Bug #77297 [Ver->Csd]: SodiumException segfaults on PHP 7.3

From: Date: Sun, 16 Dec 2018 15:37:45 +0000
Subject: Bug #77297 [Ver->Csd]: SodiumException segfaults on PHP 7.3
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218471@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77297&edit=1 ID: 77297 Updated by: cmb@php.net Reported by: security at paragonie dot com Summary: SodiumException segfaults on PHP 7.3 -Status: Verified +Status: Closed Type: Bug Package: Reproducible crash Operating System: Ubuntu 18.04 PHP Version: 7.3.0 Assigned To: jedisct1 Block user comment: N Private report: N New Comment: Automatic comment on behalf of scott@paragonie.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=e0e08d376ed14c6a94e2712659828a60aa71b70a Log: Fix #77297: SodiumException segfaults on PHP 7.3 Previous Comments: ------------------------------------------------------------------------ [2018-12-16 14:23:15] sjon at hortensius dot net FYI the 3v4l failure (to crash) was caused by sodium not being loaded correctly which I fixed - therefore making this test fail there as well ------------------------------------------------------------------------ [2018-12-14 21:36:26] security at paragonie dot com Patch here: https://github.com/php/php-src/pull/3708 ------------------------------------------------------------------------ [2018-12-14 12:10:32] cmb@php.net It seems the problem is that zend_hash_clean() is called[1] on a hash table with refcount==2, which is not allowed: php: /mnt/c/Users/cmb/php-dev/php-src/Zend/zend_hash.c:1521: zend_hash_clean: Assertion `(zend_gc_refcount(&(ht)->gc) == 1) || ((ht)->u.flags & (1<<6))' failed. Aborted (core dumped) Also Z_TYPE_P(frame) == IS_ARRAY looks fishy; shouldn't that be Z_TYPE_P(args) == IS_ARRAY? [1] <https://github.com/php/php-src/blob/php-7.3.0/ext/sodium/libsodium.c#L390-L392> ------------------------------------------------------------------------ [2018-12-14 02:14:06] security at paragonie dot com $ gdb $(which php) GNU gdb (Ubuntu 8.1-0ubuntu3) 8.1.0.20180409-git Copyright (C) 2018 Free Software Foundation, Inc. License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html> This is free software: you are free to change and redistribute it. There is NO WARRANTY, to the extent permitted by law. Type "show copying" and "show warranty" for details. This GDB was configured as "x86_64-linux-gnu". Type "show configuration" for configuration details. For bug reporting instructions, please see: <http://www.gnu.org/software/gdb/bugs/>. Find the GDB manual and other documentation resources online at: <http://www.gnu.org/software/gdb/documentation/>. For help, type "help". Type "apropos word" to search for commands related to "word"... Reading symbols from /usr/bin/php...(no debugging symbols found)...done. (gdb) run /home/scott/sodium_compat/segfault.php Starting program: /usr/bin/php /home/scott/sodium_compat/segfault.php [Thread debugging using libthread_db enabled] Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1". Program received signal SIGSEGV, Segmentation fault. 0x00005555557fb831 in zend_hash_clean () (gdb) bt #0 0x00005555557fb831 in zend_hash_clean () #1 0x00005555556d68b2 in ?? () #2 0x00005555556d68dc in ?? () #3 0x00005555557ed35b in object_and_properties_init () #4 0x000055555586a494 in ?? () #5 0x0000555555873924 in execute_ex () #6 0x000055555587a313 in zend_execute () #7 0x00005555557eb9d2 in zend_execute_scripts () #8 0x000055555578bce0 in php_execute_script () #9 0x000055555587c7ec in ?? () #10 0x000055555564480b in ?? () #11 0x00007ffff5c2eb97 in __libc_start_main (main=0x5555556443f0, argc=2, argv=0x7fffffffe038, init=<optimized out>, fini=<optimized out>, rtld_fini=<optimized out>, stack_end=0x7fffffffe028) at ../csu/libc-start.c:310 #12 0x00005555556449aa in _start () (gdb) ------------------------------------------------------------------------ [2018-12-14 00:31:50] requinix@php.net Can you get a backtrace too? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77297 -- Edit this bug report at https://bugs.php.net/bug.php?id=77297&edit=1

« previous php.bugs (#218471) next »