Bug #78658 [NEW]: Memory corruption using Closure::bindTo
| From: | leigh@php.net | Date: | Wed, 09 Oct 2019 14:32:41 +0000 |
| Subject: | Bug #78658 [NEW]: Memory corruption using Closure::bindTo | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-223161@lists.php.net to get a copy of this message | ||
From: leigh
Operating system:
PHP version: 7.3.10
Package: Reproducible crash
Bug Type: Bug
Bug description:Memory corruption using Closure::bindTo
Description:
------------
Test script produces a SEGFAULT on branches PHP-7.3, PHP-7.4 and master
but not in PHP-7.2. Compiled with
--disable-all. Found using AFL.
In the test script by the time it gets to the string interpolation with
"CCCC" the zval already appears to be corrupt.
The memory location of a stdClass object on the end of the string
instead of the requested characters.
Test script:
---------------
<?php
$c = function(){};
$scope = "AAAA";
$c->bindTo(new stdClass, $scope);
$scope = "{$scope}BBBB";
$c->bindTo(new stdClass, $scope);
$scope = "{$scope}CCCC"; // var_dump($scope); // string(12) "AAAABBBB"
$c->bindTo(new stdClass, $scope);
Expected result:
----------------
Exit code 0
Actual result:
--------------
Program received signal SIGSEGV, Segmentation fault.
zend_mm_gc (heap=0x7ffff7a00040) at
/home/leigh/php-src/Zend/zend_alloc.c:1956
1956 ZEND_MM_CHECK(chunk->heap == heap,
"zend_mm_heap corrupted");
(gdb) bt
#0 zend_mm_gc (heap=0x7ffff7a00040) at
/home/leigh/php-src/Zend/zend_alloc.c:1956
#1 0x00005555557c950b in zend_mm_gc (heap=0x7ffff7a00040) at
/home/leigh/php-src/Zend/zend_alloc.c:1946
#2 zend_mm_alloc_huge (heap=0x7ffff7a00040, size=93824997779152) at
/home/leigh/php-src/Zend/zend_alloc.c:1808
#3 0x00005555557e73d1 in zend_string_alloc (persistent=0,
len=93824997779120) at /home/leigh/php-src/Zend/zend_string.h:133
#4 zend_string_tolower_ex (str=0x7ffff7a6a938,
persistent=persistent@entry=0) at
/home/leigh/php-src/Zend/zend_operators.c:2686
#5 0x00005555557e29f7 in zend_lookup_class_ex
(name=name@entry=0x7ffff7a6a938, key=key@entry=0x0,
use_autoload=use_autoload@entry=1) at
/home/leigh/php-src/Zend/zend_execute_API.c:851
#6 0x0000555555817293 in zim_Closure_bind (execute_data=<optimised
out>, return_value=0x7fffffffa450) at
/home/leigh/php-src/Zend/zend_closures.c:201
#7 0x000055555587375e in ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER () at
/home/leigh/php-src/Zend/zend_vm_execute.h:984
#8 execute_ex (ex=0x6262626261600000) at
/home/leigh/php-src/Zend/zend_vm_execute.h:55493
#9 0x0000555555875230 in zend_execute
(op_array=op_array@entry=0x7ffff7a7f2a0, return_value=0x0,
return_value@entry=0x7ffff7a1d030) at
/home/leigh/php-src/Zend/zend_vm_execute.h:60889
#10 0x00005555557f0239 in zend_execute_scripts (type=type@entry=8,
retval=0x7ffff7a1d030, retval@entry=0x0, file_count=file_count@entry=3)
at /home/leigh/php-src/Zend/zend.c:1568
#11 0x000055555578f440 in php_execute_script (primary_file=<optimised
out>) at /home/leigh/php-src/main/main.c:2639
#12 0x000055555587770e in do_cli (argc=2, argv=0x555555a96860) at
/home/leigh/php-src/sapi/cli/php_cli.c:997
#13 0x0000555555648bcd in main (argc=2, argv=0x555555a96860) at
/home/leigh/php-src/sapi/cli/php_cli.c:1389
--
Edit bug report at https://bugs.php.net/bug.php?id=78658&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=78658&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=78658&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=78658&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=78658&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=78658&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=78658&r=support
Expected behavior: https://bugs.php.net/fix.php?id=78658&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=78658&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=78658&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=78658&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=78658&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=78658&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=78658&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=78658&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=78658&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=78658&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=78658&r=mysqlcfg