Bug #78711 [NEW]: Refreshable PHP crash
| From: | songmingxuan at cert dot org dot cn | Date: | Mon, 21 Oct 2019 11:55:05 +0000 |
| Subject: | Bug #78711 [NEW]: Refreshable PHP crash | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-223339@lists.php.net to get a copy of this message | ||
From: songmingxuan at cert dot org dot cn
Operating system: #31~18.04.1-Ubuntu
PHP version: 7.4.0RC4
Package: Reproducible crash
Bug Type: Bug
Bug description:Refreshable PHP crash
Description:
------------
#/Desktop/fuzz_php/php-7.4.0beta4
#php test.php
Test script:
---------------
<?php
spl_autoload_register(function ($name) {
echo "IN: autoload($name)\n";
static $i = 0;
if ($i++ > 10) {
echo "-> Recursion detected - as expected.\n";
;
}
class_exists('UndefinedClass' . $i);
echo "OUT: autoload($name)\n";
});
var_dump(class_exists('UndefinedClass0'));
?>
Expected result:
----------------
I submitted it very seriously. haha~
;)
Actual result:
--------------
Program received signal SIGSEGV, Segmentation fault.
[----------------------------------registers-----------------------------------]
RAX: 0x0
RBX: 0x0
RCX: 0x106
RDX: 0x7fffff7ff0b8 --> 0x0
RSI: 0x555556bc74fa --> 0x696c61766e49007a ('z')
RDI: 0x1
RBP: 0x7ffff20be810 --> 0x0
RSP: 0x7fffff7feff0
RIP: 0x5555566e5768 (<zend_parse_parameters+8>: mov QWORD PTR
[rsp],rdx)
R8 : 0x555557176680 --> 0x0
R9 : 0x7fffff7ff270 --> 0x55555731af60 --> 0x55555718b620 --> 0x0
R10: 0x55555718e9f0 --> 0x0
R11: 0x7fffff7ff2e0 --> 0x7ffff20dedb0 --> 0x600000003
R12: 0x7fffff7ff280 --> 0x555557199560 --> 0x100000001
R13: 0x555557176708 --> 0x33f0
R14: 0x7ffff20be810 --> 0x0
R15: 0x555557199560 --> 0x100000001
EFLAGS: 0x10246 (carry PARITY adjust ZERO sign trap INTERRUPT direction
overflow)
[-------------------------------------code-------------------------------------]
0x5555566e5758 <zend_parse_parameters_ex+408>:
call 0x55555566c000 <__stack_chk_fail@plt>
0x5555566e575d: nop DWORD PTR [rax]
0x5555566e5760 <zend_parse_parameters>: lea rsp,[rsp-0x98]
=> 0x5555566e5768 <zend_parse_parameters+8>: mov QWORD PTR [rsp],rdx
0x5555566e576c <zend_parse_parameters+12>: mov QWORD PTR
[rsp+0x8],rcx
0x5555566e5771 <zend_parse_parameters+17>: mov QWORD PTR
[rsp+0x10],rax
0x5555566e5776 <zend_parse_parameters+22>: mov rcx,0x90bb
0x5555566e577d <zend_parse_parameters+29>:
call 0x5555566f0ff8 <__afl_maybe_log>
[------------------------------------stack-------------------------------------]
Invalid $SP address: 0x7fffff7feff0
[------------------------------------------------------------------------------]
Legend: code, data, rodata, value
Stopped reason: SIGSEGV
0x00005555566e5768 in zend_parse_parameters (num_args=0x1,
type_spec=0x555556bc74fa "z")
at /home/fuzz/Desktop/fuzz_php/php-7.4.0beta4/Zend/zend_API.c:1053
1053 {
gdb-peda$
--
Edit bug report at https://bugs.php.net/bug.php?id=78711&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=78711&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=78711&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=78711&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=78711&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=78711&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=78711&r=support
Expected behavior: https://bugs.php.net/fix.php?id=78711&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=78711&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=78711&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=78711&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=78711&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=78711&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=78711&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=78711&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=78711&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=78711&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=78711&r=mysqlcfg