Bug #77447 [Opn->Ver]: PHP 7.3 built with ASAN crashes in zend_cpu_supports_avx2

From: Date: Mon, 14 Jan 2019 09:56:19 +0000
Subject: Bug #77447 [Opn->Ver]: PHP 7.3 built with ASAN crashes in zend_cpu_supports_avx2
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218932@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77447&edit=1

 ID:                 77447
 Updated by:         nikic@php.net
 Reported by:        hanno at hboeck dot de
 Summary:            PHP 7.3 built with ASAN crashes in
                     zend_cpu_supports_avx2
-Status:             Open
+Status:             Verified
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   Linux
 PHP Version:        7.3.1
 Block user comment: N
 Private report:     N

 New Comment:

Confirming the segfault. Had to add LIBS="-ldl" to avoid linker errors.


Previous Comments:
------------------------------------------------------------------------
[2019-01-11 14:59:05] hanno at hboeck dot de

Description:
------------
I'm unable to get PHP 7.3 to run with address sanitizer.

Reproduce:
./configure CFLAGS="-fsanitize=address -g" CXXFLAGS="-fsanitize=address -g"
LDFLAGS="-fsanitize=address" --enable-debug
make

./sapi/cli/php
leads to a segfault.

This problem does not happen with 7.2.x.
Address Sanitizer has been an extremely helpful tool to identify memory corruption bugs and security
issues in PHP, therefore this is concerning, as it might hamper the ability of security researchers
to find bugs in PHP.

A stack trace from GDB shows this happens in the function zend_cpu_supports_avx2(). AVX2 support is
not available in PHP 7.2, therefore I believe this explains the difference between 7.2 and 7.3.

Expected result:
----------------
No segfault with ASAN.

Actual result:
--------------
Segfault with ASAN.


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=77447&edit=1


Thread (13 messages)

« previous php.bugs (#218932) next »