Bug #74733 [Opn]: stack-overflow in spl_autoload_register
Edit report at https://bugs.php.net/bug.php?id=74733&edit=1
ID: 74733
Updated by: kalle@php.net
Reported by: martino dot sani at gmail dot com
Summary: stack-overflow in spl_autoload_register
Status: Open
Type: Bug
Package: SPL related
Operating System: Linux x86_64
PHP Version: 7.2Git-2017-06-09 (Git)
Block user comment: N
Private report: N
New Comment:
If anything this should result in a memory_limit error, much like other recursive loops
Previous Comments:
------------------------------------------------------------------------
[2017-06-10 07:43:34] requinix@php.net
Well yeah, of course that results in infinite recursion.
The only "bug" I see is that class_exists has no problem trying to load a class with an
invalid name. Same for interface_exists and trait_exists. Not that it should ever happen in real
code, though.
------------------------------------------------------------------------
[2017-06-09 21:37:00] martino dot sani at gmail dot com
Description:
------------
American fuzzy lop detects an infinite recursion that can lead to a stack-overflow.
Test platform:
Linux 4.9.20-std-1 #1 SMP Tue Apr 4 12:56:17 UTC 2017 x86_64 GNU/Linux
GIT SHA:
e72970026d381ab250b5cc4f9e3ad5f0a384ddaf
Test script:
---------------
<?php
spl_autoload_register(function($e){static$i;if($i++){}class_exists(''.$i);});var_dump(class_exists('0'))?>
Actual result:
--------------
$ ./php -f 0.php.tmin
ASAN:DEADLYSIGNAL
==18723==ERROR: AddressSanitizer: stack-overflow on address 0x7ffed1e32da8 (pc 0x0000004dcc91 bp
0x7ffed1e33650 sp 0x7ffed1e32db0 T0)
#0 0x4dcc90 in __interceptor_memcmp.part.69 (/tmp/bin/php+0x4dcc90)
#1 0x1aa4d2e in zend_hash_find_bucket /tmp/php-src-latest/Zend/zend_hash.c:491:8
#2 0x1aa4944 in zend_hash_find /tmp/php-src-latest/Zend/zend_hash.c:1958:6
#3 0x1db91c4 in ZEND_BIND_STATIC_SPEC_CV_CONST_HANDLER
/tmp/php-src-latest/Zend/zend_vm_execute.h:38766:10
#4 0x1b8de13 in execute_ex /tmp/php-src-latest/Zend/zend_vm_execute.h:59725:7
#5 0x19f18d3 in zend_call_function /tmp/php-src-latest/Zend/zend_execute_API.c:863:3
#6 0x143a561 in zif_spl_autoload_call /tmp/php-src-latest/ext/spl/php_spl.c:451:4
#7 0x19f1cda in zend_call_function /tmp/php-src-latest/Zend/zend_execute_API.c:877:4
#8 0x19f40f0 in zend_lookup_class_ex /tmp/php-src-latest/Zend/zend_execute_API.c:1040:7
#9 0x19f464d in zend_lookup_class /tmp/php-src-latest/Zend/zend_execute_API.c:1061:9
#10 0x1ac3441 in zif_class_exists /tmp/php-src-latest/Zend/zend_builtin_functions.c:1391:8
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74733&edit=1
Thread (5 messages)