Bug #74954 [NEW]: null deref and segfault in zend_generator_resume()

From: Date: Wed, 19 Jul 2017 19:58:00 +0000
Subject: Bug #74954 [NEW]: null deref and segfault in zend_generator_resume()
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-210143@lists.php.net to get a copy of this message
From: geeknik at protonmail dot ch Operating system: Fedora 26 x64 PHP version: 7.1.7 Package: Reproducible crash Bug Type: Bug Bug description:null deref and segfault in zend_generator_resume() Description: ------------ Compiled with afl-clang-fast on Fedora 26 x64. While fuzzing with AFL this null deref triggered a segfault. Test script: --------------- <?php function from() { yield 1; throw new Exception(); } function gen($gen) { try { var_dump(yield from $gen); } catch (Exception $e) { print "Caught exception!\n$e\n"; } } $gen = from(); $gens[] = gen($gen); $gens[] = gen($gen); foreach ($gens as $g) { $g->current(); } do { foreach ($gens as $i => $g) { $g->next(); } } while($gens[0]->valid()); ?> Expected result: ---------------- No crash. Actual result: -------------- Caught exception! Exception in /root/php-tmp/tmp/1.php:4 Stack trace: #0 /root/php-tmp/tmp/1.php(9): from() #1 [internal function]: gen(Object(Generator)) #2 /root/php-tmp/tmp/1.php(23): Generator->next() #3 {main} /root/php-7.1.7/Zend/zend_hash.c:1291:41: runtime error: left shift of 32768 by 16 places cannot be represented in type 'int' SUMMARY: AddressSanitizer: undefined-behavior /root/php-7.1.7/Zend/zend_hash.c:1291:41 in /root/php-7.1.7/Zend/zend_smart_str.c:44:12: runtime error: member access within null pointer of type 'zend_string' (aka 'struct _zend_string') SUMMARY: AddressSanitizer: undefined-behavior /root/php-7.1.7/Zend/zend_smart_str.c:44:12 in /root/php-7.1.7/Zend/zend_smart_str.c:44:12: runtime error: member access within null pointer of type 'zend_string' (aka 'struct _zend_string') SUMMARY: AddressSanitizer: undefined-behavior /root/php-7.1.7/Zend/zend_smart_str.c:44:12 in /root/php-7.1.7/Zend/zend_smart_str.c:45:28: runtime error: member access within null pointer of type 'zend_string' (aka 'struct _zend_string') SUMMARY: AddressSanitizer: undefined-behavior /root/php-7.1.7/Zend/zend_smart_str.c:45:28 in /root/php-7.1.7/Zend/zend_smart_str.c:45:28: runtime error: member access within null pointer of type 'zend_string' (aka 'struct _zend_string') SUMMARY: AddressSanitizer: undefined-behavior /root/php-7.1.7/Zend/zend_smart_str.c:45:28 in Caught exception! ClosedGeneratorException: Generator yielded from aborted, no return value available in /root/php-tmp/tmp/1.php:9 Stack trace: #0 [internal function]: gen(Object(Generator)) #1 /root/php-tmp/tmp/1.php(23): Generator->next() #2 {main} /root/php-7.1.7/Zend/zend_generators.c:802:29: runtime error: member access within null pointer of type 'zend_execute_data' (aka 'struct _zend_execute_data') SUMMARY: AddressSanitizer: undefined-behavior /root/php-7.1.7/Zend/zend_generators.c:802:29 in ASAN:DEADLYSIGNAL ================================================================= ==27573==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000030 (pc 0x00000207dcb5 bp 0x7fff3545ab10 sp 0x7fff3545a980 T0) ==27573==The signal is caused by a WRITE memory access. ==27573==Hint: address points to the zero page. #0 0x207dcb4 in zend_generator_resume /root/php-7.1.7/Zend/zend_generators.c #1 0x23792d6 in ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER /root/php-7.1.7/Zend/zend_vm_execute.h:970:4 #2 0x21a9e8a in execute_ex /root/php-7.1.7/Zend/zend_vm_execute.h:432:7 #3 0x21ab3f7 in zend_execute /root/php-7.1.7/Zend/zend_vm_execute.h:474:2 #4 0x1e37ccd in zend_execute_scripts /root/php-7.1.7/Zend/zend.c:1476:4 #5 0x1aa8eb2 in php_execute_script /root/php-7.1.7/main/main.c:2537:14 #6 0x2984423 in do_cli /root/php-7.1.7/sapi/cli/php_cli.c:993:5 #7 0x2980752 in main /root/php-7.1.7/sapi/cli/php_cli.c:1381:18 #8 0x7f3fc73b54d9 in __libc_start_main /usr/src/debug/glibc-2.25-24-g49f97e6/csu/../csu/libc-start.c:295 #9 0x43aad9 in _start (/root/php-7.1.7/sapi/cli/php+0x43aad9) AddressSanitizer can not provide additional info. SUMMARY: AddressSanitizer: SEGV /root/php-7.1.7/Zend/zend_generators.c in zend_generator_resume ==27573==ABORTING -- Edit bug report at https://bugs.php.net/bug.php?id=74954&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=74954&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=74954&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=74954&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=74954&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=74954&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=74954&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=74954&r=needscript Try newer version: https://bugs.php.net/fix.php?id=74954&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=74954&r=support Expected behavior: https://bugs.php.net/fix.php?id=74954&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=74954&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=74954&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=74954&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=74954&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=74954&r=dst IIS Stability: https://bugs.php.net/fix.php?id=74954&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=74954&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=74954&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=74954&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=74954&r=mysqlcfg

« previous php.bugs (#210143) next »