Bug #78620 [Com]: Out of memory error

From: Date: Wed, 02 Oct 2019 20:50:21 +0000
Subject: Bug #78620 [Com]: Out of memory error
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223002@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78620&edit=1

 ID:                 78620
 Comment by:         dude at mailinator dot com
 Reported by:        v-altruo at microsoft dot com
 Summary:            Out of memory error
 Status:             Re-Opened
 Type:               Bug
 Package:            Scripting Engine problem
 Operating System:   Windows Server 2012 R2
 PHP Version:        7.2.23
 Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

Dude!


Previous Comments:
------------------------------------------------------------------------
[2019-10-02 17:05:49] cmb@php.net

Cf. <https://github.com/php/php-src/pull/4766#discussion_r330658679>.

------------------------------------------------------------------------
[2019-10-02 17:04:33] cmb@php.net

Automatic comment on behalf of cmbecker69@gmx.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=f2fb37a772908a9331e67f583fddcc4b1b186ccf
Log: Revert &quot;Fix #78620: Out of memory error&quot;

------------------------------------------------------------------------
[2019-10-02 16:23:17] cmb@php.net

Automatic comment on behalf of cmbecker69@gmx.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=8ce04df7e0108a10f7b782a28204e9384ab1129c
Log: Fix #78620: Out of memory error

------------------------------------------------------------------------
[2019-10-02 14:25:23] cmb@php.net

The following pull request has been associated:

Patch Name: Fix #78620: Out of memory error
On GitHub:  https://github.com/php/php-src/pull/4766
Patch:      https://github.com/php/php-src/pull/4766.patch

------------------------------------------------------------------------
[2019-10-01 22:10:21] cmb@php.net

Oh, indeed!

The problem is that ZEND_MM_ALIGNED_SIZE_EX evaluates to 0[1],
since (size + alignment -1) overflows (in this case size ==
4294901777 && alignment == 2097152), and we don't catch that.

[1] <https://github.com/php/php-src/blob/php-7.2.23/Zend/zend_alloc.c#L1458>

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=78620


--
Edit this bug report at https://bugs.php.net/bug.php?id=78620&edit=1


Thread (8 messages)

« previous php.bugs (#223002) next »