Bug #74960 [Opn]: SIGSEV in concat_function

From: Date: Fri, 21 Jul 2017 04:59:04 +0000
Subject: Bug #74960 [Opn]: SIGSEV in concat_function
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-210158@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74960&edit=1

 ID:                 74960
 User updated by:    zhihua dot yao at dbappsecurity dot com dot cn
 Reported by:        zhihua dot yao at dbappsecurity dot com dot cn
 Summary:            SIGSEV in concat_function
 Status:             Open
 Type:               Bug
 Package:            Reproducible crash
 PHP Version:        7.1.7
 Block user comment: N
 Private report:     N

 New Comment:

Program received signal SIGSEGV, Segmentation fault.

[----------------------------------registers-----------------------------------]
EAX: 0xb6e5f981 --> 0x0 
EBX: 0xb7a8b000 --> 0x1aada8 
ECX: 0x7ffffff6 
EDX: 0x36e5f980 
ESI: 0x36e5f977 
EDI: 0xb6e5f981 --> 0x0 
EBP: 0xbfffbae8 --> 0xbfffbb38 --> 0xbfffbb48 --> 0xbfffbb68 --> 0xbfffbba8 -->
0xbfffbbd8 (--> ...)
ESP: 0xbfffba60 --> 0xb6e14020 --> 0xb6e7c0fc --> 0x859b7ab
(<ZEND_ASSIGN_CONCAT_SPEC_CV_CV_HANDLER>:	push   ebp)
EIP: 0xb7a14f84 (<__memcpy_ssse3_rep+3380>:	movdqu XMMWORD PTR [esi],xmm0)
EFLAGS: 0x210206 (carry PARITY adjust zero sign trap INTERRUPT direction overflow)
[-------------------------------------code-------------------------------------]
   0xb7a14f77 <__memcpy_ssse3_rep+3367>:	mov    esi,esi
   0xb7a14f79 <__memcpy_ssse3_rep+3369>:	lea    edi,[edi+eiz*1+0x0]
   0xb7a14f80 <__memcpy_ssse3_rep+3376>:	movdqu xmm1,XMMWORD PTR [eax]
=> 0xb7a14f84 <__memcpy_ssse3_rep+3380>:	movdqu XMMWORD PTR [esi],xmm0
   0xb7a14f88 <__memcpy_ssse3_rep+3384>:	movntdq XMMWORD PTR [edx],xmm1
   0xb7a14f8c <__memcpy_ssse3_rep+3388>:	add    eax,0x10
   0xb7a14f8f <__memcpy_ssse3_rep+3391>:	add    edx,0x10
   0xb7a14f92 <__memcpy_ssse3_rep+3394>:	sub    ecx,0x10
[------------------------------------stack-------------------------------------]
0000| 0xbfffba60 --> 0xb6e14020 --> 0xb6e7c0fc --> 0x859b7ab
(<ZEND_ASSIGN_CONCAT_SPEC_CV_CV_HANDLER>:	push   ebp)
0004| 0xbfffba64 --> 0xb6e7c0fc --> 0x859b7ab
(<ZEND_ASSIGN_CONCAT_SPEC_CV_CV_HANDLER>:	push   ebp)
0008| 0xbfffba68 --> 0x84efff0 (<concat_function>:	push   ebp)
0012| 0xbfffba6c --> 0x84f055d (<concat_function+1389>:	mov    edx,DWORD PTR [ebp-0x4c])
0016| 0xbfffba70 --> 0x36e5f977 
0020| 0xbfffba74 --> 0xb6e5f978 --> 0x0 
0024| 0xbfffba78 --> 0x7fffffff 
0028| 0xbfffba7c --> 0x83a5df6 (<zend_string_safe_alloc+153>:	mov    eax,DWORD PTR
[ebp+0x8])
[------------------------------------------------------------------------------]
Legend: code, data, rodata, value
Stopped reason: SIGSEGV
__memcpy_ssse3_rep () at ../sysdeps/i386/i686/multiarch/memcpy-ssse3-rep.S:1269
1269	../sysdeps/i386/i686/multiarch/memcpy-ssse3-rep.S: No such file or directory.
gdb-peda$ bt
#0  __memcpy_ssse3_rep ()
    at ../sysdeps/i386/i686/multiarch/memcpy-ssse3-rep.S:1269
#1  0x084f055d in concat_function (result=0xb6e14050, op1=0xb6e14050, 
    op2=0xb6e14050) at /home/hjy/Desktop/php-7.1.7/Zend/zend_operators.c:1773
#2  0x0859b599 in zend_binary_assign_op_helper_SPEC_CV_CV (
    binary_op=0x84efff0 <concat_function>)
    at /home/hjy/Desktop/php-7.1.7/Zend/zend_vm_execute.h:44196
#3  0x0859b7bb in ZEND_ASSIGN_CONCAT_SPEC_CV_CV_HANDLER ()
    at /home/hjy/Desktop/php-7.1.7/Zend/zend_vm_execute.h:44613
#4  0x08548973 in execute_ex (ex=0xb6e14020)
    at /home/hjy/Desktop/php-7.1.7/Zend/zend_vm_execute.h:429
#5  0x08548a36 in zend_execute (op_array=0xb6e6c1e0, return_value=0x0)
    at /home/hjy/Desktop/php-7.1.7/Zend/zend_vm_execute.h:474
#6  0x084f74a1 in zend_execute_scripts (type=0x8, retval=0x0, file_count=0x3)
    at /home/hjy/Desktop/php-7.1.7/Zend/zend.c:1476
#7  0x08479d1f in php_execute_script (primary_file=0xbfffdeb4)
    at /home/hjy/Desktop/php-7.1.7/main/main.c:2537
#8  0x085b9dbe in do_cli (argc=0x3, argv=0x8c4d068)
    at /home/hjy/Desktop/php-7.1.7/sapi/cli/php_cli.c:993
#9  0x085bac75 in main (argc=0x3, argv=0x8c4d068)
    at /home/hjy/Desktop/php-7.1.7/sapi/cli/php_cli.c:1381
#10 0xb78f9a83 in __libc_start_main (main=0x85ba68d <main>, argc=0x3, 
    argv=0xbffff154, init=0x85c3cd0 <__libc_csu_init>, 
    fini=0x85c3d40 <__libc_csu_fini>, rtld_fini=0xb7fed180 <_dl_fini>, 
    stack_end=0xbffff14c) at libc-start.c:287
#11 0x08070f21 in _start ()


Previous Comments:
------------------------------------------------------------------------
[2017-07-21 04:41:46] zhihua dot yao at dbappsecurity dot com dot cn

Description:
------------
I have tested on Ubuntu x86.

Test script:
---------------
<?php
ini_set("memory_limit",-1);
$str=str_repeat("A",0x7fffffff);

$str.=$str;
    
?>


Expected result:
----------------
no crash

Actual result:
--------------
<?php
ini_set("memory_limit",-1);
$str=str_repeat("A",0x7fffffff);

$str.=$str;
    
?>



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=74960&edit=1


Thread (7 messages)

« previous php.bugs (#210158) next »