Bug #73490 [Opn]: segfault in match (pcre_exec.c)
| From: | brian dot carpenter at gmail dot com | Date: | Thu, 10 Nov 2016 21:07:10 +0000 |
| Subject: | Bug #73490 [Opn]: segfault in match (pcre_exec.c) | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-205290@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73490&edit=1
ID: 73490
User updated by: brian dot carpenter at gmail dot com
Reported by: brian dot carpenter at gmail dot com
-Summary: segfault in pcre_exec.c
+Summary: segfault in match (pcre_exec.c)
Status: Open
Type: Bug
Package: Reproducible crash
Operating System: Debian 8.x
-PHP Version: 5.6.27
+PHP Version: 5.6.28
Block user comment: N
Private report: N
New Comment:
Updated because it also crashes the recently released 5.6.28.
Previous Comments:
------------------------------------------------------------------------
[2016-11-10 19:27:44] brian dot carpenter at gmail dot com
Description:
------------
Found while fuzzing with AFL+ASan.
Test script:
---------------
<?php
$pattern = '(?(1)0|(?(1)0)+)+((()))';
$a = preg_match("/$pattern/", '2966');
var_dump($a);
Expected result:
----------------
No crash. For example, PHP 5.6.24-0+deb8u1 returns int(1).
Actual result:
--------------
Program received signal SIGSEGV, Segmentation fault.
0x000000000060e47f in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743
"\207", mstart=0x7ffff7e63610 "2966", offset_top=2,
md=0x7fffffff9d40, eptrb=0x0, rdepth=8715) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:516
516 {
(gdb) list
511
512 static int
513 match(REGISTER PCRE_PUCHAR eptr, REGISTER const pcre_uchar *ecode,
514 PCRE_PUCHAR mstart, int offset_top, match_data *md, eptrblock *eptrb,
515 unsigned int rdepth)
516 {
517 /* These variables do not need to be preserved over recursion in this function,
518 so they can be ordinary variables in all cases. Mark some of them with
519 "register" because they are used a lot in loops. */
520
(gdb) bt
#0 0x000000000060e47f in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743
"\207", mstart=0x7ffff7e63610 "2966", offset_top=2,
md=0x7fffffff9d40, eptrb=0x0, rdepth=8715) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:516
#1 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743
"\207", mstart=0x7ffff7e63610 "2966", offset_top=2,
md=0x7fffffff9d40, eptrb=0x0, rdepth=8714) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061
#2 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743
"\207", mstart=0x7ffff7e63610 "2966", offset_top=2,
md=0x7fffffff9d40, eptrb=0x0, rdepth=8713) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061
#3 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743
"\207", mstart=0x7ffff7e63610 "2966", offset_top=2,
md=0x7fffffff9d40, eptrb=0x0, rdepth=8712) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061
#4 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743
"\207", mstart=0x7ffff7e63610 "2966", offset_top=2,
md=0x7fffffff9d40, eptrb=0x0, rdepth=8711) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061
#5 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743
"\207", mstart=0x7ffff7e63610 "2966", offset_top=2,
md=0x7fffffff9d40, eptrb=0x0, rdepth=8710) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061
#6 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743
"\207", mstart=0x7ffff7e63610 "2966", offset_top=2,
md=0x7fffffff9d40, eptrb=0x0, rdepth=8709) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061
#7 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743
"\207", mstart=0x7ffff7e63610 "2966", offset_top=2,
md=0x7fffffff9d40, eptrb=0x0, rdepth=8708) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061
#8 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743
"\207", mstart=0x7ffff7e63610 "2966", offset_top=2,
md=0x7fffffff9d40, eptrb=0x0, rdepth=8707) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061
#9 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743
"\207", mstart=0x7ffff7e63610 "2966", offset_top=2,
md=0x7fffffff9d40, eptrb=0x0, rdepth=8706) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061
and on and on for infinity...
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73490&edit=1