Bug #75237 [Opn->Dup]: jsonSerialize() - Returning new instance of self causes segfault
| From: | nikic@php.net | Date: | Thu, 05 Oct 2017 10:48:58 +0000 |
| Subject: | Bug #75237 [Opn->Dup]: jsonSerialize() - Returning new instance of self causes segfault | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-211523@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75237&edit=1
ID: 75237
Updated by: nikic@php.net
Reported by: sammyk@php.net
Summary: jsonSerialize() - Returning new instance of self
causes segfault
-Status: Open
+Status: Duplicate
Type: Bug
Package: JSON related
Operating System: macOS 10.12.6
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
This is a standard infinite recursion stack overflow -- I'm marking it as a duplicate of
#64196, which is about __clone(), but the same general issue.
Previous Comments:
------------------------------------------------------------------------
[2017-09-20 21:39:14] sammyk@php.net
Description:
------------
You can easily create a segfault in jsonSerialize() by returning a new instance of self. You can see
this affects all actively supported versions of PHP here: https://3v4l.org/tLMv6
I'm working on a patch and will be submitting it as a PR soon. :)
Test script:
---------------
<?php
class Foo implements JsonSerializable {
public function jsonSerialize() {
return new self;
}
}
var_dump(json_encode(new Foo));
Expected result:
----------------
We'd should see a fatal error raised on an exception thrown.
Actual result:
--------------
Segmentation fault. Doh!
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75237&edit=1