Bug #78326 [PATCH]: improper memory deallocation on stream_get_contents() with fixed lenght buffer
| From: | albertcasademont@gmail.com | Date: | Tue, 23 Jul 2019 12:06:31 +0000 |
| Subject: | Bug #78326 [PATCH]: improper memory deallocation on stream_get_contents() with fixed lenght buffer | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-221909@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78326&edit=1
ID: 78326
Patch added by: albertcasademont@gmail.com
Reported by: albertcasademont at gmail dot com
Summary: improper memory deallocation on
stream_get_contents() with fixed lenght buffer
Status: Open
Type: Bug
Package: Streams related
Operating System: Alpine Linux 3.10
PHP Version: 7.2.21RC1
Block user comment: N
Private report: N
New Comment:
The following pull request has been associated:
Patch Name: fix #78326 memory issues with stream_get_contents() fixed length buffer
On GitHub: https://github.com/php/php-src/pull/4464
Patch: https://github.com/php/php-src/pull/4464.patch
Previous Comments:
------------------------------------------------------------------------
[2019-07-23 12:05:59] albertcasademont at gmail dot com
PR: https://github.com/php/php-src/pull/4464
------------------------------------------------------------------------
[2019-07-23 12:02:01] albertcasademont at gmail dot com
Description:
------------
When calling stream_get_contents() with a fixed length buffer, the memory allocated for that buffer
is not freed even though the actual data might be much shorter than the allocated buffer. This can
potentially crash the script just after a couple of stream_get_contents() calls due to memory
issues.
If we don't specify a fixed lenght buffer, php will correctly reallocate the string to the
exact amount of data read. This would also be the expected thing to do even if we fix the buffer
length.
Test script:
---------------
<?php
$f = tmpfile();
fwrite($f, '.');
$chunks = array();
for ($i = 0; $i < 1000; ++$i) {
rewind($f);
$chunks[] = stream_get_contents($f, 1000000);
}
var_dump(count($chunks));
Expected result:
----------------
int(1000)
Actual result:
--------------
Fatal error: Allowed memory size of 67108864 bytes exhausted (tried to allocate 1003520 bytes) in
/in/HP2U9 on line 9
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78326&edit=1