Bug #74702 [Com]: segfault in gc_zval_possible_root()
| From: | andrew dot nester dot dev at gmail dot com | Date: | Wed, 07 Jun 2017 10:19:10 +0000 |
| Subject: | Bug #74702 [Com]: segfault in gc_zval_possible_root() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-209403@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=74702&edit=1
ID: 74702
Comment by: andrew dot nester dot dev at gmail dot com
Reported by: brian dot carpenter at gmail dot com
Summary: segfault in gc_zval_possible_root()
Status: Open
Type: Bug
Package: Reproducible crash
Operating System: Debian 8 x64
PHP Version: 5.6.30
Block user comment: N
Private report: N
New Comment:
Since PHP 5.6+ supports only security fixes and this issue is not reproducible in PHP 7+ I guess
this issue should be closed as
won't fix
Previous Comments:
------------------------------------------------------------------------
[2017-06-06 21:03:12] brian dot carpenter at gmail dot com
Description:
------------
The attached script crashes PHP 5.6.30.
Test script:
---------------
<?php
class bad{function t(){$h[]=0;}function __destruct(){global$bar;$bar=$this;}}$foo->f=$foo=$d=new
bad;unserialize(serialize($foo));gc_collect_cycles();
Expected result:
----------------
No crash.
Actual result:
--------------
==12586==ERROR: AddressSanitizer: SEGV on unknown address 0x100139182d88 (pc 0x00000198aad7 sp
0x7fffc2f3a1c0 bp 0x7fe67d2d1840 T0)
#0 0x198aad6 in gc_zval_possible_root /root/php-5.6.30/Zend/zend_gc.c:143
#1 0x19019d6 in zend_hash_destroy /root/php-5.6.30/Zend/zend_hash.c:548
#2 0x19b32da in zend_object_std_dtor /root/php-5.6.30/Zend/zend_objects.c:44
#3 0x19b3650 in zend_objects_free_object_storage /root/php-5.6.30/Zend/zend_objects.c:137
#4 0x19e201a in zend_objects_store_del_ref_by_handle_ex
/root/php-5.6.30/Zend/zend_objects_API.c:226
#5 0x19e25b5 in zend_objects_store_del_ref /root/php-5.6.30/Zend/zend_objects_API.c:178
#6 0x18162c7 in _zval_dtor /root/php-5.6.30/Zend/zend_variables.h:35
#7 0x18162c7 in i_zval_ptr_dtor /root/php-5.6.30/Zend/zend_execute.h:79
#8 0x18162c7 in _zval_ptr_dtor /root/php-5.6.30/Zend/zend_execute_API.c:424
#9 0x1906e8e in i_zend_hash_bucket_delete /root/php-5.6.30/Zend/zend_hash.c:182
#10 0x1906e8e in zend_hash_bucket_delete /root/php-5.6.30/Zend/zend_hash.c:192
#11 0x1906e8e in zend_hash_reverse_apply /root/php-5.6.30/Zend/zend_hash.c:733
#12 0x1817940 in shutdown_destructors /root/php-5.6.30/Zend/zend_execute_API.c:214
#13 0x1898593 in zend_call_destructors /root/php-5.6.30/Zend/zend.c:944
#14 0x15d2974 in php_request_shutdown /root/php-5.6.30/main/main.c:1840
#15 0x1e68480 in do_cli /root/php-5.6.30/sapi/cli/php_cli.c:1181
#16 0x456468 in main /root/php-5.6.30/sapi/cli/php_cli.c:1382
#17 0x7fe67ae0cb44 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x21b44)
#18 0x45730e (/root/php-5.6.30/sapi/cli/php+0x45730e)
AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV /root/php-5.6.30/Zend/zend_gc.c:143 gc_zval_possible_root
==12586==ABORTING
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74702&edit=1