Bug #79781 [NEW]: zend_mm_heap corrupted in zend_array_destroy
| From: | changochen1 at gmail dot com | Date: | Sat, 04 Jul 2020 00:37:05 +0000 |
| Subject: | Bug #79781 [NEW]: zend_mm_heap corrupted in zend_array_destroy | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-227801@lists.php.net to get a copy of this message | ||
From: changochen1 at gmail dot com
Operating system:
PHP version: 8.0Git-2020-07-04 (Git)
Package: Scripting Engine problem
Bug Type: Bug
Bug description:zend_mm_heap corrupted in zend_array_destroy
Description:
------------
Cmdline: php -f poc
Stack dump:
---
Fatal error: Allowed memory size of 134217728 bytes exhausted at
/home/yongheng/php_clean/Zend/zend_hash.c:2104 (tried to allocate 320
bytes) in /home/yongheng/php_poc5.php on line 2
zend_mm_heap corrupted
MemorySanitizer:DEADLYSIGNAL
==230806==ERROR: MemorySanitizer: SEGV on unknown address 0x03e900038596
(pc 0x7fbc7c66d187 bp 0x000001e00000 sp 0x7ffc089355c8 T230806)
==230806==The signal is caused by a READ memory access.
#0 0x7fbc7c66d186 in kill
/build/glibc-OTsEL5/glibc-2.27/signal/../sysdeps/unix/syscall-template.S:78
#1 0x120f077 in zend_mm_panic
/home/yongheng/php_clean/Zend/zend_alloc.c:364:2
#2 0x121628a in zend_mm_free_heap
/home/yongheng/php_clean/Zend/zend_alloc.c
#3 0x13e29a8 in zend_array_destroy
/home/yongheng/php_clean/Zend/zend_hash.c:1660:2
#4 0x174fdeb in zend_objects_store_free_object_storage
/home/yongheng/php_clean/Zend/zend_objects_API.c:117:6
#5 0x13246c0 in shutdown_executor
/home/yongheng/php_clean/Zend/zend_execute_API.c:338:2
#6 0x137edc3 in zend_deactivate
/home/yongheng/php_clean/Zend/zend.c:1206:2
#7 0x10e6c13 in php_request_shutdown
/home/yongheng/php_clean/main/main.c:1876:2
#8 0x177a53d in do_cli
/home/yongheng/php_clean/sapi/cli/php_cli.c:1127:3
#9 0x1779b7f in main
/home/yongheng/php_clean/sapi/cli/php_cli.c:1357:18
#10 0x7fbc7c64fb96 in __libc_start_main
/build/glibc-OTsEL5/glibc-2.27/csu/../csu/libc-start.c:310
#11 0x43f8c9 in _start
(/home/yongheng/php_clean/bld/sapi/cli/php+0x43f8c9)
MemorySanitizer can not provide additional info.
SUMMARY: MemorySanitizer: SEGV
/build/glibc-OTsEL5/glibc-2.27/signal/../sysdeps/unix/syscall-template.S:78
in kill
==230806==ABORTING
...
---
Test script:
---------------
<?
a () ;
function a () {
a ( new ArrayIterator ( [ 1 ] ) ) ;
}
--
Edit bug report at https://bugs.php.net/bug.php?id=79781&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=79781&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=79781&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=79781&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=79781&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=79781&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=79781&r=support
Expected behavior: https://bugs.php.net/fix.php?id=79781&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=79781&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=79781&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=79781&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=79781&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=79781&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=79781&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=79781&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=79781&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=79781&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=79781&r=mysqlcfg