Bug #74310 [Com]: segfault in i_zval_ptr_dtor()
Edit report at https://bugs.php.net/bug.php?id=74310&edit=1
ID: 74310
Comment by: contacto at agora-security dot com
Reported by: brian dot carpenter at gmail dot com
Summary: segfault in i_zval_ptr_dtor()
Status: Assigned
Type: Bug
Package: Reproducible crash
Operating System: Debian 8 x64
PHP Version: 7.1Git-2017-03-24 (Git)
Assigned To: pollita
Block user comment: N
Private report: N
New Comment:
Hello,
This bug hasn't been patch, correct?
Also, I think the CVE should be CVE-2017-9119.
Cheers!
Previous Comments:
------------------------------------------------------------------------
[2017-09-10 21:34:53] cmb@php.net
Related To: Bug #74593
------------------------------------------------------------------------
[2017-03-27 22:10:26] pollita@php.net
Sort of...
It's happening because a zval referencing a free'd string is being dtor'd (in the
middle of a bailout).
I've got a fix for the problem and will push it when I finish testing edge cases.
------------------------------------------------------------------------
[2017-03-26 17:09:20] bwoebi@php.net
This happens as the refcount is decremented, but the assignment to the new value never happening,
thus leaving us with a zend_string with two references but rc=1.
A trivial fix would be:
https://bugs.php.net/patch-display.php?bug_id=74310&patch=bug_74310_decrement_after_alloc&revision=latest
But I'm not sure whether that's the ideal fix though.
------------------------------------------------------------------------
[2017-03-26 17:08:41] bwoebi@php.net
The following patch has been added/updated:
Patch Name: bug_74310_decrement_after_alloc
Revision: 1490548119
URL: https://bugs.php.net/patch-display.php?bug=74310&patch=bug_74310_decrement_after_alloc&revision=1490548119
------------------------------------------------------------------------
[2017-03-25 22:29:29] pollita@php.net
I've been able to reduce the repro script to the following. When I gdb, it still crashes,
apparently while trying to clean up the global symbol table at request end.
<?
$o{8}='800000000';
$$o{'8000000'}=$Array='Q';
$$o{'800000000'}=$$Array=0;
Interestingly, shortening the keys (while keeping them unique) *does* avoid the crash.
(gdb) bt
#0 0x00000000009a006c in i_zval_ptr_dtor (zval_ptr=0x7fffef01e090,
__zend_filename=0x10d7148 "/home/sgolemon/dev/php/php-src/Zend/zend_execute_API.c",
__zend_lineno=212) at /home/sgolemon/dev/php/php-src/Zend/zend_variables.h:48
#1 0x00000000009a0c5c in zend_unclean_zval_ptr_dtor (zv=0x7fffef01e090)
at /home/sgolemon/dev/php/php-src/Zend/zend_execute_API.c:212
#2 0x00000000009d2893 in _zend_hash_del_el_ex (ht=0x1452d90 <executor_globals+304>, idx=8,
p=0x7fffef063200, prev=0x0) at /home/sgolemon/dev/php/php-src/Zend/zend_hash.c:997
#3 0x00000000009d2973 in _zend_hash_del_el (ht=0x1452d90 <executor_globals+304>, idx=8,
p=0x7fffef063200) at /home/sgolemon/dev/php/php-src/Zend/zend_hash.c:1020
#4 0x00000000009d3ef8 in zend_hash_graceful_reverse_destroy (
ht=0x1452d90 <executor_globals+304>) at
/home/sgolemon/dev/php/php-src/Zend/zend_hash.c:1476
#5 0x00000000009a0f86 in shutdown_executor ()
at /home/sgolemon/dev/php/php-src/Zend/zend_execute_API.c:281
#6 0x00000000009bbc73 in zend_deactivate () at /home/sgolemon/dev/php/php-src/Zend/zend.c:1060
#7 0x0000000000921857 in php_request_shutdown (dummy=0x0)
at /home/sgolemon/dev/php/php-src/main/main.c:1879
#8 0x0000000000aa848b in do_cli (argc=2, argv=0x1457d20)
at /home/sgolemon/dev/php/php-src/sapi/cli/php_cli.c:1164
#9 0x0000000000aa8cf9 in main (argc=2, argv=0x1457d20)
at /home/sgolemon/dev/php/php-src/sapi/cli/php_cli.c:1390
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=74310
--
Edit this bug report at https://bugs.php.net/bug.php?id=74310&edit=1
Thread (9 messages)