Bug #79172 [Opn->Csd]: STRUCT_OFFSET() relies on undefined behavior

From: Date: Tue, 28 Jan 2020 08:20:10 +0000
Subject: Bug #79172 [Opn->Csd]: STRUCT_OFFSET() relies on undefined behavior
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-225182@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79172&edit=1 ID: 79172 Updated by: cmb@php.net Reported by: cmb@php.net Summary: STRUCT_OFFSET() relies on undefined behavior -Status: Open +Status: Closed Type: Bug Package: MySQLi related Operating System: * PHP Version: 7.2.27 Block user comment: N Private report: N New Comment: Automatic comment on behalf of cmbecker69@gmx.de Revision: http://git.php.net/?p=php-src.git;a=commit;h=412b476b7fb386c6aa04efb936881f5b2250ded9 Log: Fix #79172: STRUCT_OFFSET() relies on undefined behavior Previous Comments: ------------------------------------------------------------------------ [2020-01-27 16:01:59] nikic@php.net Not a security issue, this is a pattern understood by compilers. Of course it should use XtOffsetOf at least on 7.4. ------------------------------------------------------------------------ [2020-01-27 14:39:26] cmb@php.net Suggested patch: ext/mysqlnd/mysqlnd_portability.h | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/ext/mysqlnd/mysqlnd_portability.h b/ext/mysqlnd/mysqlnd_portability.h index 873f49b0cd..2064906193 100644 --- a/ext/mysqlnd/mysqlnd_portability.h +++ b/ext/mysqlnd/mysqlnd_portability.h @@ -15,7 +15,7 @@ This file is public domain and comes with NO WARRANTY of any kind */ /* Comes from global.h as OFFSET, renamed to STRUCT_OFFSET */ -#define STRUCT_OFFSET(t, f) ((size_t)(char *)&((t *)0)->f) +#define STRUCT_OFFSET(t, f) XtOffsetOf(t, f) #ifndef __attribute #if !defined(__GNUC__) ------------------------------------------------------------------------ [2020-01-27 14:39:03] cmb@php.net Description: ------------ The STRUCT_OFFSET() macro[1] evaluates to an expression which relies on undefined behavior (null pointer dereferencing). I'm not sure if that qualifies as security issue, but it is certainly a bug. <https://github.com/php/php-src/blob/php-7.2.27/ext/mysqlnd/mysqlnd_portability.h#L18> Test script: --------------- mysqli_connect($host, $user, $password, $database); ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=79172&edit=1

« previous php.bugs (#225182) next »