Bug #77137 [Nab]: preg_replace memory exhaustion
| From: | php at abiusx dot com | Date: | Sun, 11 Nov 2018 00:04:09 +0000 |
| Subject: | Bug #77137 [Nab]: preg_replace memory exhaustion | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-217896@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77137&edit=1
ID: 77137
User updated by: php at abiusx dot com
Reported by: php at abiusx dot com
Summary: preg_replace memory exhaustion
Status: Not a bug
Type: Bug
Package: *Regular Expressions
Operating System: macOS Mojave
PHP Version: 7.2.12
Block user comment: N
Private report: N
New Comment:
Why is this community so toxic.
1. I know what I am doing.
2. This is not my code.
3. We're running a PHP anti-malware sandbox on a large (20TB) codebase and this is one of the
instances that is crashing the sandbox (unexpected behavior)
That's why it's being shared. If you don't like it, don't look at it.
Previous Comments:
------------------------------------------------------------------------
[2018-11-10 23:55:27] requinix@php.net
The problem here is you don't know what you're doing.
Here's an exercise:
1. Try your code with a different replacement character than "&".
2. Try with only one /()/ regex and note the final result.
3. Try with two regexes and note the result.
4. Try with three.
------------------------------------------------------------------------
[2018-11-10 23:44:50] php at abiusx dot com
preg_replace and similar functions are regularly use to parse, sanitize and validate user input.
I admit in this case, the pattern also needs to be something very specific, but the replacement
string is the major factor here, which can come from the user in many scenarios.
I was unable to see any reference to "&" in the docs. I am assuming it's a
backreference and thus the computational complexity is growing exponentially, but that'd be a
very good point to make in the docs (or at least in the comments, or for future reference just in
case someone googles it).
------------------------------------------------------------------------
[2018-11-10 23:38:29] spam2 at rhsoft dot net
> or explain that pattern/replacement should not come from user input
breaking news: until you prove the opposite user inout is always bad
------------------------------------------------------------------------
[2018-11-10 23:31:05] php at abiusx dot com
Description:
------------
The following code will result in memory exhaustion and very long execution times:
preg_replace(array_fill(0, 10, '/()/'),str_repeat("&", 10),NULL);
https://3v4l.org/LnV37
Either add an example to the docs, or explain that pattern/replacement should not come from user
input.
Test script:
---------------
<?php
preg_replace(array_fill(0, 10, '/()/'),str_repeat("&", 10),NULL);
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77137&edit=1