Bug #74376 [Opn->Csd]: Invalid free of persistent results on error/connection loss
| From: | krakjoe@php.net | Date: | Mon, 10 Apr 2017 05:58:54 +0000 |
| Subject: | Bug #74376 [Opn->Csd]: Invalid free of persistent results on error/connection loss | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-208412@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=74376&edit=1
ID: 74376
Updated by: krakjoe@php.net
Reported by: dev at pp3345 dot net
Summary: Invalid free of persistent results on
error/connection loss
-Status: Open
+Status: Closed
Type: Bug
Package: MySQL related
Operating System: Irrelevant
PHP Version: 7.1.3
-Assigned To:
+Assigned To: krakjoe
Block user comment: N
Private report: N
New Comment:
The fix for this bug has been committed.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
For Windows:
http://windows.php.net/snapshots/
Thank you for the report, and for helping us make PHP better.
Not sure why this didn't close automatically.
Previous Comments:
------------------------------------------------------------------------
[2017-04-05 18:51:12] dev at pp3345 dot net
Description:
------------
mysqlnd allocates result objects in mysqlnd_result.c:1899 (mysqlnd_result_init):
MYSQLND_RES * ret = mnd_pecalloc(1, alloc_size, persistent);
Note that these objects may be allocated persistently if the underlying connection is persistent.
Normally these objects will be free'd in mysqlnd_result.c:347
(mysqlnd_res::free_result_internal):
mnd_pefree(result, result->persistent);
Here, the persistency flag is respected.
However, in some cases (query errors or connection loss), mysqlnd_ps.c will use mnd_efree() instead
of mnd_pefree() to free a result object:
line 132 (mysqlnd_stmt::store_result):
mnd_efree(stmt->result);
line 359 (mysqlnd_stmt_prepare_read_eof):
mnd_efree(stmt->result);
This will cause segfaults/"zend_mm_heap corrupted" in the above-mentioned cases.
Test script:
---------------
<?php
$conn = new PDO("mysql:...", "...", "...", [PDO::ATTR_PERSISTENT =>
true, PDO::ATTR_EMULATE_PREPARES => false]);
$conn->query("select (select 1 union select 2)");
Expected result:
----------------
Script executes successfully.
Actual result:
--------------
segfault
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74376&edit=1