Bug #77793 [Asn->Csd]: Segmentation fault in extract() when overwriting reference with itself

From: Date: Mon, 25 Mar 2019 16:36:59 +0000
Subject: Bug #77793 [Asn->Csd]: Segmentation fault in extract() when overwriting reference with itself
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-220175@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77793&edit=1 ID: 77793 Updated by: nikic@php.net Reported by: contact at joycebabu dot com Summary: Segmentation fault in extract() when overwriting reference with itself -Status: Assigned +Status: Closed Type: Bug Package: Unknown/Other Function Operating System: macOs Mojave 10.14.2 PHP Version: 7.3.3 Assigned To: nikic Block user comment: N Private report: N New Comment: Automatic comment on behalf of nikita.ppv@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=e97577edde49e1f6e86219091b343f80b3b92e65 Log: Fixed bug #77793 Previous Comments: ------------------------------------------------------------------------ [2019-03-25 16:22:14] nikic@php.net Slightly reduced test case: <?php $str = 'foo'; $vars = ['var' => $str . 'bar']; $var = &$vars['var']; extract($vars); var_dump($vars, $var); The problem is that when we destroy the old value of the variable, we also happen to destroy the new value we're trying to assign... ------------------------------------------------------------------------ [2019-03-25 16:14:53] nikic@php.net Confirm that this is faulting on 7.3 and working on 7.2. ------------------------------------------------------------------------ [2019-03-25 16:14:00] contact at joycebabu dot com As per the following online PHP interpreter, the issue is present in 7.3.x only. https://3v4l.org/PSMRW ------------------------------------------------------------------------ [2019-03-25 16:10:16] contact at joycebabu dot com Description: ------------ The following test code causes PHP to exit with a segmentation fault. Test script: --------------- <?php register_shutdown_function(function () { $hookInfo = [function () {}]; $hooks[][] = [$hookInfo]; }); $options = [ 'sort' => [] ]; $defaultOption = ['sort' => []]; $sort = &$options['sort']; $sort['direction'] = 'asc'; $val = array_merge($defaultOption, $options); extract($val); print_r($val); Expected result: ---------------- Array ( [sort] => Array ( [direction] => asc ) ) Actual result: -------------- Array ( [sort] => Array ( [direction] => asc ) ) Segmentation fault: 11 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77793&edit=1

« previous php.bugs (#220175) next »