Bug #75573 [NEW]: Segmentation fault in 7.1.12 and 7.0.26
| From: | manuel-php at mausz dot at | Date: | Sun, 26 Nov 2017 15:48:46 +0000 |
| Subject: | Bug #75573 [NEW]: Segmentation fault in 7.1.12 and 7.0.26 | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-212723@lists.php.net to get a copy of this message | ||
From: manuel-php at mausz dot at
Operating system: Linux
PHP version: 7.1.12
Package: Reproducible crash
Bug Type: Bug
Bug description:Segmentation fault in 7.1.12 and 7.0.26
Description:
------------
After updating to 7.1.12 and 7.0.26 we noticed an increased rate in
crashes across all our webservers. The crashes are somehow triggered by
"NextGEN Gallery" and reverting
https://github.com/php/php-src/commit/bc59289b7a25219ea2179554dc26c88e533250a5
+
https://github.com/php/php-src/commit/98eee90734c4fabf3f3a3d4168576cb6b25ad9b1
fixed it.
Backtrace:
#0 zend_mm_alloc_small (bin_num=<optimized out>, size=<optimized out>,
heap=0x7fe70d600040) at /tmp/php-7.0.26/fpm/Zend/zend_alloc.c:1318
#1 zend_mm_alloc_heap (size=<optimized out>, heap=0x7fe70d600040) at
/tmp/php-7.0.26/fpm/Zend/zend_alloc.c:1389
#2 _emalloc (size=<optimized out>) at
/tmp/php-7.0.26/fpm/Zend/zend_alloc.c:2477
#3 0x00000000007bf579 in zend_hash_real_init_ex (packed=<optimized
out>, ht=0x7fe70b0ccd20) at /tmp/php-7.0.26/fpm/Zend/zend_hash.c:135
#4 zend_hash_check_init (packed=<optimized out>, ht=0x7fe70b0ccd20) at
/tmp/php-7.0.26/fpm/Zend/zend_hash.c:163
#5 _zend_hash_index_add_or_update_i (flag=10, pData=0x10cb840
<executor_globals>, h=0, ht=0x7fe70b0ccd20) at
/tmp/php-7.0.26/fpm/Zend/zend_hash.c:729
#6 _zend_hash_index_add_new (ht=ht@entry=0x7fe70b0ccd20, h=0,
pData=pData@entry=0x10cb840 <executor_globals>) at
/tmp/php-7.0.26/fpm/Zend/zend_hash.c:853
#7 0x000000000081c8f8 in zend_fetch_dimension_address_inner (type=1,
dim_type=16, dim=<optimized out>, ht=<optimized out>) at
/tmp/php-7.0.26/fpm/Zend/zend_execute.c:1572
#8 ZEND_ASSIGN_DIM_SPEC_VAR_CV_HANDLER () at
/tmp/php-7.0.26/fpm/Zend/zend_vm_execute.h:20864
#9 0x00000000007eddf8 in execute_ex (ex=<optimized out>) at
/tmp/php-7.0.26/fpm/Zend/zend_vm_execute.h:414
#10 0x00000000007a3285 in zend_call_function
(fci=fci@entry=0x7ffe0e1640e0, fci_cache=0x7fe70d6d6da0,
fci_cache@entry=0x0) at /tmp/php-7.0.26/fpm/Zend/zend_execute_API.c:867
#11 0x00000000007a3698 in call_user_function_ex
(function_table=<optimized out>, object=object@entry=0x0,
function_name=<optimized out>,
retval_ptr=retval_ptr@entry=0x7ffe0e164170, param_count=<optimized out>,
params=<optimized out>,
no_separation=no_separation@entry=1,
symbol_table=symbol_table@entry=0x0) at
/tmp/php-7.0.26/fpm/Zend/zend_execute_API.c:675
#12 0x00000000007a36d0 in call_user_function (function_table=<optimized
out>, object=object@entry=0x0, function_name=<optimized out>,
retval_ptr=retval_ptr@entry=0x7ffe0e164170, param_count=<optimized out>,
params=<optimized out>)
at /tmp/php-7.0.26/fpm/Zend/zend_execute_API.c:657
#13 0x00000000006ab7b2 in user_shutdown_function_call (zv=<optimized
out>) at /tmp/php-7.0.26/fpm/ext/standard/basic_functions.c:4934
#14 0x00000000007c1f6d in zend_hash_apply (ht=0x7fe70d79a3b8,
apply_func=apply_func@entry=0x6ab6dd <user_shutdown_function_call>) at
/tmp/php-7.0.26/fpm/Zend/zend_hash.c:1537
#15 0x00000000006ae9ad in php_call_shutdown_functions () at
/tmp/php-7.0.26/fpm/ext/standard/basic_functions.c:5018
#16 0x0000000000754595 in php_request_shutdown (dummy=dummy@entry=0x0)
at /tmp/php-7.0.26/fpm/main/main.c:1804
#17 0x000000000048e07a in main (argc=<optimized out>, argv=<optimized
out>) at /tmp/php-7.0.26/fpm/sapi/fpm/fpm/fpm_main.c:2066
PHP backtrace from core dump:
(gdb) dump_bt executor_globals.current_execute_data
[0x7fe70d618740] WP_Hook->apply_filters("", array(1)[0x7fe70d6187b0])
/path/to/wp-includes/class-wp-hook.php:271
[0x7fe70d618680] WP_Hook->do_action(array(1)[0x7fe70d6186e0])
/path/to/wp-includes/class-wp-hook.php:310
[0x7fe70d618330] do_action("shutdown")
/path/to/wp-includes/plugin.php:453
[0x7fe70d6182b0] shutdown_action_hook()
/path/to/wp-includes/load.php:679
[0x7ffe0e164040] ???
--
Edit bug report at https://bugs.php.net/bug.php?id=75573&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=75573&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=75573&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=75573&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=75573&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=75573&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=75573&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=75573&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=75573&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=75573&r=support
Expected behavior: https://bugs.php.net/fix.php?id=75573&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=75573&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=75573&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=75573&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=75573&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=75573&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=75573&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=75573&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=75573&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=75573&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=75573&r=mysqlcfg