Bug #73490 [NEW]: segfault in pcre_exec.c
| From: | brian dot carpenter at gmail dot com | Date: | Thu, 10 Nov 2016 19:27:45 +0000 |
| Subject: | Bug #73490 [NEW]: segfault in pcre_exec.c | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-205289@lists.php.net to get a copy of this message | ||
From: brian dot carpenter at gmail dot com
Operating system: Debian 8.x
PHP version: 5.6.27
Package: Reproducible crash
Bug Type: Bug
Bug description:segfault in pcre_exec.c
Description:
------------
Found while fuzzing with AFL+ASan.
Test script:
---------------
<?php
$pattern = '(?(1)0|(?(1)0)+)+((()))';
$a = preg_match("/$pattern/", '2966');
var_dump($a);
Expected result:
----------------
No crash. For example, PHP 5.6.24-0+deb8u1 returns int(1).
Actual result:
--------------
Program received signal SIGSEGV, Segmentation fault.
0x000000000060e47f in match (eptr=0x7ffff7e63610 "2966",
ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966",
offset_top=2,
md=0x7fffffff9d40, eptrb=0x0, rdepth=8715) at
/root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:516
516 {
(gdb) list
511
512 static int
513 match(REGISTER PCRE_PUCHAR eptr, REGISTER const pcre_uchar
*ecode,
514 PCRE_PUCHAR mstart, int offset_top, match_data *md, eptrblock
*eptrb,
515 unsigned int rdepth)
516 {
517 /* These variables do not need to be preserved over recursion in
this function,
518 so they can be ordinary variables in all cases. Mark some of
them with
519 "register" because they are used a lot in loops. */
520
(gdb) bt
#0 0x000000000060e47f in match (eptr=0x7ffff7e63610 "2966",
ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966",
offset_top=2,
md=0x7fffffff9d40, eptrb=0x0, rdepth=8715) at
/root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:516
#1 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966",
ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966",
offset_top=2,
md=0x7fffffff9d40, eptrb=0x0, rdepth=8714) at
/root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061
#2 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966",
ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966",
offset_top=2,
md=0x7fffffff9d40, eptrb=0x0, rdepth=8713) at
/root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061
#3 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966",
ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966",
offset_top=2,
md=0x7fffffff9d40, eptrb=0x0, rdepth=8712) at
/root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061
#4 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966",
ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966",
offset_top=2,
md=0x7fffffff9d40, eptrb=0x0, rdepth=8711) at
/root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061
#5 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966",
ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966",
offset_top=2,
md=0x7fffffff9d40, eptrb=0x0, rdepth=8710) at
/root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061
#6 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966",
ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966",
offset_top=2,
md=0x7fffffff9d40, eptrb=0x0, rdepth=8709) at
/root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061
#7 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966",
ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966",
offset_top=2,
md=0x7fffffff9d40, eptrb=0x0, rdepth=8708) at
/root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061
#8 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966",
ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966",
offset_top=2,
md=0x7fffffff9d40, eptrb=0x0, rdepth=8707) at
/root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061
#9 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966",
ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966",
offset_top=2,
md=0x7fffffff9d40, eptrb=0x0, rdepth=8706) at
/root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061
and on and on for infinity...
--
Edit bug report at https://bugs.php.net/bug.php?id=73490&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=73490&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=73490&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=73490&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=73490&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=73490&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=73490&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=73490&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=73490&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=73490&r=support
Expected behavior: https://bugs.php.net/fix.php?id=73490&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=73490&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=73490&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=73490&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=73490&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=73490&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=73490&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=73490&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=73490&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=73490&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=73490&r=mysqlcfg