Bug #78488 [Opn]: OOB in ZEND_FUNCTION(ffi_trampoline)
| From: | cmb@php.net | Date: | Tue, 03 Sep 2019 13:46:27 +0000 |
| Subject: | Bug #78488 [Opn]: OOB in ZEND_FUNCTION(ffi_trampoline) | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-222542@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78488&edit=1
ID: 78488
Updated by: cmb@php.net
Reported by: cmb@php.net
Summary: OOB in ZEND_FUNCTION(ffi_trampoline)
Status: Open
Type: Bug
Package: Unknown/Other Function
Operating System: Windows x86
PHP Version: 7.4Git-2019-09-03 (Git)
-Assigned To:
+Assigned To: dmitry
Block user comment: N
Private report: N
New Comment:
Dmitry, could you please have a look at this?
Previous Comments:
------------------------------------------------------------------------
[2019-09-03 13:45:47] cmb@php.net
Description:
------------
As of commit 77a0fa1[1], x86 Windows debug builds signal stack
memory corruption in ZEND_FUNCTION(ffi_trampoline) when running
callconv.phpt. The culprit is that we're allocating not enough
space[2], since FFI_SIZEOF_ARG is 4 on x86 Windows, but in
zend_ffi_pass_arg() we're copying doubles (and perhaps even wider
values) to that memory.
I'm somewhat confused to have a constant for the argument size,
since at least some call conventions do not have a fixed argument
size to my knowledge, but at least here we must not use this
constant, but rather the maximum size of the supported argument
types.
[1] <http://git.php.net/?p=php-src.git;a=commit;h=77a0fa101ed59f05ea07b03adb1cb66962fc45e7>
[2] <https://github.com/php/php-src/blob/php-7.4.0beta4/ext/ffi/ffi.c#L2616-L2617>
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78488&edit=1