Bug #74954 [NEW]: null deref and segfault in zend_generator_resume()
| From: | geeknik at protonmail dot ch | Date: | Wed, 19 Jul 2017 19:58:00 +0000 |
| Subject: | Bug #74954 [NEW]: null deref and segfault in zend_generator_resume() | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-210143@lists.php.net to get a copy of this message | ||
From: geeknik at protonmail dot ch
Operating system: Fedora 26 x64
PHP version: 7.1.7
Package: Reproducible crash
Bug Type: Bug
Bug description:null deref and segfault in zend_generator_resume()
Description:
------------
Compiled with afl-clang-fast on Fedora 26 x64. While fuzzing with AFL
this null deref triggered a segfault.
Test script:
---------------
<?php
function from() {
yield 1;
throw new Exception();
}
function gen($gen) {
try {
var_dump(yield from $gen);
} catch (Exception $e) { print "Caught exception!\n$e\n"; }
}
$gen = from();
$gens[] = gen($gen);
$gens[] = gen($gen);
foreach ($gens as $g) {
$g->current();
}
do {
foreach ($gens as $i => $g) {
$g->next();
}
} while($gens[0]->valid());
?>
Expected result:
----------------
No crash.
Actual result:
--------------
Caught exception!
Exception in /root/php-tmp/tmp/1.php:4
Stack trace:
#0 /root/php-tmp/tmp/1.php(9): from()
#1 [internal function]: gen(Object(Generator))
#2 /root/php-tmp/tmp/1.php(23): Generator->next()
#3 {main}
/root/php-7.1.7/Zend/zend_hash.c:1291:41: runtime error: left shift of
32768 by 16 places cannot be represented in type 'int'
SUMMARY: AddressSanitizer: undefined-behavior
/root/php-7.1.7/Zend/zend_hash.c:1291:41 in
/root/php-7.1.7/Zend/zend_smart_str.c:44:12: runtime error: member
access within null pointer of type 'zend_string' (aka 'struct
_zend_string')
SUMMARY: AddressSanitizer: undefined-behavior
/root/php-7.1.7/Zend/zend_smart_str.c:44:12 in
/root/php-7.1.7/Zend/zend_smart_str.c:44:12: runtime error: member
access within null pointer of type 'zend_string' (aka 'struct
_zend_string')
SUMMARY: AddressSanitizer: undefined-behavior
/root/php-7.1.7/Zend/zend_smart_str.c:44:12 in
/root/php-7.1.7/Zend/zend_smart_str.c:45:28: runtime error: member
access within null pointer of type 'zend_string' (aka 'struct
_zend_string')
SUMMARY: AddressSanitizer: undefined-behavior
/root/php-7.1.7/Zend/zend_smart_str.c:45:28 in
/root/php-7.1.7/Zend/zend_smart_str.c:45:28: runtime error: member
access within null pointer of type 'zend_string' (aka 'struct
_zend_string')
SUMMARY: AddressSanitizer: undefined-behavior
/root/php-7.1.7/Zend/zend_smart_str.c:45:28 in
Caught exception!
ClosedGeneratorException: Generator yielded from aborted, no return
value available in /root/php-tmp/tmp/1.php:9
Stack trace:
#0 [internal function]: gen(Object(Generator))
#1 /root/php-tmp/tmp/1.php(23): Generator->next()
#2 {main}
/root/php-7.1.7/Zend/zend_generators.c:802:29: runtime error: member
access within null pointer of type 'zend_execute_data' (aka 'struct
_zend_execute_data')
SUMMARY: AddressSanitizer: undefined-behavior
/root/php-7.1.7/Zend/zend_generators.c:802:29 in
ASAN:DEADLYSIGNAL
=================================================================
==27573==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000030
(pc 0x00000207dcb5 bp 0x7fff3545ab10 sp 0x7fff3545a980 T0)
==27573==The signal is caused by a WRITE memory access.
==27573==Hint: address points to the zero page.
#0 0x207dcb4 in zend_generator_resume
/root/php-7.1.7/Zend/zend_generators.c
#1 0x23792d6 in ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER
/root/php-7.1.7/Zend/zend_vm_execute.h:970:4
#2 0x21a9e8a in execute_ex
/root/php-7.1.7/Zend/zend_vm_execute.h:432:7
#3 0x21ab3f7 in zend_execute
/root/php-7.1.7/Zend/zend_vm_execute.h:474:2
#4 0x1e37ccd in zend_execute_scripts
/root/php-7.1.7/Zend/zend.c:1476:4
#5 0x1aa8eb2 in php_execute_script
/root/php-7.1.7/main/main.c:2537:14
#6 0x2984423 in do_cli /root/php-7.1.7/sapi/cli/php_cli.c:993:5
#7 0x2980752 in main /root/php-7.1.7/sapi/cli/php_cli.c:1381:18
#8 0x7f3fc73b54d9 in __libc_start_main
/usr/src/debug/glibc-2.25-24-g49f97e6/csu/../csu/libc-start.c:295
#9 0x43aad9 in _start (/root/php-7.1.7/sapi/cli/php+0x43aad9)
AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV /root/php-7.1.7/Zend/zend_generators.c
in zend_generator_resume
==27573==ABORTING
--
Edit bug report at https://bugs.php.net/bug.php?id=74954&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=74954&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=74954&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=74954&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=74954&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=74954&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=74954&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=74954&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=74954&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=74954&r=support
Expected behavior: https://bugs.php.net/fix.php?id=74954&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=74954&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=74954&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=74954&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=74954&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=74954&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=74954&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=74954&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=74954&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=74954&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=74954&r=mysqlcfg