Bug #79259 [Ver]: Segfault in php_array_element_dump
| From: | nikic@php.net | Date: | Wed, 12 Feb 2020 09:19:33 +0000 |
| Subject: | Bug #79259 [Ver]: Segfault in php_array_element_dump | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-225522@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79259&edit=1
ID: 79259
Updated by: nikic@php.net
Reported by: changochen1 at gmail dot com
Summary: Segfault in php_array_element_dump
Status: Verified
Type: Bug
Package: Scripting Engine problem
Operating System: ALL
PHP Version: master-Git-2020-02-11 (Git)
Block user comment: N
Private report: N
New Comment:
Just increasing the refcount while dumping should probably work? We do things like that in various
recursive walks due to issues like this.
Previous Comments:
------------------------------------------------------------------------
[2020-02-12 06:40:56] laruence@php.net
this is simply because the dumping array is resized(reallocaed).
a simple reproduced script is:
$obj = range(0, 5);
ob_start ( function ( $name ) { $GLOBALS[] = &$obj; } , 1 ) ;
var_dump ( $GLOBALS) ;
I am not sure how to fix this with a reasonable cost
------------------------------------------------------------------------
[2020-02-11 17:15:35] changochen1 at gmail dot com
Description:
------------
Segfault in php_array_element_dump.
PHP version:
```
PHP 8.0.0-dev (cli) (built: Jan 31 2020 21:52:09) ( NTS )
```
Run script:
```
php -f poc.php
```
Stack dump:
```
=================================================================
==301720==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000014 (pc 0x000000bc05f1 bp
0x7ffcdd24dec0 sp 0x7ffcdd24dea0 T0)
#0 0xbc05f0 in php_array_element_dump (/home/rxz226/php-src/bld_asan/sapi/cli/php+0xbc05f0)
#1 0xbc12df in php_var_dump (/home/rxz226/php-src/bld_asan/sapi/cli/php+0xbc12df)
#2 0xbc062a in php_array_element_dump (/home/rxz226/php-src/bld_asan/sapi/cli/php+0xbc062a)
#3 0xbc12df in php_var_dump (/home/rxz226/php-src/bld_asan/sapi/cli/php+0xbc12df)
#4 0xbc2184 in zif_var_dump (/home/rxz226/php-src/bld_asan/sapi/cli/php+0xbc2184)
#5 0x123b7e9 in execute_ex (/home/rxz226/php-src/bld_asan/sapi/cli/php+0x123b7e9)
#6 0x127aab7 in zend_execute (/home/rxz226/php-src/bld_asan/sapi/cli/php+0x127aab7)
#7 0xe43dfb in zend_execute_scripts (/home/rxz226/php-src/bld_asan/sapi/cli/php+0xe43dfb)
#8 0xcab3b7 in php_execute_script (/home/rxz226/php-src/bld_asan/sapi/cli/php+0xcab3b7)
#9 0x1280971 in do_cli (/home/rxz226/php-src/bld_asan/sapi/cli/php+0x1280971)
#10 0x1282acb in main (/home/rxz226/php-src/bld_asan/sapi/cli/php+0x1282acb)
#11 0x7f55f1ee282f in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x2082f)
#12 0x428a78 in _start (/home/rxz226/php-src/bld_asan/sapi/cli/php+0x428a78)
AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV ??:0 php_array_element_dump
```
Test script:
---------------
<?php
$strings = array ( 'into' , 'info' , 'inf' , 'infinity' ,
'infin' , 'inflammable' ) ;
foreach ( $strings as $v ) { var_dump ( [ ++ $GLOBALS ] ) ;
$a [ $b = 0 ] [ ] [ 2 ] ++ ;
unset ( $GLOBALS [ is_subclass_of ( ob_start ( function ( $name ) { $GLOBALS [ ] = &
$obj ;
var_dump ( $name ) ;
}
, 1 ) , 'dooh' ) [ ++ $i ] ] ) ;
}
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79259&edit=1