Bug #75015 [NEW]: Crash in spl_recursive_it_dtor()
| From: | jpauli@php.net | Date: | Tue, 01 Aug 2017 10:57:52 +0000 |
| Subject: | Bug #75015 [NEW]: Crash in spl_recursive_it_dtor() | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-210443@lists.php.net to get a copy of this message | ||
From: jpauli
Operating system: *
PHP version: 7.1.7
Package: SPL related
Bug Type: Bug
Bug description:Crash in spl_recursive_it_dtor()
Description:
------------
Under some circumstences, spl_recursive_it_dtor() crashes because it
accessed a NULL pointer free'ed before by
spl_RecursiveIteratorIterator_free_storage().
This is related to #51697 , seems very similar. 51697 is marked as
closed though
Test script:
---------------
I could not isolate easily the behavior.
But launching Symfony tests with latest PHPUnit under PHP 7.1 can
trigger the crash in the Debug component of Symfony.
Stack trace is then
#0 0x00000000008605fe in zval_get_type (pz=0xd0) at
/home/julien.pauli/workspace/php/Zend/zend_types.h:332
#1 0x00000000008610ae in spl_recursive_it_dtor (_iter=0x7fffdd787300)
at /home/julien.pauli/workspace/php/ext/spl/spl_iterators.c:178
#2 0x0000000000a95a2f in iter_wrapper_free (object=0x7fffdd787300) at
/home/julien.pauli/workspace/php/Zend/zend_iterators.c:69
#3 0x0000000000abef48 in zend_objects_store_free_object_storage
(objects=0x14bfa78 <executor_globals+824>) at
/home/julien.pauli/workspace/php/Zend/zend_objects_API.c:99
#4 0x0000000000a516d5 in shutdown_executor () at
/home/julien.pauli/workspace/php/Zend/zend_execute_API.c:363
#5 0x0000000000a6b6ea in zend_deactivate () at
/home/julien.pauli/workspace/php/Zend/zend.c:999
#6 0x00000000009d122b in php_request_shutdown (dummy=0x0) at
/home/julien.pauli/workspace/php/main/main.c:1877
This happens because spl_RecursiveIteratorIterator_free_storage() has
been called, and free'ed object->iterators but did not reset the level
(object->level). Then spl_recursive_it_dtor tries to read from
object->iterators (NULL).
The patch is simply to reset the level while dtor'ing.
Expected result:
----------------
No crash
Actual result:
--------------
Crash with NULL pointer dereference
--
Edit bug report at https://bugs.php.net/bug.php?id=75015&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=75015&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=75015&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=75015&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=75015&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=75015&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=75015&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=75015&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=75015&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=75015&r=support
Expected behavior: https://bugs.php.net/fix.php?id=75015&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=75015&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=75015&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=75015&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=75015&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=75015&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=75015&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=75015&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=75015&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=75015&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=75015&r=mysqlcfg