Bug #74146 [NEW]: Null pointer dereference in _zval_get_long_func_ex()
| From: | fumfi dot 255 at gmail dot com | Date: | Wed, 22 Feb 2017 07:48:17 +0000 |
| Subject: | Bug #74146 [NEW]: Null pointer dereference in _zval_get_long_func_ex() | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-207503@lists.php.net to get a copy of this message | ||
From: fumfi dot 255 at gmail dot com
Operating system: Linux x64
PHP version: 7.1.2
Package: Unknown/Other Function
Bug Type: Bug
Bug description:Null pointer dereference in _zval_get_long_func_ex()
Description:
------------
After some fuzz testing I found a crashing test case.
PHP 7.1.2 compiled from source with ASAN.
To reproduce: /php-7.1.2/sapi/cli/php php_zend_null_ptr.php
ASAN report:
ASAN:DEADLYSIGNAL
=================================================================
==26915==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000159
(pc 0x00000181faa6 bp 0x7fffa1f671b0 sp 0x7fffa1f670a0 T0)
==26915==The signal is caused by a READ memory access.
==26915==Hint: address points to the zero page.
#0 0x181faa5 in _zval_get_long_func_ex
XYZ/php-7.1.2/Zend/zend_operators.c:787:5
#1 0x181faa5 in _zval_get_long_func
XYZ/php-7.1.2/Zend/zend_operators.c:805
#2 0x17b581d in _zval_get_long
XYZ/php-7.1.2/Zend/zend_operators.h:270:50
#3 0x17b581d in zend_compile_declare
XYZ/php-7.1.2/Zend/zend_compile.c:4973
#4 0x17a6806 in zend_compile_stmt
XYZ/php-7.1.2/Zend/zend_compile.c:7834:4
#5 0x17cada3 in zend_compile_top_stmt
XYZ/php-7.1.2/Zend/zend_compile.c:7756:2
#6 0x17cad48 in zend_compile_top_stmt
XYZ/php-7.1.2/Zend/zend_compile.c:7751:4
#7 0x16e65c6 in zend_compile
XYZ/php-7.1.2/Zend/zend_language_scanner.l:601:3
#8 0x16e5f34 in compile_file
XYZ/php-7.1.2/Zend/zend_language_scanner.l:635:14
#9 0x11ba040 in phar_compile_file
XYZ/php-7.1.2/ext/phar/phar.c:3320:9
#10 0x185b1a8 in zend_execute_scripts
XYZ/php-7.1.2/Zend/zend.c:1469:14
#11 0x161d54d in php_execute_script
XYZ/php-7.1.2/main/main.c:2537:14
#12 0x1ccd48b in do_cli XYZ/php-7.1.2/sapi/cli/php_cli.c:993:5
#13 0x1cca38e in main XYZ/php-7.1.2/sapi/cli/php_cli.c:1381:18
#14 0x7f5bac0ed82f in __libc_start_main
(/lib/x86_64-linux-gnu/libc.so.6+0x2082f)
#15 0x463528 in _start (XYZ/php-7.1.2/sapi/cli/php+0x463528)
AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV
XYZ/php-7.1.2/Zend/zend_operators.c:787:5 in _zval_get_long_func_ex
==26915==ABORTING
Test script:
---------------
<?(function(){});function f(){}declare(ticks=±){}
--
Edit bug report at https://bugs.php.net/bug.php?id=74146&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=74146&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=74146&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=74146&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=74146&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=74146&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=74146&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=74146&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=74146&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=74146&r=support
Expected behavior: https://bugs.php.net/fix.php?id=74146&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=74146&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=74146&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=74146&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=74146&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=74146&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=74146&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=74146&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=74146&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=74146&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=74146&r=mysqlcfg