Bug #77793 [Asn->Csd]: Segmentation fault in extract() when overwriting reference with itself
| From: | nikic@php.net | Date: | Mon, 25 Mar 2019 16:36:59 +0000 |
| Subject: | Bug #77793 [Asn->Csd]: Segmentation fault in extract() when overwriting reference with itself | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-220175@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77793&edit=1
ID: 77793
Updated by: nikic@php.net
Reported by: contact at joycebabu dot com
Summary: Segmentation fault in extract() when overwriting
reference with itself
-Status: Assigned
+Status: Closed
Type: Bug
Package: Unknown/Other Function
Operating System: macOs Mojave 10.14.2
PHP Version: 7.3.3
Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of nikita.ppv@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=e97577edde49e1f6e86219091b343f80b3b92e65
Log: Fixed bug #77793
Previous Comments:
------------------------------------------------------------------------
[2019-03-25 16:22:14] nikic@php.net
Slightly reduced test case:
<?php
$str = 'foo';
$vars = ['var' => $str . 'bar'];
$var = &$vars['var'];
extract($vars);
var_dump($vars, $var);
The problem is that when we destroy the old value of the variable, we also happen to destroy the new
value we're trying to assign...
------------------------------------------------------------------------
[2019-03-25 16:14:53] nikic@php.net
Confirm that this is faulting on 7.3 and working on 7.2.
------------------------------------------------------------------------
[2019-03-25 16:14:00] contact at joycebabu dot com
As per the following online PHP interpreter, the issue is present in 7.3.x only.
https://3v4l.org/PSMRW
------------------------------------------------------------------------
[2019-03-25 16:10:16] contact at joycebabu dot com
Description:
------------
The following test code causes PHP to exit with a segmentation fault.
Test script:
---------------
<?php
register_shutdown_function(function () {
$hookInfo = [function () {}];
$hooks[][] = [$hookInfo];
});
$options = [
'sort' => []
];
$defaultOption = ['sort' => []];
$sort = &$options['sort'];
$sort['direction'] = 'asc';
$val = array_merge($defaultOption, $options);
extract($val);
print_r($val);
Expected result:
----------------
Array
(
[sort] => Array
(
[direction] => asc
)
)
Actual result:
--------------
Array
(
[sort] => Array
(
[direction] => asc
)
)
Segmentation fault: 11
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77793&edit=1