Bug #79836 [NEW]: Segfault in concat_function

From: Date: Sat, 11 Jul 2020 20:14:00 +0000
Subject: Bug #79836 [NEW]: Segfault in concat_function
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-227969@lists.php.net to get a copy of this message
From:             changochen1 at gmail dot com
Operating system: 
PHP version:      8.0Git-2020-07-11 (Git)
Package:          Scripting Engine problem
Bug Type:         Bug
Bug description:Segfault in concat_function

Description:
------------
Stack dump:
---
MemorySanitizer:DEADLYSIGNAL
==167862==ERROR: MemorySanitizer: SEGV on unknown address 0x000000000010
(pc 0x000001367a21 bp 0x000000000000 sp 0x7fffd3643eb0 T167862)
==167862==The signal is caused by a READ memory access.
==167862==Hint: address points to the zero page.
    #0 0x1367a20 in concat_function
/home/yongheng/php_clean/Zend/zend_operators.c:1847:6
    #1 0x14c91a9 in zend_binary_op
/home/yongheng/php_clean/Zend/zend_execute.c:1290:9
    #2 0x14c91a9 in ZEND_ASSIGN_OP_SPEC_CV_TMPVAR_HANDLER
/home/yongheng/php_clean/Zend/zend_vm_execute.h:41337
    #3 0x14307ff in execute_ex
/home/yongheng/php_clean/Zend/zend_vm_execute.h:52020:7
    #4 0x1334451 in zend_call_function
/home/yongheng/php_clean/Zend/zend_execute_API.c:785:3
    #5 0xe760d2 in zif_array_map
/home/yongheng/php_clean/ext/standard/array.c:6061:10
    #6 0x15dbed2 in ZEND_DO_ICALL_SPEC_RETVAL_UNUSED_HANDLER
/home/yongheng/php_clean/Zend/zend_vm_execute.h:1226:2
    #7 0x14307ff in execute_ex
/home/yongheng/php_clean/Zend/zend_vm_execute.h:52020:7
    #8 0x1431214 in zend_execute
/home/yongheng/php_clean/Zend/zend_vm_execute.h:56362:2
    #9 0x138d418 in zend_execute_scripts
/home/yongheng/php_clean/Zend/zend.c:1667:4
    #10 0x10f0cf9 in php_execute_script
/home/yongheng/php_clean/main/main.c:2537:14
    #11 0x179c8af in do_cli
/home/yongheng/php_clean/sapi/cli/php_cli.c:951:5
    #12 0x1798c9f in main
/home/yongheng/php_clean/sapi/cli/php_cli.c:1349:18
    #13 0x7f9d81a3bb96 in __libc_start_main
/build/glibc-OTsEL5/glibc-2.27/csu/../csu/libc-start.c:310
    #14 0x43fa49 in _start
(/home/yongheng/php_clean/bld/sapi/cli/php+0x43fa49)

MemorySanitizer can not provide additional info.
SUMMARY: MemorySanitizer: SEGV
/home/yongheng/php_clean/Zend/zend_operators.c:1847:6 in
concat_function
==167862==ABORTING
---

Test script:
---------------
<?
for ( ; $b < 8 ; ob_start ( function () use ( & $c ) { $c = $d ;}, 1 )
)
    str_replace ( $e , 0 , 'x' , $a  [ ++ $b ] ) ;
array_map ( function () use ( & $c ) {
    $c .= debug_backtrace () ;
}, $a );


-- 
Edit bug report at https://bugs.php.net/bug.php?id=79836&edit=1
-- 
Fix committed:                    https://bugs.php.net/fix.php?id=79836&r=fixed
Fixed in release:                 https://bugs.php.net/fix.php?id=79836&r=alreadyfixed
Need backtrace:                   https://bugs.php.net/fix.php?id=79836&r=needtrace
Need Reproduce Script:            https://bugs.php.net/fix.php?id=79836&r=needscript
Try newer version:                https://bugs.php.net/fix.php?id=79836&r=oldversion
Not developer issue:              https://bugs.php.net/fix.php?id=79836&r=support
Expected behavior:                https://bugs.php.net/fix.php?id=79836&r=notwrong
Not enough info:                  https://bugs.php.net/fix.php?id=79836&r=notenoughinfo
Submitted twice:                  https://bugs.php.net/fix.php?id=79836&r=submittedtwice
register_globals:                 https://bugs.php.net/fix.php?id=79836&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=79836&r=phptooold
Daylight Savings:                 https://bugs.php.net/fix.php?id=79836&r=dst
IIS Stability:                    https://bugs.php.net/fix.php?id=79836&r=isapi
Install GNU Sed:                  https://bugs.php.net/fix.php?id=79836&r=gnused
Floating point limitations:       https://bugs.php.net/fix.php?id=79836&r=float
No Zend Extensions:               https://bugs.php.net/fix.php?id=79836&r=nozend
MySQL Configuration Error:        https://bugs.php.net/fix.php?id=79836&r=mysqlcfg


Thread (2 messages)

« previous php.bugs (#227969) next »