Bug #75128 [Opn]: Invalid write in zval_delref_p()

From: Date: Sat, 02 Sep 2017 03:56:21 +0000
Subject: Bug #75128 [Opn]: Invalid write in zval_delref_p()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-210914@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75128&edit=1

 ID:                 75128
 Updated by:         laruence@php.net
 Reported by:        fumfi dot 255 at gmail dot com
 Summary:            Invalid write in zval_delref_p()
 Status:             Open
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   Ubuntu 16.04 x64
 PHP Version:        7.1.8
 Block user comment: N
 Private report:     N

 New Comment:

this is an knew issue..... just don't have a good way to fix it yet


Previous Comments:
------------------------------------------------------------------------
[2017-08-28 08:52:34] fumfi dot 255 at gmail dot com

Description:
------------
After some fuzz testing I found a crashing test case.

Version: 7.18

Command: php php_iw_zval_delref_p.php

Faulting PHP script: https://frankowicz.me/storage/crashes/php_iw_zval_delref_p.txt

ASAN:

==32358==ERROR: AddressSanitizer: SEGV on unknown address 0x7ff1ff400000 (pc 0x0000017678cf bp
0x7ffc9544dc90 sp 0x7ffc9544daf0 T0)
==32358==The signal is caused by a WRITE memory access.
    #0 0x17678ce in zval_delref_p XYZ/php-7.1.8/Zend/zend_types.h:838:9
    #1 0x17678ce in i_zval_ptr_dtor XYZ/php-7.1.8/Zend/zend_variables.h:47
    #2 0x17678ce in zend_unclean_zval_ptr_dtor XYZ/php-7.1.8/Zend/zend_execute_API.c:210
    #3 0x1851027 in _zend_hash_del_el_ex XYZ/php-7.1.8/Zend/zend_hash.c:997:3
    #4 0x1851027 in _zend_hash_del_el XYZ/php-7.1.8/Zend/zend_hash.c:1020
    #5 0x1851027 in zend_hash_graceful_reverse_destroy XYZ/php-7.1.8/Zend/zend_hash.c:1476
    #6 0x1767f89 in shutdown_executor XYZ/php-7.1.8/Zend/zend_execute_API.c:279:3
    #7 0x17ce8ca in zend_deactivate XYZ/php-7.1.8/Zend/zend.c:999:2
    #8 0x1564144 in php_request_shutdown XYZ/php-7.1.8/main/main.c:1877:2
    #9 0x1c4215c in do_cli XYZ/php-7.1.8/sapi/cli/php_cli.c:1160:3
    #10 0x1c418e5 in main XYZ/php-7.1.8/sapi/cli/php_cli.c:1381:18
    #11 0x7ff20a65982f in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x2082f)
    #12 0x43ac28 in _start (/usr/local/bin/php+0x43ac28)

AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV XYZ/php-7.1.8/Zend/zend_types.h:838:9 in zval_delref_p
==32358==ABORTING



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=75128&edit=1


Thread (3 messages)

« previous php.bugs (#210914) next »