Bug #77359 [Asn->Csd]: spl_autoload causes segfault
| From: | nikic@php.net | Date: | Thu, 27 Dec 2018 14:30:13 +0000 |
| Subject: | Bug #77359 [Asn->Csd]: spl_autoload causes segfault | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-218645@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77359&edit=1
ID: 77359
Updated by: nikic@php.net
Reported by: lauri dot kentta at gmail dot com
Summary: spl_autoload causes segfault
-Status: Assigned
+Status: Closed
Type: Bug
Package: SPL related
Operating System: Linux
PHP Version: 7.3.0
Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of lauri.kentta@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=89bf3df67d0f0ba3090b273d1b1b9fba9514a62d
Log: Fix #77359: spl_autoload causes segfault
Previous Comments:
------------------------------------------------------------------------
[2018-12-27 13:55:22] lauri dot kentta at gmail dot com
Description:
------------
The function spl_autoload converts class name to lower case and later tries to free this string.
However, if it's already in lower case, it's not copied, but the reference count is
incremented instead. Then zend_string_free is called, but this function can only be used if the
reference count is 1 (or 0) and otherwise leads to use-after-free (or failed assertion).
Looks like blame goes to commit 084c17fe0b68d391467fd48a14433443d4fcba81 (Dmitry Stogov
<dmitry@zend.com>). Cases of zend_str_tolower_copy were converted to zend_string_tolower to
avoid reallocations, but at least in this case, freeing was not fixed accordingly.
Test script:
---------------
<?php
$a = md5(""); # Create a non-interned string.
spl_autoload($a); # Invalid free.
spl_autoload($a); # Use after free.
echo "{$a} + foo\n"; # Use after free.
# Notice how "foo" is not printed even if the code does not crash.
# Run it a few times to get a crash.
?>
Expected result:
----------------
No crash, full output.
Actual result:
--------------
Crash or truncated output.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77359&edit=1