Bug #77137 [Nab]: preg_replace memory exhaustion

From: Date: Sun, 11 Nov 2018 00:04:09 +0000
Subject: Bug #77137 [Nab]: preg_replace memory exhaustion
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-217896@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77137&edit=1 ID: 77137 User updated by: php at abiusx dot com Reported by: php at abiusx dot com Summary: preg_replace memory exhaustion Status: Not a bug Type: Bug Package: *Regular Expressions Operating System: macOS Mojave PHP Version: 7.2.12 Block user comment: N Private report: N New Comment: Why is this community so toxic. 1. I know what I am doing. 2. This is not my code. 3. We're running a PHP anti-malware sandbox on a large (20TB) codebase and this is one of the instances that is crashing the sandbox (unexpected behavior) That's why it's being shared. If you don't like it, don't look at it. Previous Comments: ------------------------------------------------------------------------ [2018-11-10 23:55:27] requinix@php.net The problem here is you don't know what you're doing. Here's an exercise: 1. Try your code with a different replacement character than "&". 2. Try with only one /()/ regex and note the final result. 3. Try with two regexes and note the result. 4. Try with three. ------------------------------------------------------------------------ [2018-11-10 23:44:50] php at abiusx dot com preg_replace and similar functions are regularly use to parse, sanitize and validate user input. I admit in this case, the pattern also needs to be something very specific, but the replacement string is the major factor here, which can come from the user in many scenarios. I was unable to see any reference to "&" in the docs. I am assuming it's a backreference and thus the computational complexity is growing exponentially, but that'd be a very good point to make in the docs (or at least in the comments, or for future reference just in case someone googles it). ------------------------------------------------------------------------ [2018-11-10 23:38:29] spam2 at rhsoft dot net > or explain that pattern/replacement should not come from user input breaking news: until you prove the opposite user inout is always bad ------------------------------------------------------------------------ [2018-11-10 23:31:05] php at abiusx dot com Description: ------------ The following code will result in memory exhaustion and very long execution times: preg_replace(array_fill(0, 10, '/()/'),str_repeat("&", 10),NULL); https://3v4l.org/LnV37 Either add an example to the docs, or explain that pattern/replacement should not come from user input. Test script: --------------- <?php preg_replace(array_fill(0, 10, '/()/'),str_repeat("&", 10),NULL); ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77137&edit=1

« previous php.bugs (#217896) next »