Bug #75393 [Opn]: Crash when assign-adding an array to an object
| From: | laruence@php.net | Date: | Tue, 17 Oct 2017 03:49:13 +0000 |
| Subject: | Bug #75393 [Opn]: Crash when assign-adding an array to an object | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-211742@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75393&edit=1
ID: 75393
Updated by: laruence@php.net
Reported by: bwoebi@php.net
Summary: Crash when assign-adding an array to an object
Status: Open
Type: Bug
Package: Reproducible crash
Operating System: Irrelevant
PHP Version: 7.0Git-2017-10-16 (Git)
Block user comment: N
Private report: N
New Comment:
I can not reproduce this....
Previous Comments:
------------------------------------------------------------------------
[2017-10-17 01:42:20] bwoebi@php.net
Related To: Bug #75393
------------------------------------------------------------------------
[2017-10-17 01:42:19] bwoebi@php.net
Unassigning myself, there's a deeper rabbit hole than expected. The fix I attempted for the
attached test to give the expected result is causing memory leaks in other tests.
Also, related issue: $rsrc += 1; leaks the resource.
--TEST--
Bug #75393 (Crash when assign-adding an array to an object)
--FILE--
<?php
try {
$o = new stdClass;
$o += [];
} catch (\Error $e) {
var_dump($e->getMessage(), $o);
}
?>
--EXPECTF--
Notice: Object of class stdClass could not be converted to int in %s on line %d
string(25) "Unsupported operand types"
object(stdClass)#1 (0) {
}
------------------------------------------------------------------------
[2017-10-17 00:21:00] bwoebi@php.net
Description:
------------
Assign-adding an array to an object leads to an use-after-free.
Test script:
---------------
$o = new stdClass;
$o += [];
Expected result:
----------------
Notice: Object of class stdClass could not be converted to int in - on line 1
Fatal error: Uncaught Error: Unsupported operand types in -:1
Stack trace:
#0 {main}
thrown in - on line 1
Actual result:
--------------
Invalid read
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75393&edit=1