Bug #75128 [Opn]: Invalid write in zval_delref_p()
Edit report at https://bugs.php.net/bug.php?id=75128&edit=1
ID: 75128
Updated by: laruence@php.net
Reported by: fumfi dot 255 at gmail dot com
Summary: Invalid write in zval_delref_p()
Status: Open
Type: Bug
Package: Reproducible crash
Operating System: Ubuntu 16.04 x64
PHP Version: 7.1.8
Block user comment: N
Private report: N
New Comment:
this is an knew issue..... just don't have a good way to fix it yet
Previous Comments:
------------------------------------------------------------------------
[2017-08-28 08:52:34] fumfi dot 255 at gmail dot com
Description:
------------
After some fuzz testing I found a crashing test case.
Version: 7.18
Command: php php_iw_zval_delref_p.php
Faulting PHP script: https://frankowicz.me/storage/crashes/php_iw_zval_delref_p.txt
ASAN:
==32358==ERROR: AddressSanitizer: SEGV on unknown address 0x7ff1ff400000 (pc 0x0000017678cf bp
0x7ffc9544dc90 sp 0x7ffc9544daf0 T0)
==32358==The signal is caused by a WRITE memory access.
#0 0x17678ce in zval_delref_p XYZ/php-7.1.8/Zend/zend_types.h:838:9
#1 0x17678ce in i_zval_ptr_dtor XYZ/php-7.1.8/Zend/zend_variables.h:47
#2 0x17678ce in zend_unclean_zval_ptr_dtor XYZ/php-7.1.8/Zend/zend_execute_API.c:210
#3 0x1851027 in _zend_hash_del_el_ex XYZ/php-7.1.8/Zend/zend_hash.c:997:3
#4 0x1851027 in _zend_hash_del_el XYZ/php-7.1.8/Zend/zend_hash.c:1020
#5 0x1851027 in zend_hash_graceful_reverse_destroy XYZ/php-7.1.8/Zend/zend_hash.c:1476
#6 0x1767f89 in shutdown_executor XYZ/php-7.1.8/Zend/zend_execute_API.c:279:3
#7 0x17ce8ca in zend_deactivate XYZ/php-7.1.8/Zend/zend.c:999:2
#8 0x1564144 in php_request_shutdown XYZ/php-7.1.8/main/main.c:1877:2
#9 0x1c4215c in do_cli XYZ/php-7.1.8/sapi/cli/php_cli.c:1160:3
#10 0x1c418e5 in main XYZ/php-7.1.8/sapi/cli/php_cli.c:1381:18
#11 0x7ff20a65982f in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x2082f)
#12 0x43ac28 in _start (/usr/local/bin/php+0x43ac28)
AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV XYZ/php-7.1.8/Zend/zend_types.h:838:9 in zval_delref_p
==32358==ABORTING
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75128&edit=1
Thread (3 messages)