Bug #79259 [Opn->Ver]: Segfault in php_array_element_dump

From: Date: Wed, 12 Feb 2020 06:40:56 +0000
Subject: Bug #79259 [Opn->Ver]: Segfault in php_array_element_dump
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-225516@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79259&edit=1 ID: 79259 Updated by: laruence@php.net Reported by: changochen1 at gmail dot com Summary: Segfault in php_array_element_dump -Status: Open +Status: Verified Type: Bug Package: Scripting Engine problem Operating System: ALL PHP Version: master-Git-2020-02-11 (Git) Block user comment: N Private report: N New Comment: this is simply because the dumping array is resized(reallocaed). a simple reproduced script is: $obj = range(0, 5); ob_start ( function ( $name ) { $GLOBALS[] = &$obj; } , 1 ) ; var_dump ( $GLOBALS) ; I am not sure how to fix this with a reasonable cost Previous Comments: ------------------------------------------------------------------------ [2020-02-11 17:15:35] changochen1 at gmail dot com Description: ------------ Segfault in php_array_element_dump. PHP version: ``` PHP 8.0.0-dev (cli) (built: Jan 31 2020 21:52:09) ( NTS ) ``` Run script: ``` php -f poc.php ``` Stack dump: ``` ================================================================= ==301720==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000014 (pc 0x000000bc05f1 bp 0x7ffcdd24dec0 sp 0x7ffcdd24dea0 T0) #0 0xbc05f0 in php_array_element_dump (/home/rxz226/php-src/bld_asan/sapi/cli/php+0xbc05f0) #1 0xbc12df in php_var_dump (/home/rxz226/php-src/bld_asan/sapi/cli/php+0xbc12df) #2 0xbc062a in php_array_element_dump (/home/rxz226/php-src/bld_asan/sapi/cli/php+0xbc062a) #3 0xbc12df in php_var_dump (/home/rxz226/php-src/bld_asan/sapi/cli/php+0xbc12df) #4 0xbc2184 in zif_var_dump (/home/rxz226/php-src/bld_asan/sapi/cli/php+0xbc2184) #5 0x123b7e9 in execute_ex (/home/rxz226/php-src/bld_asan/sapi/cli/php+0x123b7e9) #6 0x127aab7 in zend_execute (/home/rxz226/php-src/bld_asan/sapi/cli/php+0x127aab7) #7 0xe43dfb in zend_execute_scripts (/home/rxz226/php-src/bld_asan/sapi/cli/php+0xe43dfb) #8 0xcab3b7 in php_execute_script (/home/rxz226/php-src/bld_asan/sapi/cli/php+0xcab3b7) #9 0x1280971 in do_cli (/home/rxz226/php-src/bld_asan/sapi/cli/php+0x1280971) #10 0x1282acb in main (/home/rxz226/php-src/bld_asan/sapi/cli/php+0x1282acb) #11 0x7f55f1ee282f in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x2082f) #12 0x428a78 in _start (/home/rxz226/php-src/bld_asan/sapi/cli/php+0x428a78) AddressSanitizer can not provide additional info. SUMMARY: AddressSanitizer: SEGV ??:0 php_array_element_dump ``` Test script: --------------- <?php $strings = array ( 'into' , 'info' , 'inf' , 'infinity' , 'infin' , 'inflammable' ) ; foreach ( $strings as $v ) { var_dump ( [ ++ $GLOBALS ] ) ; $a [ $b = 0 ] [ ] [ 2 ] ++ ; unset ( $GLOBALS [ is_subclass_of ( ob_start ( function ( $name ) { $GLOBALS [ ] = & $obj ; var_dump ( $name ) ; } , 1 ) , 'dooh' ) [ ++ $i ] ] ) ; } ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=79259&edit=1

« previous php.bugs (#225516) next »