Bug #78488 [Opn]: OOB in ZEND_FUNCTION(ffi_trampoline)

From: Date: Tue, 03 Sep 2019 13:46:27 +0000
Subject: Bug #78488 [Opn]: OOB in ZEND_FUNCTION(ffi_trampoline)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-222542@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78488&edit=1 ID: 78488 Updated by: cmb@php.net Reported by: cmb@php.net Summary: OOB in ZEND_FUNCTION(ffi_trampoline) Status: Open Type: Bug Package: Unknown/Other Function Operating System: Windows x86 PHP Version: 7.4Git-2019-09-03 (Git) -Assigned To: +Assigned To: dmitry Block user comment: N Private report: N New Comment: Dmitry, could you please have a look at this? Previous Comments: ------------------------------------------------------------------------ [2019-09-03 13:45:47] cmb@php.net Description: ------------ As of commit 77a0fa1[1], x86 Windows debug builds signal stack memory corruption in ZEND_FUNCTION(ffi_trampoline) when running callconv.phpt. The culprit is that we're allocating not enough space[2], since FFI_SIZEOF_ARG is 4 on x86 Windows, but in zend_ffi_pass_arg() we're copying doubles (and perhaps even wider values) to that memory. I'm somewhat confused to have a constant for the argument size, since at least some call conventions do not have a fixed argument size to my knowledge, but at least here we must not use this constant, but rather the maximum size of the supported argument types. [1] <http://git.php.net/?p=php-src.git;a=commit;h=77a0fa101ed59f05ea07b03adb1cb66962fc45e7> [2] <https://github.com/php/php-src/blob/php-7.4.0beta4/ext/ffi/ffi.c#L2616-L2617> ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=78488&edit=1

« previous php.bugs (#222542) next »