Bug #73800 [Opn->Csd]: Sporadic segfault in mysqlnd with MYSQLI_OPT_INT_AND_FLOAT_NATIVE enabled
| From: | krakjoe@php.net | Date: | Sun, 08 Jan 2017 17:17:17 +0000 |
| Subject: | Bug #73800 [Opn->Csd]: Sporadic segfault in mysqlnd with MYSQLI_OPT_INT_AND_FLOAT_NATIVE enabled | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-206395@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73800&edit=1
ID: 73800
Updated by: krakjoe@php.net
Reported by: php at vanviegen dot net
Summary: Sporadic segfault in mysqlnd with
MYSQLI_OPT_INT_AND_FLOAT_NATIVE enabled
-Status: Open
+Status: Closed
Type: Bug
Package: MySQLi related
PHP Version: 7.0.14
-Assigned To:
+Assigned To: krakjoe
Block user comment: N
Private report: N
New Comment:
The fix for this bug has been committed.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
For Windows:
http://windows.php.net/snapshots/
Thank you for the report, and for helping us make PHP better.
Previous Comments:
------------------------------------------------------------------------
[2016-12-21 15:14:46] php at vanviegen dot net
Description:
------------
The segfault happens sporadically, usually when reading large amounts of data. The backtrace is
instructive:
#0 php_mysqlnd_rowp_read_text_protocol_aux (row_buffer=<optimized out>,
fields=<optimized out>, field_count=<optimized out>, fields_metadata=0x7fa0dd9c5e20,
as_int_or_float=1 '\001', stats=0x7fa0dd95c460)
at /usr/src/builddir/ext/mysqlnd/mysqlnd_wireprotocol.c:1674
#1 0x00007fa0d97a6239 in php_mysqlnd_result_buffered_zval_fetch_row_pub (
result=<optimized out>, param=0x7fa0d9c146b0, flags=2,
fetched_anything=0x7ffebc5139a7 "")
at /usr/src/builddir/ext/mysqlnd/mysqlnd_result.c:1078
#2 0x00007fa0d97a6705 in php_mysqlnd_res_fetch_into_pub (result=0x7fa0dd9c4500, flags=2,
return_value=0x7fa0d9c146b0, extension=MYSQLND_MYSQLI)
at /usr/src/builddir/ext/mysqlnd/mysqlnd_result.c:1727
#3 0x00007fa0cfd044e7 in php_mysqli_fetch_into_hash (execute_data=0x7ffebc5138e0,
return_value=0x7fa0d9c146b0, override_flags=0, into_object=0)
at /usr/src/builddir/ext/mysqli/mysqli.c:1275
#4 0x00007fa0dc0b7726 in ZEND_DO_FCALL_SPEC_HANDLER ()
at /usr/src/builddir/Zend/zend_vm_execute.h:842
[...]
Which resolves to the second line of this code fragment of ext/mysqlnd/mysqlnd_wireprotocol.c:
if (as_int_or_float && perm_bind.php_type == IS_LONG) {
zend_uchar save = *(p + len);
/* We have to make it ASCIIZ temporarily */
*(p + len) = '\0';
So when a row ends with a long (or a float), this writes past the end of the row_buffer. As the old
value is restored later on in this function, this is usually not a problem. Unless of course it
happens to access unmapped address space.
Test script:
---------------
This bug seems rather impossible to reproduce deterministically, sorry!
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73800&edit=1