Edit report at https://bugs.php.net/bug.php?id=74960&edit=1
ID: 74960
User updated by: zhihua dot yao at dbappsecurity dot com dot cn
Reported by: zhihua dot yao at dbappsecurity dot com dot cn
Summary: SIGSEV in concat_function
Status: Open
Type: Bug
Package: Reproducible crash
PHP Version: 7.1.7
Block user comment: N
Private report: N
New Comment:
Program received signal SIGSEGV, Segmentation fault.
[----------------------------------registers-----------------------------------]
EAX: 0xb6e5f981 --> 0x0
EBX: 0xb7a8b000 --> 0x1aada8
ECX: 0x7ffffff6
EDX: 0x36e5f980
ESI: 0x36e5f977
EDI: 0xb6e5f981 --> 0x0
EBP: 0xbfffbae8 --> 0xbfffbb38 --> 0xbfffbb48 --> 0xbfffbb68 --> 0xbfffbba8 -->
0xbfffbbd8 (--> ...)
ESP: 0xbfffba60 --> 0xb6e14020 --> 0xb6e7c0fc --> 0x859b7ab
(<ZEND_ASSIGN_CONCAT_SPEC_CV_CV_HANDLER>: push ebp)
EIP: 0xb7a14f84 (<__memcpy_ssse3_rep+3380>: movdqu XMMWORD PTR [esi],xmm0)
EFLAGS: 0x210206 (carry PARITY adjust zero sign trap INTERRUPT direction overflow)
[-------------------------------------code-------------------------------------]
0xb7a14f77 <__memcpy_ssse3_rep+3367>: mov esi,esi
0xb7a14f79 <__memcpy_ssse3_rep+3369>: lea edi,[edi+eiz*1+0x0]
0xb7a14f80 <__memcpy_ssse3_rep+3376>: movdqu xmm1,XMMWORD PTR [eax]
=> 0xb7a14f84 <__memcpy_ssse3_rep+3380>: movdqu XMMWORD PTR [esi],xmm0
0xb7a14f88 <__memcpy_ssse3_rep+3384>: movntdq XMMWORD PTR [edx],xmm1
0xb7a14f8c <__memcpy_ssse3_rep+3388>: add eax,0x10
0xb7a14f8f <__memcpy_ssse3_rep+3391>: add edx,0x10
0xb7a14f92 <__memcpy_ssse3_rep+3394>: sub ecx,0x10
[------------------------------------stack-------------------------------------]
0000| 0xbfffba60 --> 0xb6e14020 --> 0xb6e7c0fc --> 0x859b7ab
(<ZEND_ASSIGN_CONCAT_SPEC_CV_CV_HANDLER>: push ebp)
0004| 0xbfffba64 --> 0xb6e7c0fc --> 0x859b7ab
(<ZEND_ASSIGN_CONCAT_SPEC_CV_CV_HANDLER>: push ebp)
0008| 0xbfffba68 --> 0x84efff0 (<concat_function>: push ebp)
0012| 0xbfffba6c --> 0x84f055d (<concat_function+1389>: mov edx,DWORD PTR [ebp-0x4c])
0016| 0xbfffba70 --> 0x36e5f977
0020| 0xbfffba74 --> 0xb6e5f978 --> 0x0
0024| 0xbfffba78 --> 0x7fffffff
0028| 0xbfffba7c --> 0x83a5df6 (<zend_string_safe_alloc+153>: mov eax,DWORD PTR
[ebp+0x8])
[------------------------------------------------------------------------------]
Legend: code, data, rodata, value
Stopped reason: SIGSEGV
__memcpy_ssse3_rep () at ../sysdeps/i386/i686/multiarch/memcpy-ssse3-rep.S:1269
1269 ../sysdeps/i386/i686/multiarch/memcpy-ssse3-rep.S: No such file or directory.
gdb-peda$ bt
#0 __memcpy_ssse3_rep ()
at ../sysdeps/i386/i686/multiarch/memcpy-ssse3-rep.S:1269
#1 0x084f055d in concat_function (result=0xb6e14050, op1=0xb6e14050,
op2=0xb6e14050) at /home/hjy/Desktop/php-7.1.7/Zend/zend_operators.c:1773
#2 0x0859b599 in zend_binary_assign_op_helper_SPEC_CV_CV (
binary_op=0x84efff0 <concat_function>)
at /home/hjy/Desktop/php-7.1.7/Zend/zend_vm_execute.h:44196
#3 0x0859b7bb in ZEND_ASSIGN_CONCAT_SPEC_CV_CV_HANDLER ()
at /home/hjy/Desktop/php-7.1.7/Zend/zend_vm_execute.h:44613
#4 0x08548973 in execute_ex (ex=0xb6e14020)
at /home/hjy/Desktop/php-7.1.7/Zend/zend_vm_execute.h:429
#5 0x08548a36 in zend_execute (op_array=0xb6e6c1e0, return_value=0x0)
at /home/hjy/Desktop/php-7.1.7/Zend/zend_vm_execute.h:474
#6 0x084f74a1 in zend_execute_scripts (type=0x8, retval=0x0, file_count=0x3)
at /home/hjy/Desktop/php-7.1.7/Zend/zend.c:1476
#7 0x08479d1f in php_execute_script (primary_file=0xbfffdeb4)
at /home/hjy/Desktop/php-7.1.7/main/main.c:2537
#8 0x085b9dbe in do_cli (argc=0x3, argv=0x8c4d068)
at /home/hjy/Desktop/php-7.1.7/sapi/cli/php_cli.c:993
#9 0x085bac75 in main (argc=0x3, argv=0x8c4d068)
at /home/hjy/Desktop/php-7.1.7/sapi/cli/php_cli.c:1381
#10 0xb78f9a83 in __libc_start_main (main=0x85ba68d <main>, argc=0x3,
argv=0xbffff154, init=0x85c3cd0 <__libc_csu_init>,
fini=0x85c3d40 <__libc_csu_fini>, rtld_fini=0xb7fed180 <_dl_fini>,
stack_end=0xbffff14c) at libc-start.c:287
#11 0x08070f21 in _start ()
Previous Comments:
------------------------------------------------------------------------
[2017-07-21 04:41:46] zhihua dot yao at dbappsecurity dot com dot cn
Description:
------------
I have tested on Ubuntu x86.
Test script:
---------------
<?php
ini_set("memory_limit",-1);
$str=str_repeat("A",0x7fffffff);
$str.=$str;
?>
Expected result:
----------------
no crash
Actual result:
--------------
<?php
ini_set("memory_limit",-1);
$str=str_repeat("A",0x7fffffff);
$str.=$str;
?>
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74960&edit=1