Bug #75573 [Com]: Segmentation fault in 7.1.12 and 7.0.26
| From: | thomas at shadowweb dot org | Date: | Tue, 28 Nov 2017 14:28:23 +0000 |
| Subject: | Bug #75573 [Com]: Segmentation fault in 7.1.12 and 7.0.26 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-212773@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75573&edit=1
ID: 75573
Comment by: thomas at shadowweb dot org
Reported by: manuel-php at mausz dot at
Summary: Segmentation fault in 7.1.12 and 7.0.26
Status: Feedback
Type: Bug
Package: Reproducible crash
Operating System: Linux
PHP Version: 7.1.12
Block user comment: N
Private report: N
New Comment:
I can confirm this issue - we are also experiencing massive amounts of segmentation faults of PHP
processes after upgrading from 7.0.25 to 7.0.26 and from 7.1.11 to 7.1.12 across our servers.
Providing a simple testcase will be difficult, since this issue mainly seems to occur in lager CMS
installations - I will try to narrow this down.
Rolling back to the previous PHP versions in the meantime.
Previous Comments:
------------------------------------------------------------------------
[2017-11-27 04:18:24] laruence@php.net
Thank you for this bug report. To properly diagnose the problem, we
need a short but complete example script to be able to reproduce
this bug ourselves.
A proper reproducing script starts with <?php and ends with ?>,
is max. 10-20 lines long and does not require any external
resources such as databases, etc. If the script requires a
database to demonstrate the issue, please make sure it creates
all necessary tables, stored procedures etc.
Please avoid embedding huge scripts into the report.
------------------------------------------------------------------------
[2017-11-26 15:48:43] manuel-php at mausz dot at
Description:
------------
After updating to 7.1.12 and 7.0.26 we noticed an increased rate in crashes across all our
webservers. The crashes are somehow triggered by "NextGEN Gallery" and reverting https://github.com/php/php-src/commit/bc59289b7a25219ea2179554dc26c88e533250a5
+ https://github.com/php/php-src/commit/98eee90734c4fabf3f3a3d4168576cb6b25ad9b1
fixed it.
Backtrace:
#0 zend_mm_alloc_small (bin_num=<optimized out>, size=<optimized out>,
heap=0x7fe70d600040) at /tmp/php-7.0.26/fpm/Zend/zend_alloc.c:1318
#1 zend_mm_alloc_heap (size=<optimized out>, heap=0x7fe70d600040) at
/tmp/php-7.0.26/fpm/Zend/zend_alloc.c:1389
#2 _emalloc (size=<optimized out>) at /tmp/php-7.0.26/fpm/Zend/zend_alloc.c:2477
#3 0x00000000007bf579 in zend_hash_real_init_ex (packed=<optimized out>, ht=0x7fe70b0ccd20)
at /tmp/php-7.0.26/fpm/Zend/zend_hash.c:135
#4 zend_hash_check_init (packed=<optimized out>, ht=0x7fe70b0ccd20) at
/tmp/php-7.0.26/fpm/Zend/zend_hash.c:163
#5 _zend_hash_index_add_or_update_i (flag=10, pData=0x10cb840 <executor_globals>, h=0,
ht=0x7fe70b0ccd20) at /tmp/php-7.0.26/fpm/Zend/zend_hash.c:729
#6 _zend_hash_index_add_new (ht=ht@entry=0x7fe70b0ccd20, h=0, pData=pData@entry=0x10cb840
<executor_globals>) at /tmp/php-7.0.26/fpm/Zend/zend_hash.c:853
#7 0x000000000081c8f8 in zend_fetch_dimension_address_inner (type=1, dim_type=16, dim=<optimized
out>, ht=<optimized out>) at /tmp/php-7.0.26/fpm/Zend/zend_execute.c:1572
#8 ZEND_ASSIGN_DIM_SPEC_VAR_CV_HANDLER () at /tmp/php-7.0.26/fpm/Zend/zend_vm_execute.h:20864
#9 0x00000000007eddf8 in execute_ex (ex=<optimized out>) at
/tmp/php-7.0.26/fpm/Zend/zend_vm_execute.h:414
#10 0x00000000007a3285 in zend_call_function (fci=fci@entry=0x7ffe0e1640e0,
fci_cache=0x7fe70d6d6da0, fci_cache@entry=0x0) at /tmp/php-7.0.26/fpm/Zend/zend_execute_API.c:867
#11 0x00000000007a3698 in call_user_function_ex (function_table=<optimized out>,
object=object@entry=0x0, function_name=<optimized out>,
retval_ptr=retval_ptr@entry=0x7ffe0e164170, param_count=<optimized out>, params=<optimized
out>,
no_separation=no_separation@entry=1, symbol_table=symbol_table@entry=0x0) at
/tmp/php-7.0.26/fpm/Zend/zend_execute_API.c:675
#12 0x00000000007a36d0 in call_user_function (function_table=<optimized out>,
object=object@entry=0x0, function_name=<optimized out>,
retval_ptr=retval_ptr@entry=0x7ffe0e164170, param_count=<optimized out>, params=<optimized
out>)
at /tmp/php-7.0.26/fpm/Zend/zend_execute_API.c:657
#13 0x00000000006ab7b2 in user_shutdown_function_call (zv=<optimized out>) at
/tmp/php-7.0.26/fpm/ext/standard/basic_functions.c:4934
#14 0x00000000007c1f6d in zend_hash_apply (ht=0x7fe70d79a3b8, apply_func=apply_func@entry=0x6ab6dd
<user_shutdown_function_call>) at /tmp/php-7.0.26/fpm/Zend/zend_hash.c:1537
#15 0x00000000006ae9ad in php_call_shutdown_functions () at
/tmp/php-7.0.26/fpm/ext/standard/basic_functions.c:5018
#16 0x0000000000754595 in php_request_shutdown (dummy=dummy@entry=0x0) at
/tmp/php-7.0.26/fpm/main/main.c:1804
#17 0x000000000048e07a in main (argc=<optimized out>, argv=<optimized out>) at
/tmp/php-7.0.26/fpm/sapi/fpm/fpm/fpm_main.c:2066
PHP backtrace from core dump:
(gdb) dump_bt executor_globals.current_execute_data
[0x7fe70d618740] WP_Hook->apply_filters("", array(1)[0x7fe70d6187b0])
/path/to/wp-includes/class-wp-hook.php:271
[0x7fe70d618680] WP_Hook->do_action(array(1)[0x7fe70d6186e0])
/path/to/wp-includes/class-wp-hook.php:310
[0x7fe70d618330] do_action("shutdown") /path/to/wp-includes/plugin.php:453
[0x7fe70d6182b0] shutdown_action_hook() /path/to/wp-includes/load.php:679
[0x7ffe0e164040] ???
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75573&edit=1