Bug #75015 [NEW]: Crash in spl_recursive_it_dtor()

From: Date: Tue, 01 Aug 2017 10:57:52 +0000
Subject: Bug #75015 [NEW]: Crash in spl_recursive_it_dtor()
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-210443@lists.php.net to get a copy of this message
From: jpauli Operating system: * PHP version: 7.1.7 Package: SPL related Bug Type: Bug Bug description:Crash in spl_recursive_it_dtor() Description: ------------ Under some circumstences, spl_recursive_it_dtor() crashes because it accessed a NULL pointer free'ed before by spl_RecursiveIteratorIterator_free_storage(). This is related to #51697 , seems very similar. 51697 is marked as closed though Test script: --------------- I could not isolate easily the behavior. But launching Symfony tests with latest PHPUnit under PHP 7.1 can trigger the crash in the Debug component of Symfony. Stack trace is then #0 0x00000000008605fe in zval_get_type (pz=0xd0) at /home/julien.pauli/workspace/php/Zend/zend_types.h:332 #1 0x00000000008610ae in spl_recursive_it_dtor (_iter=0x7fffdd787300) at /home/julien.pauli/workspace/php/ext/spl/spl_iterators.c:178 #2 0x0000000000a95a2f in iter_wrapper_free (object=0x7fffdd787300) at /home/julien.pauli/workspace/php/Zend/zend_iterators.c:69 #3 0x0000000000abef48 in zend_objects_store_free_object_storage (objects=0x14bfa78 <executor_globals+824>) at /home/julien.pauli/workspace/php/Zend/zend_objects_API.c:99 #4 0x0000000000a516d5 in shutdown_executor () at /home/julien.pauli/workspace/php/Zend/zend_execute_API.c:363 #5 0x0000000000a6b6ea in zend_deactivate () at /home/julien.pauli/workspace/php/Zend/zend.c:999 #6 0x00000000009d122b in php_request_shutdown (dummy=0x0) at /home/julien.pauli/workspace/php/main/main.c:1877 This happens because spl_RecursiveIteratorIterator_free_storage() has been called, and free'ed object->iterators but did not reset the level (object->level). Then spl_recursive_it_dtor tries to read from object->iterators (NULL). The patch is simply to reset the level while dtor'ing. Expected result: ---------------- No crash Actual result: -------------- Crash with NULL pointer dereference -- Edit bug report at https://bugs.php.net/bug.php?id=75015&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=75015&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=75015&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=75015&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=75015&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=75015&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=75015&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=75015&r=needscript Try newer version: https://bugs.php.net/fix.php?id=75015&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=75015&r=support Expected behavior: https://bugs.php.net/fix.php?id=75015&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=75015&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=75015&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=75015&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=75015&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=75015&r=dst IIS Stability: https://bugs.php.net/fix.php?id=75015&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=75015&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=75015&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=75015&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=75015&r=mysqlcfg

« previous php.bugs (#210443) next »