Bug #78830 [Opn->Wfx]: Infinite recursion crash

From: Date: Tue, 19 Nov 2019 08:52:16 +0000
Subject: Bug #78830 [Opn->Wfx]: Infinite recursion crash
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223793@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78830&edit=1 ID: 78830 Updated by: cmb@php.net Reported by: syjzwjj at gmail dot com -Summary: php +Summary: Infinite recursion crash -Status: Open +Status: Wont fix Type: Bug Package: Class/Object related Operating System: linux PHP Version: 7.3.11 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: > […] the engine should do the job of checking whether the engine > are in infinite recursion. PHP doesn't do this for performance reasons[1]. During development, Xdebug can be used to catch such issues[2]. [1] <https://www.php.net/manual/en/functions.user-defined.php> [2] <https://xdebug.org/docs/basic> Previous Comments: ------------------------------------------------------------------------ [2019-11-18 22:29:53] stas@php.net This looks like regular stack overflow driven by endless loop. ------------------------------------------------------------------------ [2019-11-18 16:39:55] syjzwjj at gmail dot com I don't think so. Firstly, the code you describe can't lead the interpreter crash, both for php engine and php engine, the engine should do the job of checking whether the engine are in infinite recursion. You can check the code of the js engine like chakra, webkit or v8, the engine itself must handle the problem. Secondly, if you think the poc can only cause the engine crash, then you should't assign https://bugs.php.net/bug.php?id=77020 for a cve, because it just a null pointer, which can't cause any effect for the system, but why you still assign a number for it ? ------------------------------------------------------------------------ [2019-11-18 16:15:35] cmb@php.net This is not related to inheritance, but rather to the fact that the code creates a new instance in the destructor of the class, which is then immediately destroyed, causing infinite recursion, resulting in a stack overflow. In my opinion, this is not a bug in PHP (let alone a security issue), but rather a userland programming error, similar to function foo() { foo(); } ------------------------------------------------------------------------ [2019-11-18 13:15:38] syjzwjj at gmail dot com php 7.1.33 and 7.2.24 also has this issue, so the main stable version are all affected. ------------------------------------------------------------------------ [2019-11-18 12:22:46] syjzwjj at gmail dot com This issue was report by Hillstone Network Neuron security team He yisheng and Zhang WangJunJie. Please assign a cve number for it when it finish, thank you ! ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=78830 -- Edit this bug report at https://bugs.php.net/bug.php?id=78830&edit=1

« previous php.bugs (#223793) next »