Bug #74977 [NEW]: Recursion leads to crash

From: Date: Mon, 24 Jul 2017 09:45:58 +0000
Subject: Bug #74977 [NEW]: Recursion leads to crash
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-210261@lists.php.net to get a copy of this message
From: zhihua dot yao at dbappsecurity dot com dot cn Operating system: all PHP version: 7.1.7 Package: SPL related Bug Type: Bug Bug description: Recursion leads to crash Description: ------------ This iterator causes a crash due to recursion. Test script: --------------- <?php $iterator = new AppendIterator(array("A","A","A")); $iterator->append($iterator); ?> Expected result: ---------------- ho crash Actual result: -------------- gdb-peda$ r Starting program: /home/hjy/Desktop/php-7.1.7/sapi/cli/php -n poc.php [Thread debugging using libthread_db enabled] Using host libthread_db library "/lib/i386-linux-gnu/libthread_db.so.1". Program received signal SIGSEGV, Segmentation fault. [----------------------------------registers-----------------------------------] EAX: 0x8d1bfe8 --> 0x1 EBX: 0x0 ECX: 0xb6e6d2b8 --> 0x6 EDX: 0x8d1bdc0 --> 0x1 ESI: 0xb6e14020 --> 0xb6e5e3a8 --> 0x854992f (<ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER>: push ebp) EDI: 0xb6e5e3a8 --> 0x854992f (<ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER>: push ebp) EBP: 0xbf800018 ESP: 0xbf7fffe0 EIP: 0x84e098b (<zend_vm_stack_push_call_frame+9>: mov DWORD PTR [esp+0x4],eax) EFLAGS: 0x210282 (carry parity adjust zero SIGN trap INTERRUPT direction overflow) [-------------------------------------code-------------------------------------] 0x84e0983 <zend_vm_stack_push_call_frame+1>: mov ebp,esp 0x84e0985 <zend_vm_stack_push_call_frame+3>: sub esp,0x38 0x84e0988 <zend_vm_stack_push_call_frame+6>: mov eax,DWORD PTR [ebp+0xc] => 0x84e098b <zend_vm_stack_push_call_frame+9>: mov DWORD PTR [esp+0x4],eax 0x84e098f <zend_vm_stack_push_call_frame+13>: mov eax,DWORD PTR [ebp+0x10] 0x84e0992 <zend_vm_stack_push_call_frame+16>: mov DWORD PTR [esp],eax 0x84e0995 <zend_vm_stack_push_call_frame+19>: call 0x84e092d <zend_vm_calc_used_stack> 0x84e099a <zend_vm_stack_push_call_frame+24>: mov DWORD PTR [ebp-0xc],eax [------------------------------------stack-------------------------------------] Invalid $SP address: 0xbf7fffe0 [------------------------------------------------------------------------------] Legend: code, data, rodata, value Stopped reason: SIGSEGV 0x084e098b in zend_vm_stack_push_call_frame (call_info=0x202, func=0x8d1bfe8, num_args=0x0, called_scope=0x8d1bdc0, object=0xb6e6d2b8) at /home/hjy/Desktop/php-7.1.7/Zend/zend_execute.h:209 209 uint32_t used_stack = zend_vm_calc_used_stack(num_args, func); -- Edit bug report at https://bugs.php.net/bug.php?id=74977&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=74977&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=74977&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=74977&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=74977&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=74977&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=74977&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=74977&r=needscript Try newer version: https://bugs.php.net/fix.php?id=74977&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=74977&r=support Expected behavior: https://bugs.php.net/fix.php?id=74977&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=74977&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=74977&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=74977&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=74977&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=74977&r=dst IIS Stability: https://bugs.php.net/fix.php?id=74977&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=74977&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=74977&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=74977&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=74977&r=mysqlcfg

« previous php.bugs (#210261) next »