Bug #79781 [NEW]: zend_mm_heap corrupted in zend_array_destroy

From: Date: Sat, 04 Jul 2020 00:37:05 +0000
Subject: Bug #79781 [NEW]: zend_mm_heap corrupted in zend_array_destroy
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-227801@lists.php.net to get a copy of this message
From: changochen1 at gmail dot com Operating system: PHP version: 8.0Git-2020-07-04 (Git) Package: Scripting Engine problem Bug Type: Bug Bug description:zend_mm_heap corrupted in zend_array_destroy Description: ------------ Cmdline: php -f poc Stack dump: --- Fatal error: Allowed memory size of 134217728 bytes exhausted at /home/yongheng/php_clean/Zend/zend_hash.c:2104 (tried to allocate 320 bytes) in /home/yongheng/php_poc5.php on line 2 zend_mm_heap corrupted MemorySanitizer:DEADLYSIGNAL ==230806==ERROR: MemorySanitizer: SEGV on unknown address 0x03e900038596 (pc 0x7fbc7c66d187 bp 0x000001e00000 sp 0x7ffc089355c8 T230806) ==230806==The signal is caused by a READ memory access. #0 0x7fbc7c66d186 in kill /build/glibc-OTsEL5/glibc-2.27/signal/../sysdeps/unix/syscall-template.S:78 #1 0x120f077 in zend_mm_panic /home/yongheng/php_clean/Zend/zend_alloc.c:364:2 #2 0x121628a in zend_mm_free_heap /home/yongheng/php_clean/Zend/zend_alloc.c #3 0x13e29a8 in zend_array_destroy /home/yongheng/php_clean/Zend/zend_hash.c:1660:2 #4 0x174fdeb in zend_objects_store_free_object_storage /home/yongheng/php_clean/Zend/zend_objects_API.c:117:6 #5 0x13246c0 in shutdown_executor /home/yongheng/php_clean/Zend/zend_execute_API.c:338:2 #6 0x137edc3 in zend_deactivate /home/yongheng/php_clean/Zend/zend.c:1206:2 #7 0x10e6c13 in php_request_shutdown /home/yongheng/php_clean/main/main.c:1876:2 #8 0x177a53d in do_cli /home/yongheng/php_clean/sapi/cli/php_cli.c:1127:3 #9 0x1779b7f in main /home/yongheng/php_clean/sapi/cli/php_cli.c:1357:18 #10 0x7fbc7c64fb96 in __libc_start_main /build/glibc-OTsEL5/glibc-2.27/csu/../csu/libc-start.c:310 #11 0x43f8c9 in _start (/home/yongheng/php_clean/bld/sapi/cli/php+0x43f8c9) MemorySanitizer can not provide additional info. SUMMARY: MemorySanitizer: SEGV /build/glibc-OTsEL5/glibc-2.27/signal/../sysdeps/unix/syscall-template.S:78 in kill ==230806==ABORTING ... --- Test script: --------------- <? a () ; function a () { a ( new ArrayIterator ( [ 1 ] ) ) ; } -- Edit bug report at https://bugs.php.net/bug.php?id=79781&edit=1 -- Fix committed: https://bugs.php.net/fix.php?id=79781&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=79781&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=79781&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=79781&r=needscript Try newer version: https://bugs.php.net/fix.php?id=79781&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=79781&r=support Expected behavior: https://bugs.php.net/fix.php?id=79781&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=79781&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=79781&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=79781&r=globals PHP version support discontinued: https://bugs.php.net/fix.php?id=79781&r=phptooold Daylight Savings: https://bugs.php.net/fix.php?id=79781&r=dst IIS Stability: https://bugs.php.net/fix.php?id=79781&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=79781&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=79781&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=79781&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=79781&r=mysqlcfg

« previous php.bugs (#227801) next »