Bug #73210 [Opn]: Segfault with stmt read only cursor and get_result due to double closing
| From: | cmb@php.net | Date: | Fri, 04 May 2018 21:26:02 +0000 |
| Subject: | Bug #73210 [Opn]: Segfault with stmt read only cursor and get_result due to double closing | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-215048@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73210&edit=1
ID: 73210
Updated by: cmb@php.net
Reported by: richard dot fussenegger at trivago dot com
Summary: Segfault with stmt read only cursor and get_result
due to double closing
Status: Open
Type: Bug
Package: MySQLi related
Operating System: Irrelevant
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
> Patch will be directly provided as GitHub PR.
FTR: <https://github.com/php/php-src/pull/2146>
didn't really
solve the issue.
Previous Comments:
------------------------------------------------------------------------
[2016-09-30 11:28:04] richard dot fussenegger at trivago dot com
Description:
------------
Getting the result of an executed prepared statement that uses a read only cursor results in a
segfault because the second close call tries to free the internal result on null. It does not matter
which is the first or second close call since stmt gives result a pointer to the result, the one
that calls it first is the one that frees it and the other one accesses null.
The access happens in mysqlnd_res::free_result_internal after the if (result->conn) condition
where result->conn->m is being called. The m might already point to nowhere because the
previous close call already freed it.
Patch will be directly provided as GitHub PR.
Test script:
---------------
<?php
mysqli_report(MYSQLI_REPORT_ERROR | MYSQLI_REPORT_STRICT);
$mysqli = new mysqli('localhost', 'root', 'keines');
$stmt = $mysqli->prepare('SELECT 1 UNION SELECT 2 UNION SELECT 3');
$stmt->attr_set(MYSQLI_STMT_ATTR_CURSOR_TYPE, MYSQLI_CURSOR_TYPE_READ_ONLY);
$stmt->execute();
$result = $stmt->get_result();
// call order does not matter {{{
$result->close();
$stmt->close();
// }}}
$mysqli->close();
Expected result:
----------------
Successful and graceful shutdown of PHP.
Actual result:
--------------
Segfault
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73210&edit=1