Bug #73282 [NEW]: Endless loop in SHA3-224

From: Date: Mon, 10 Oct 2016 11:07:39 +0000
Subject: Bug #73282 [NEW]: Endless loop in SHA3-224
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204580@lists.php.net to get a copy of this message
From:             rainer dot jung at kippdata dot de
Operating system: Solaris 10 Sparc
PHP version:      7.1.0RC3
Package:          hash related
Bug Type:         Bug
Bug description:Endless loop in SHA3-224

Description:
------------
Tests sha3 and hash_copy_001 do not terminate. They run in an endless
loop consuming CPU. Stacks:

#0  0xfed08a00 in PHP_SHA3_Final (digest=<optimized out>,
digest_size=28, block_size=144, ctx=0xfe45f700)
    at /some/path/ext/hash/hash_sha3.c:179
No locals.
#1  PHP_SHA3224Final (digest=0xfe456250 "", ctx=0xfe45f700) at
/some/path/ext/hash/hash_sha3.c:224
No locals.
#2  0xfecf2d50 in php_hash_do_hash (isfilename=<optimized out>,
raw_output_default=<optimized out>,
    return_value=<error reading variable: Unhandled dwarf expression
opcode 0xfa>, return_value=<error reading variable: Unhandled dwarf
expression opcode 0xfa>,
    execute_data=<error reading variable: Unhandled dwarf expression
opcode 0xfa>) at /some/path/ext/hash/hash.c:160
        algo = 0xfe455530 "sha3-224"
        data = 0x3cff8 ""
        algo_len = 8
        data_len = 0
        raw_output = 0 '\000'
        ops = 0xff0744a4
        context = 0xfe45f700
        stream = <optimized out>
#3  0xfeea086c in ZEND_DO_ICALL_SPEC_RETVAL_USED_HANDLER
(execute_data=0xfe414020)
    at /some/path/Zend/zend_vm_execute.h:675
        opline = 0xfe475380
        call = 0xfe414110
        fbc = <optimized out>
        ret = <optimized out>
#4  0xfee8a240 in execute_ex (ex=<optimized out>) at
/some/path/Zend/zend_vm_execute.h:432
        ret = <optimized out>
        execute_data = 0xfe414020
#5  0xfeefaadc in zend_execute (op_array=0xfe461080,
return_value=<optimized out>)
    at /some/path/Zend/zend_vm_execute.h:474
No locals.

with

(gdb) print *ctx
$1 = {state = "\006", '\000' <repeats 142 times>, "\200",
'\000'
<repeats 55 times>, pos = 1}
(gdb) print &(ctx->state[block_size-1])
$2 = (unsigned char *) 0xfe45f78f "\200"


and


#0  0xfed08a00 in PHP_SHA3_Final (digest=<optimized out>,
digest_size=28, block_size=144, ctx=0xfe45f1c0)
    at /some/path/ext/hash/hash_sha3.c:179
No locals.
#1  PHP_SHA3224Final (digest=0xfe456250
"▒W=\016?l>-\027L\223Z5▒▒1\003/\004▒▒4\231▒<▒h",
ctx=0xfe45f1c0)
    at /some/path/ext/hash/hash_sha3.c:224
No locals.
#2  0xfecf2958 in zif_hash_final (execute_data=0xfe414260,
return_value=0xfe414120) at /some/path/ext/hash/hash.c:510
        zhash = 0xfe414290
        hash = 0xfe46a060
        raw_output = 0 '\000'
        digest_len = 28
#3  0xfeea086c in ZEND_DO_ICALL_SPEC_RETVAL_USED_HANDLER
(execute_data=0xfe414020)
    at /some/path/Zend/zend_vm_execute.h:675
        opline = 0xfe477284
        call = 0xfe414260
        fbc = <optimized out>
        ret = <optimized out>

with

(gdb) print *ctx
$1 = {state = "I can't remember anything\006", '\000' <repeats 117
times>, "\200", '\000' <repeats 55 times>, pos = 26}
(gdb) print &(ctx->state[block_size-1])
$2 = (unsigned char *) 0xfe45f24f "\200"



-- 
Edit bug report at https://bugs.php.net/bug.php?id=73282&edit=1
-- 
Try a snapshot (PHP 5.4):   https://bugs.php.net/fix.php?id=73282&r=trysnapshot54
Try a snapshot (PHP 5.5):   https://bugs.php.net/fix.php?id=73282&r=trysnapshot55
Try a snapshot (trunk):     https://bugs.php.net/fix.php?id=73282&r=trysnapshottrunk
Fixed in SVN:               https://bugs.php.net/fix.php?id=73282&r=fixed
Fixed in release:           https://bugs.php.net/fix.php?id=73282&r=alreadyfixed
Need backtrace:             https://bugs.php.net/fix.php?id=73282&r=needtrace
Need Reproduce Script:      https://bugs.php.net/fix.php?id=73282&r=needscript
Try newer version:          https://bugs.php.net/fix.php?id=73282&r=oldversion
Not developer issue:        https://bugs.php.net/fix.php?id=73282&r=support
Expected behavior:          https://bugs.php.net/fix.php?id=73282&r=notwrong
Not enough info:            https://bugs.php.net/fix.php?id=73282&r=notenoughinfo
Submitted twice:            https://bugs.php.net/fix.php?id=73282&r=submittedtwice
register_globals:           https://bugs.php.net/fix.php?id=73282&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=73282&r=php4
Daylight Savings:           https://bugs.php.net/fix.php?id=73282&r=dst
IIS Stability:              https://bugs.php.net/fix.php?id=73282&r=isapi
Install GNU Sed:            https://bugs.php.net/fix.php?id=73282&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=73282&r=float
No Zend Extensions:         https://bugs.php.net/fix.php?id=73282&r=nozend
MySQL Configuration Error:  https://bugs.php.net/fix.php?id=73282&r=mysqlcfg



Thread (6 messages)

« previous php.bugs (#204580) next »