Bug #74702 [NEW]: segfault in gc_zval_possible_root()
| From: | brian dot carpenter at gmail dot com | Date: | Tue, 06 Jun 2017 21:03:19 +0000 |
| Subject: | Bug #74702 [NEW]: segfault in gc_zval_possible_root() | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-209399@lists.php.net to get a copy of this message | ||
From: brian dot carpenter at gmail dot com
Operating system: Debian 8 x64
PHP version: 5.6.30
Package: Reproducible crash
Bug Type: Bug
Bug description:segfault in gc_zval_possible_root()
Description:
------------
The attached script crashes PHP 5.6.30.
Test script:
---------------
<?php
class bad{function t(){$h[]=0;}function
__destruct(){global$bar;$bar=$this;}}$foo->f=$foo=$d=new
bad;unserialize(serialize($foo));gc_collect_cycles();
Expected result:
----------------
No crash.
Actual result:
--------------
==12586==ERROR: AddressSanitizer: SEGV on unknown address 0x100139182d88
(pc 0x00000198aad7 sp 0x7fffc2f3a1c0 bp 0x7fe67d2d1840 T0)
#0 0x198aad6 in gc_zval_possible_root
/root/php-5.6.30/Zend/zend_gc.c:143
#1 0x19019d6 in zend_hash_destroy
/root/php-5.6.30/Zend/zend_hash.c:548
#2 0x19b32da in zend_object_std_dtor
/root/php-5.6.30/Zend/zend_objects.c:44
#3 0x19b3650 in zend_objects_free_object_storage
/root/php-5.6.30/Zend/zend_objects.c:137
#4 0x19e201a in zend_objects_store_del_ref_by_handle_ex
/root/php-5.6.30/Zend/zend_objects_API.c:226
#5 0x19e25b5 in zend_objects_store_del_ref
/root/php-5.6.30/Zend/zend_objects_API.c:178
#6 0x18162c7 in _zval_dtor
/root/php-5.6.30/Zend/zend_variables.h:35
#7 0x18162c7 in i_zval_ptr_dtor
/root/php-5.6.30/Zend/zend_execute.h:79
#8 0x18162c7 in _zval_ptr_dtor
/root/php-5.6.30/Zend/zend_execute_API.c:424
#9 0x1906e8e in i_zend_hash_bucket_delete
/root/php-5.6.30/Zend/zend_hash.c:182
#10 0x1906e8e in zend_hash_bucket_delete
/root/php-5.6.30/Zend/zend_hash.c:192
#11 0x1906e8e in zend_hash_reverse_apply
/root/php-5.6.30/Zend/zend_hash.c:733
#12 0x1817940 in shutdown_destructors
/root/php-5.6.30/Zend/zend_execute_API.c:214
#13 0x1898593 in zend_call_destructors
/root/php-5.6.30/Zend/zend.c:944
#14 0x15d2974 in php_request_shutdown
/root/php-5.6.30/main/main.c:1840
#15 0x1e68480 in do_cli /root/php-5.6.30/sapi/cli/php_cli.c:1181
#16 0x456468 in main /root/php-5.6.30/sapi/cli/php_cli.c:1382
#17 0x7fe67ae0cb44 in __libc_start_main
(/lib/x86_64-linux-gnu/libc.so.6+0x21b44)
#18 0x45730e (/root/php-5.6.30/sapi/cli/php+0x45730e)
AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV /root/php-5.6.30/Zend/zend_gc.c:143
gc_zval_possible_root
==12586==ABORTING
--
Edit bug report at https://bugs.php.net/bug.php?id=74702&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=74702&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=74702&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=74702&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=74702&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=74702&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=74702&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=74702&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=74702&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=74702&r=support
Expected behavior: https://bugs.php.net/fix.php?id=74702&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=74702&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=74702&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=74702&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=74702&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=74702&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=74702&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=74702&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=74702&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=74702&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=74702&r=mysqlcfg