Bug #73210 [Opn]: Segfault with stmt read only cursor and get_result due to double closing

From: Date: Fri, 04 May 2018 21:26:02 +0000
Subject: Bug #73210 [Opn]: Segfault with stmt read only cursor and get_result due to double closing
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-215048@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73210&edit=1 ID: 73210 Updated by: cmb@php.net Reported by: richard dot fussenegger at trivago dot com Summary: Segfault with stmt read only cursor and get_result due to double closing Status: Open Type: Bug Package: MySQLi related Operating System: Irrelevant PHP Version: Irrelevant Block user comment: N Private report: N New Comment: > Patch will be directly provided as GitHub PR. FTR: <https://github.com/php/php-src/pull/2146> didn't really solve the issue. Previous Comments: ------------------------------------------------------------------------ [2016-09-30 11:28:04] richard dot fussenegger at trivago dot com Description: ------------ Getting the result of an executed prepared statement that uses a read only cursor results in a segfault because the second close call tries to free the internal result on null. It does not matter which is the first or second close call since stmt gives result a pointer to the result, the one that calls it first is the one that frees it and the other one accesses null. The access happens in mysqlnd_res::free_result_internal after the if (result->conn) condition where result->conn->m is being called. The m might already point to nowhere because the previous close call already freed it. Patch will be directly provided as GitHub PR. Test script: --------------- <?php mysqli_report(MYSQLI_REPORT_ERROR | MYSQLI_REPORT_STRICT); $mysqli = new mysqli('localhost', 'root', 'keines'); $stmt = $mysqli->prepare('SELECT 1 UNION SELECT 2 UNION SELECT 3'); $stmt->attr_set(MYSQLI_STMT_ATTR_CURSOR_TYPE, MYSQLI_CURSOR_TYPE_READ_ONLY); $stmt->execute(); $result = $stmt->get_result(); // call order does not matter {{{ $result->close(); $stmt->close(); // }}} $mysqli->close(); Expected result: ---------------- Successful and graceful shutdown of PHP. Actual result: -------------- Segfault ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73210&edit=1

« previous php.bugs (#215048) next »