Bug #72413 [Ver->Asn]: mysqlnd segfault (fetch_row second parameter typemismatch)

From: Date: Tue, 24 Oct 2017 05:17:52 +0000
Subject: Bug #72413 [Ver->Asn]: mysqlnd segfault (fetch_row second parameter typemismatch)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-211925@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72413&edit=1

 ID:                 72413
 Updated by:         kalle@php.net
 Reported by:        martin dot koegler at brz dot gv dot at
 Summary:            mysqlnd segfault (fetch_row second parameter
                     typemismatch)
-Status:             Verified
+Status:             Assigned
 Type:               Bug
 Package:            *General Issues
 Operating System:   Linux
 PHP Version:        5.6.22
 Assigned To:        mysql
 Block user comment: N
 Private report:     N



Previous Comments:
------------------------------------------------------------------------
[2016-06-15 14:47:49] martin dot koegler at brz dot gv dot at

Description:
------------
If the MYSQLI_CURSOR_TYPE_READ_ONLY option is active on a mysqli statement,
mysqlnd_fetch_stmt_row_cursor is selected as row fetch method.

mysqlnd_fetch_stmt_row_cursor expects a MYSQLND_STMT passed as "param" parameter. 
mysqlnd_res::fetch_into passes a zval as this parameter, which yields to a crash.

Test script:
---------------
<?php
$link1=mysqli_connect(....);
$SQL="SELECT 1";
$stmt=$link1->prepare($SQL);
$stmt->attr_set(MYSQLI_STMT_ATTR_CURSOR_TYPE, MYSQLI_CURSOR_TYPE_READ_ONLY);
$stmt->execute();
$res = $stmt->get_result();
while($res->fetch_row());
?>


Expected result:
----------------
No segfault

Actual result:
--------------
Segfault in
1022                    SET_CLIENT_ERROR(*stmt->conn->error_info, CR_COMMANDS_OUT_OF_SYNC,
UNKNOWN_SQLSTATE,

mysqlnd_fetch_stmt_row_cursor at ext/mysqlnd/mysqlnd_ps.c:1022
php_mysqlnd_res_fetch_into_pub at ext/mysqlnd/mysqlnd_result.c:1823


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=72413&edit=1


Thread (1 message)

  • kalle@php.net
  • Unknown Message
    • kalle@php.net
« previous php.bugs (#211925) next »