Bug #73490 [Opn->Nab]: segfault in match (pcre_exec.c)

From: Date: Fri, 18 Nov 2016 12:10:34 +0000
Subject: Bug #73490 [Opn->Nab]: segfault in match (pcre_exec.c)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205451@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73490&edit=1 ID: 73490 Updated by: cmb@php.net Reported by: brian dot carpenter at gmail dot com Summary: segfault in match (pcre_exec.c) -Status: Open +Status: Not a bug Type: Bug -Package: Reproducible crash +Package: PCRE related Operating System: Debian 8.x PHP Version: 5.6.28 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: I can reproduce the segfault due to "infinite" recursion with the default pcre.recursion_limit=100000. The script succeeds for me with pcre.recursion_limit=25000, though. The result is than correctly bool(false) and not int(1) which would be wrong. I don't think this is a bug, because the regexp is "pathological"[1], and pcre.recursion_limit is already configurable. [1] <https://swtch.com/~rsc/regexp/regexp1.html> Previous Comments: ------------------------------------------------------------------------ [2016-11-10 21:07:10] brian dot carpenter at gmail dot com Updated because it also crashes the recently released 5.6.28. ------------------------------------------------------------------------ [2016-11-10 19:27:44] brian dot carpenter at gmail dot com Description: ------------ Found while fuzzing with AFL+ASan. Test script: --------------- <?php $pattern = '(?(1)0|(?(1)0)+)+((()))'; $a = preg_match("/$pattern/", '2966'); var_dump($a); Expected result: ---------------- No crash. For example, PHP 5.6.24-0+deb8u1 returns int(1). Actual result: -------------- Program received signal SIGSEGV, Segmentation fault. 0x000000000060e47f in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966", offset_top=2, md=0x7fffffff9d40, eptrb=0x0, rdepth=8715) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:516 516 { (gdb) list 511 512 static int 513 match(REGISTER PCRE_PUCHAR eptr, REGISTER const pcre_uchar *ecode, 514 PCRE_PUCHAR mstart, int offset_top, match_data *md, eptrblock *eptrb, 515 unsigned int rdepth) 516 { 517 /* These variables do not need to be preserved over recursion in this function, 518 so they can be ordinary variables in all cases. Mark some of them with 519 "register" because they are used a lot in loops. */ 520 (gdb) bt #0 0x000000000060e47f in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966", offset_top=2, md=0x7fffffff9d40, eptrb=0x0, rdepth=8715) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:516 #1 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966", offset_top=2, md=0x7fffffff9d40, eptrb=0x0, rdepth=8714) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061 #2 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966", offset_top=2, md=0x7fffffff9d40, eptrb=0x0, rdepth=8713) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061 #3 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966", offset_top=2, md=0x7fffffff9d40, eptrb=0x0, rdepth=8712) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061 #4 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966", offset_top=2, md=0x7fffffff9d40, eptrb=0x0, rdepth=8711) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061 #5 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966", offset_top=2, md=0x7fffffff9d40, eptrb=0x0, rdepth=8710) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061 #6 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966", offset_top=2, md=0x7fffffff9d40, eptrb=0x0, rdepth=8709) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061 #7 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966", offset_top=2, md=0x7fffffff9d40, eptrb=0x0, rdepth=8708) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061 #8 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966", offset_top=2, md=0x7fffffff9d40, eptrb=0x0, rdepth=8707) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061 #9 0x000000000066b5a1 in match (eptr=0x7ffff7e63610 "2966", ecode=0x60c000006743 "\207", mstart=0x7ffff7e63610 "2966", offset_top=2, md=0x7fffffff9d40, eptrb=0x0, rdepth=8706) at /root/php-5.6.27/ext/pcre/pcrelib/pcre_exec.c:2061 and on and on for infinity... ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73490&edit=1

« previous php.bugs (#205451) next »