------------------------------------------------------------------------ [2016-08-31 00:24:50] irishbughunting at gmail dot com Description: ------------ Description =========== Due to the zend_accel_blacklist_update_regexp() function not releasing/freeing memory allocated on the heap, a memory leak can occur. This relates to the *it pointer. Code Snippet ============ static void zend_accel_blacklist_update_regexp(zend_blacklist *blacklist) { const char *pcre_error; int i, pcre_error_offset; zend_regexp_list **regexp_list_it, *it; char regexp[12*1024], *p, *end, *c, *backtrack = NULL; ----------SNIP--------- it = (zend_regexp_list*)malloc(sizeof(zend_regexp_list)); if (!it) { zend_accel_error(ACCEL_LOG_ERROR, "malloc() failed\n"); return; } it->next = NULL; if ((it->re = pcre_compile(regexp, PCRE_NO_AUTO_CAPTURE, &pcre_error, &pcre_error_offset, 0)) == NULL) { blacklist_report_regexp_error(pcre_error, pcre_error_offset); } /* prepare for the next iteration */ p = regexp + 2; *regexp_list_it = it; regexp_list_it = &it->next; ----------SNIP--------- Expected result: ---------------- An expected result it that the *it pointer is free'd after finish of use, as opposed to using up unnecessary system resources. Actual result: -------------- A memory leak occurs. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72982&edit=1

« previous php.bugs (#204418) next »