Bug #73490 [NEW]: segfault in pcre_exec.c

From: Date: Thu, 10 Nov 2016 19:27:45 +0000
Subject: Bug #73490 [NEW]: segfault in pcre_exec.c
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205289@lists.php.net to get a copy of this message
From: brian dot carpenter at gmail dot com Operating system: Debian 8.x PHP version: 5.6.27 Package: Reproducible crash Bug Type: Bug Bug description:segfault in pcre_exec.c Description: ------------ Found while fuzzing with AFL+ASan. Test script: --------------- <?php $pattern = '(?(1)0|(?(1)0)+)+((()))'; $a = preg_match("/$pattern/", '2966'); var_dump($a); Expected result: ---------------- No crash. For example, PHP 5.6.24-0+deb8u1 returns int(1). Actual result: -------------- Program received signal SIGSEGV, Segmentation fault. 0x000000000060e47f in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966", offset_top=2, md=0x7fffffff9d40, eptrb=0x0, rdepth=8715) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:516 516 { (gdb) list 511 512 static int 513 match(REGISTER PCRE_PUCHAR eptr, REGISTER const pcre_uchar *ecode, 514 PCRE_PUCHAR mstart, int offset_top, match_data *md, eptrblock *eptrb, 515 unsigned int rdepth) 516 { 517 /* These variables do not need to be preserved over recursion in this function, 518 so they can be ordinary variables in all cases. Mark some of them with 519 "register" because they are used a lot in loops. */ 520 (gdb) bt #0 0x000000000060e47f in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966", offset_top=2, md=0x7fffffff9d40, eptrb=0x0, rdepth=8715) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:516 #1 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966", offset_top=2, md=0x7fffffff9d40, eptrb=0x0, rdepth=8714) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061 #2 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966", offset_top=2, md=0x7fffffff9d40, eptrb=0x0, rdepth=8713) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061 #3 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966", offset_top=2, md=0x7fffffff9d40, eptrb=0x0, rdepth=8712) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061 #4 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966", offset_top=2, md=0x7fffffff9d40, eptrb=0x0, rdepth=8711) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061 #5 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966", offset_top=2, md=0x7fffffff9d40, eptrb=0x0, rdepth=8710) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061 #6 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966", offset_top=2, md=0x7fffffff9d40, eptrb=0x0, rdepth=8709) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061 #7 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966", offset_top=2, md=0x7fffffff9d40, eptrb=0x0, rdepth=8708) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061 #8 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966", offset_top=2, md=0x7fffffff9d40, eptrb=0x0, rdepth=8707) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061 #9 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966", offset_top=2, md=0x7fffffff9d40, eptrb=0x0, rdepth=8706) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061 and on and on for infinity... -- Edit bug report at https://bugs.php.net/bug.php?id=73490&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=73490&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=73490&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=73490&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=73490&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=73490&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=73490&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=73490&r=needscript Try newer version: https://bugs.php.net/fix.php?id=73490&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=73490&r=support Expected behavior: https://bugs.php.net/fix.php?id=73490&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=73490&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=73490&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=73490&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=73490&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=73490&r=dst IIS Stability: https://bugs.php.net/fix.php?id=73490&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=73490&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=73490&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=73490&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=73490&r=mysqlcfg

« previous php.bugs (#205289) next »