Bug #74733 [Opn]: stack-overflow in spl_autoload_register

From: Date: Thu, 15 Jun 2017 18:51:33 +0000
Subject: Bug #74733 [Opn]: stack-overflow in spl_autoload_register
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-209546@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74733&edit=1

 ID:                 74733
 Updated by:         kalle@php.net
 Reported by:        martino dot sani at gmail dot com
 Summary:            stack-overflow in spl_autoload_register
 Status:             Open
 Type:               Bug
 Package:            SPL related
 Operating System:   Linux x86_64
 PHP Version:        7.2Git-2017-06-09 (Git)
 Block user comment: N
 Private report:     N

 New Comment:

If anything this should result in a memory_limit error, much like other recursive loops


Previous Comments:
------------------------------------------------------------------------
[2017-06-10 07:43:34] requinix@php.net

Well yeah, of course that results in infinite recursion.

The only "bug" I see is that class_exists has no problem trying to load a class with an
invalid name. Same for interface_exists and trait_exists. Not that it should ever happen in real
code, though.

------------------------------------------------------------------------
[2017-06-09 21:37:00] martino dot sani at gmail dot com

Description:
------------
American fuzzy lop detects an infinite recursion that can lead to a stack-overflow.

Test platform:
Linux 4.9.20-std-1 #1 SMP Tue Apr 4 12:56:17 UTC 2017 x86_64 GNU/Linux

GIT SHA:
e72970026d381ab250b5cc4f9e3ad5f0a384ddaf

Test script:
---------------
<?php
spl_autoload_register(function($e){static$i;if($i++){}class_exists(''.$i);});var_dump(class_exists('0'))?>

Actual result:
--------------
$ ./php -f 0.php.tmin
                         
ASAN:DEADLYSIGNAL

==18723==ERROR: AddressSanitizer: stack-overflow on address 0x7ffed1e32da8 (pc 0x0000004dcc91 bp
0x7ffed1e33650 sp 0x7ffed1e32db0 T0)
    #0 0x4dcc90 in __interceptor_memcmp.part.69 (/tmp/bin/php+0x4dcc90)               
    #1 0x1aa4d2e in zend_hash_find_bucket /tmp/php-src-latest/Zend/zend_hash.c:491:8
    #2 0x1aa4944 in zend_hash_find /tmp/php-src-latest/Zend/zend_hash.c:1958:6                      
         
    #3 0x1db91c4 in ZEND_BIND_STATIC_SPEC_CV_CONST_HANDLER
/tmp/php-src-latest/Zend/zend_vm_execute.h:38766:10
    #4 0x1b8de13 in execute_ex /tmp/php-src-latest/Zend/zend_vm_execute.h:59725:7                   
         
    #5 0x19f18d3 in zend_call_function /tmp/php-src-latest/Zend/zend_execute_API.c:863:3            
         
    #6 0x143a561 in zif_spl_autoload_call /tmp/php-src-latest/ext/spl/php_spl.c:451:4               
         
    #7 0x19f1cda in zend_call_function /tmp/php-src-latest/Zend/zend_execute_API.c:877:4     
    #8 0x19f40f0 in zend_lookup_class_ex /tmp/php-src-latest/Zend/zend_execute_API.c:1040:7   
    #9 0x19f464d in zend_lookup_class /tmp/php-src-latest/Zend/zend_execute_API.c:1061:9            
         
    #10 0x1ac3441 in zif_class_exists /tmp/php-src-latest/Zend/zend_builtin_functions.c:1391:8      
         


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=74733&edit=1


Thread (5 messages)

« previous php.bugs (#209546) next »