Bug #73612 [Asn->Csd]: preg_*() may leak memory

From: Date: Sat, 26 Nov 2016 15:18:18 +0000
Subject: Bug #73612 [Asn->Csd]: preg_*() may leak memory
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205651@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73612&edit=1 ID: 73612 Updated by: cmb@php.net Reported by: cmb@php.net Summary: preg_*() may leak memory -Status: Assigned +Status: Closed Type: Bug Package: PCRE related Operating System: * PHP Version: 7.0Git-2016-11-26 (Git) Assigned To: cmb Block user comment: N Private report: N New Comment: Automatic comment on behalf of cmbecker69@gmx.de Revision: http://git.php.net/?p=php-src.git;a=commit;h=003727d851da770c60555a2aecf6d82497b04f42 Log: Fix #73612: preg_*() may leak memory Previous Comments: ------------------------------------------------------------------------ [2016-11-26 14:12:50] cmb@php.net Description: ------------ As has been pointed out by Nikita[1], as of PHP 7.0.0 zval_dtor() is actually the same as zval_ptr_dtor_nogc(). Therefore preg_match() and some other PCRE functions may leak memory if objects are passed as $matches and $count, respectively. [1] <http://news.php.net/php.internals/97197> Test script: --------------- <?php $obj = new stdClass; $obj->obj = $obj; preg_match('/./', 'x', $obj); $obj = new stdClass; $obj->obj = $obj; preg_replace('/./', '', 'x', -1, $obj); $obj = new stdClass; $obj->obj = $obj; preg_replace_callback('/./', 'array_merge', 'x', -1, $obj); $obj = new stdClass; $obj->obj = $obj; preg_replace_callback_array(['/./' => 'array_merge'], 'x', -1, $obj); $obj = new stdClass; $obj->obj = $obj; preg_filter('/./', '', 'x', -1, $obj); Actual result: -------------- [Sat Nov 26 14:03:38 2016] Script: '/vagrant/leak.php' /vagrant/php-src/Zend/zend_objects.c(162) : Freeing 0x7FF12465ECD0 (40 bytes), script=/vagrant/leak.php Last leak repeated 4 times === Total 5 memory leaks detected === ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73612&edit=1

« previous php.bugs (#205651) next »