Bug #79241 [Ver->Ana]: Segmentation fault on preg_match()

From: Date: Fri, 07 Feb 2020 15:19:44 +0000
Subject: Bug #79241 [Ver->Ana]: Segmentation fault on preg_match()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-225430@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79241&edit=1 ID: 79241 Updated by: nikic@php.net Reported by: ivan dot voskoboinyk at gmail dot com Summary: Segmentation fault on preg_match() -Status: Verified +Status: Analyzed Type: Bug Package: PCRE related Operating System: Ubuntu 19.04 PHP Version: 7.4.2 Block user comment: N Private report: N New Comment: Pretty sure this is due to the VALID_UTF8 optimization. We remember that the string is valid UTF-8, but we also need to verify that the offset is at a valid character boundary. Previous Comments: ------------------------------------------------------------------------ [2020-02-07 15:10:41] ivan dot voskoboinyk at gmail dot com Description: ------------ We had this bug on our production server happening on matching Regex on a unicode string decoded from JSON. I've taken the exact production code and removed everything that is not necessary for demonstrating the problem. Removing any other part from the snippet bellow fixes the crash. It seems the issue only appeared in PHP 7.4: https://3v4l.org/DqL76 Test script: --------------- // if "’" string is used directly without json_decode, // the issue does not reproduce $text = json_decode('"’"'); $pattern = '/\b/u'; // it has to be exact two calls to preg_match(), // with the second call offsetting after the tick symbol preg_match($pattern, $text, $matches, 0, 0); preg_match($pattern, $text, $matches, 0, 1); echo 'OK'; Expected result: ---------------- "OK" is output Actual result: -------------- Segmentation fault (core dumped) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=79241&edit=1

« previous php.bugs (#225430) next »