Bug #74376 [Opn->Csd]: Invalid free of persistent results on error/connection loss

From: Date: Mon, 10 Apr 2017 05:58:54 +0000
Subject: Bug #74376 [Opn->Csd]: Invalid free of persistent results on error/connection loss
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-208412@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74376&edit=1 ID: 74376 Updated by: krakjoe@php.net Reported by: dev at pp3345 dot net Summary: Invalid free of persistent results on error/connection loss -Status: Open +Status: Closed Type: Bug Package: MySQL related Operating System: Irrelevant PHP Version: 7.1.3 -Assigned To: +Assigned To: krakjoe Block user comment: N Private report: N New Comment: The fix for this bug has been committed. Snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. For Windows: http://windows.php.net/snapshots/ Thank you for the report, and for helping us make PHP better. Not sure why this didn't close automatically. Previous Comments: ------------------------------------------------------------------------ [2017-04-05 18:51:12] dev at pp3345 dot net Description: ------------ mysqlnd allocates result objects in mysqlnd_result.c:1899 (mysqlnd_result_init): MYSQLND_RES * ret = mnd_pecalloc(1, alloc_size, persistent); Note that these objects may be allocated persistently if the underlying connection is persistent. Normally these objects will be free'd in mysqlnd_result.c:347 (mysqlnd_res::free_result_internal): mnd_pefree(result, result->persistent); Here, the persistency flag is respected. However, in some cases (query errors or connection loss), mysqlnd_ps.c will use mnd_efree() instead of mnd_pefree() to free a result object: line 132 (mysqlnd_stmt::store_result): mnd_efree(stmt->result); line 359 (mysqlnd_stmt_prepare_read_eof): mnd_efree(stmt->result); This will cause segfaults/"zend_mm_heap corrupted" in the above-mentioned cases. Test script: --------------- <?php $conn = new PDO("mysql:...", "...", "...", [PDO::ATTR_PERSISTENT => true, PDO::ATTR_EMULATE_PREPARES => false]); $conn->query("select (select 1 union select 2)"); Expected result: ---------------- Script executes successfully. Actual result: -------------- segfault ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=74376&edit=1

« previous php.bugs (#208412) next »