Bug #74702 [Com]: segfault in gc_zval_possible_root()

From: Date: Wed, 07 Jun 2017 10:19:10 +0000
Subject: Bug #74702 [Com]: segfault in gc_zval_possible_root()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-209403@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74702&edit=1 ID: 74702 Comment by: andrew dot nester dot dev at gmail dot com Reported by: brian dot carpenter at gmail dot com Summary: segfault in gc_zval_possible_root() Status: Open Type: Bug Package: Reproducible crash Operating System: Debian 8 x64 PHP Version: 5.6.30 Block user comment: N Private report: N New Comment: Since PHP 5.6+ supports only security fixes and this issue is not reproducible in PHP 7+ I guess this issue should be closed as won't fix Previous Comments: ------------------------------------------------------------------------ [2017-06-06 21:03:12] brian dot carpenter at gmail dot com Description: ------------ The attached script crashes PHP 5.6.30. Test script: --------------- <?php class bad{function t(){$h[]=0;}function __destruct(){global$bar;$bar=$this;}}$foo->f=$foo=$d=new bad;unserialize(serialize($foo));gc_collect_cycles(); Expected result: ---------------- No crash. Actual result: -------------- ==12586==ERROR: AddressSanitizer: SEGV on unknown address 0x100139182d88 (pc 0x00000198aad7 sp 0x7fffc2f3a1c0 bp 0x7fe67d2d1840 T0) #0 0x198aad6 in gc_zval_possible_root /root/php-5.6.30/Zend/zend_gc.c:143 #1 0x19019d6 in zend_hash_destroy /root/php-5.6.30/Zend/zend_hash.c:548 #2 0x19b32da in zend_object_std_dtor /root/php-5.6.30/Zend/zend_objects.c:44 #3 0x19b3650 in zend_objects_free_object_storage /root/php-5.6.30/Zend/zend_objects.c:137 #4 0x19e201a in zend_objects_store_del_ref_by_handle_ex /root/php-5.6.30/Zend/zend_objects_API.c:226 #5 0x19e25b5 in zend_objects_store_del_ref /root/php-5.6.30/Zend/zend_objects_API.c:178 #6 0x18162c7 in _zval_dtor /root/php-5.6.30/Zend/zend_variables.h:35 #7 0x18162c7 in i_zval_ptr_dtor /root/php-5.6.30/Zend/zend_execute.h:79 #8 0x18162c7 in _zval_ptr_dtor /root/php-5.6.30/Zend/zend_execute_API.c:424 #9 0x1906e8e in i_zend_hash_bucket_delete /root/php-5.6.30/Zend/zend_hash.c:182 #10 0x1906e8e in zend_hash_bucket_delete /root/php-5.6.30/Zend/zend_hash.c:192 #11 0x1906e8e in zend_hash_reverse_apply /root/php-5.6.30/Zend/zend_hash.c:733 #12 0x1817940 in shutdown_destructors /root/php-5.6.30/Zend/zend_execute_API.c:214 #13 0x1898593 in zend_call_destructors /root/php-5.6.30/Zend/zend.c:944 #14 0x15d2974 in php_request_shutdown /root/php-5.6.30/main/main.c:1840 #15 0x1e68480 in do_cli /root/php-5.6.30/sapi/cli/php_cli.c:1181 #16 0x456468 in main /root/php-5.6.30/sapi/cli/php_cli.c:1382 #17 0x7fe67ae0cb44 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x21b44) #18 0x45730e (/root/php-5.6.30/sapi/cli/php+0x45730e) AddressSanitizer can not provide additional info. SUMMARY: AddressSanitizer: SEGV /root/php-5.6.30/Zend/zend_gc.c:143 gc_zval_possible_root ==12586==ABORTING ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=74702&edit=1

« previous php.bugs (#209403) next »