Bug #78658 [NEW]: Memory corruption using Closure::bindTo

From: Date: Wed, 09 Oct 2019 14:32:41 +0000
Subject: Bug #78658 [NEW]: Memory corruption using Closure::bindTo
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223161@lists.php.net to get a copy of this message
From: leigh Operating system: PHP version: 7.3.10 Package: Reproducible crash Bug Type: Bug Bug description:Memory corruption using Closure::bindTo Description: ------------ Test script produces a SEGFAULT on branches PHP-7.3, PHP-7.4 and master but not in PHP-7.2. Compiled with --disable-all. Found using AFL. In the test script by the time it gets to the string interpolation with "CCCC" the zval already appears to be corrupt. The memory location of a stdClass object on the end of the string instead of the requested characters. Test script: --------------- <?php $c = function(){}; $scope = "AAAA"; $c->bindTo(new stdClass, $scope); $scope = "{$scope}BBBB"; $c->bindTo(new stdClass, $scope); $scope = "{$scope}CCCC"; // var_dump($scope); // string(12) "AAAABBBB" $c->bindTo(new stdClass, $scope); Expected result: ---------------- Exit code 0 Actual result: -------------- Program received signal SIGSEGV, Segmentation fault. zend_mm_gc (heap=0x7ffff7a00040) at /home/leigh/php-src/Zend/zend_alloc.c:1956 1956 ZEND_MM_CHECK(chunk->heap == heap, "zend_mm_heap corrupted"); (gdb) bt #0 zend_mm_gc (heap=0x7ffff7a00040) at /home/leigh/php-src/Zend/zend_alloc.c:1956 #1 0x00005555557c950b in zend_mm_gc (heap=0x7ffff7a00040) at /home/leigh/php-src/Zend/zend_alloc.c:1946 #2 zend_mm_alloc_huge (heap=0x7ffff7a00040, size=93824997779152) at /home/leigh/php-src/Zend/zend_alloc.c:1808 #3 0x00005555557e73d1 in zend_string_alloc (persistent=0, len=93824997779120) at /home/leigh/php-src/Zend/zend_string.h:133 #4 zend_string_tolower_ex (str=0x7ffff7a6a938, persistent=persistent@entry=0) at /home/leigh/php-src/Zend/zend_operators.c:2686 #5 0x00005555557e29f7 in zend_lookup_class_ex (name=name@entry=0x7ffff7a6a938, key=key@entry=0x0, use_autoload=use_autoload@entry=1) at /home/leigh/php-src/Zend/zend_execute_API.c:851 #6 0x0000555555817293 in zim_Closure_bind (execute_data=<optimised out>, return_value=0x7fffffffa450) at /home/leigh/php-src/Zend/zend_closures.c:201 #7 0x000055555587375e in ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER () at /home/leigh/php-src/Zend/zend_vm_execute.h:984 #8 execute_ex (ex=0x6262626261600000) at /home/leigh/php-src/Zend/zend_vm_execute.h:55493 #9 0x0000555555875230 in zend_execute (op_array=op_array@entry=0x7ffff7a7f2a0, return_value=0x0, return_value@entry=0x7ffff7a1d030) at /home/leigh/php-src/Zend/zend_vm_execute.h:60889 #10 0x00005555557f0239 in zend_execute_scripts (type=type@entry=8, retval=0x7ffff7a1d030, retval@entry=0x0, file_count=file_count@entry=3) at /home/leigh/php-src/Zend/zend.c:1568 #11 0x000055555578f440 in php_execute_script (primary_file=<optimised out>) at /home/leigh/php-src/main/main.c:2639 #12 0x000055555587770e in do_cli (argc=2, argv=0x555555a96860) at /home/leigh/php-src/sapi/cli/php_cli.c:997 #13 0x0000555555648bcd in main (argc=2, argv=0x555555a96860) at /home/leigh/php-src/sapi/cli/php_cli.c:1389 -- Edit bug report at https://bugs.php.net/bug.php?id=78658&edit=1 -- Fix committed: https://bugs.php.net/fix.php?id=78658&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=78658&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=78658&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=78658&r=needscript Try newer version: https://bugs.php.net/fix.php?id=78658&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=78658&r=support Expected behavior: https://bugs.php.net/fix.php?id=78658&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=78658&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=78658&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=78658&r=globals PHP version support discontinued: https://bugs.php.net/fix.php?id=78658&r=phptooold Daylight Savings: https://bugs.php.net/fix.php?id=78658&r=dst IIS Stability: https://bugs.php.net/fix.php?id=78658&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=78658&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=78658&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=78658&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=78658&r=mysqlcfg

« previous php.bugs (#223161) next »