Bug #80099 [NEW]: php_memnstr segfaults

From: Date: Sun, 13 Sep 2020 17:03:22 +0000
Subject: Bug #80099 [NEW]: php_memnstr segfaults
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-228992@lists.php.net to get a copy of this message
From:             alex dot mashin at gmail dot com
Operating system: Ubuntu 20.04
PHP version:      7.4.10
Package:          Program Execution
Bug Type:         Bug
Bug description:php_memnstr segfaults

Description:
------------
I am trying to improve a third-party PHP extension. I was trying to
split a comma-separated string with php_explode() but it caused a
segmentation fault.

I managed to find out that the segfault was caused by php_memnstr.

If its third parameter (delimiter length) is a plain number, or strlen(
ZSTR_VAL(needle) ), or even needle->len, there is no segfault.

However, if it is ZSTR_LEN(delimiter), as in php_memnstr, a segfault
happens. The delimiter is a properly initiated zend_string *, and its
ZSTR_LEN can be output with php_printf and looks correct.

It is interesting, that the segfaults seems to happen immediately: the
numerous php_prints calls above php_memnstr are not executed (as if the
compiler optimises something incorrectly).

Unfortunately, I was unable to make gdb work.

PHP 7.4.10 (cli) (built: Sep  9 2020 06:36:30) ( NTS )
Copyright (c) The PHP Group
Zend Engine v3.4.0, Copyright (c) Zend Technologies
    with Zend OPcache v7.4.10, Copyright (c), by Zend Technologies
    with Xdebug v2.9.6, Copyright (c) 2002-2020, by Derick Rethans


Test script:
---------------
zend_string * haystack;
haystack = zend_string_init( "1,2,3", 5, 0 );

zend_string * needle;
needle = zend_string_init( ",", 1, 0 );

// Works:
const char *p = php_memnstr(ZSTR_VAL(haystack), ZSTR_VAL(needle), 1,
ZSTR_VAL(haustack) + ZSTR_LEN(haystack) );

// Also works:
const char *p = php_memnstr(ZSTR_VAL(haystack), ZSTR_VAL(needle),
strlen( ZSTR_VAL(needle) ), ZSTR_VAL(haustack) + ZSTR_LEN(haystack) );

// Even this works:
const char *p = php_memnstr(ZSTR_VAL(haystack), ZSTR_VAL(needle),
needle->len, ZSTR_VAL(haustack) + ZSTR_LEN(haystack) );

// Segfaults:
const char *p = php_memnstr(ZSTR_VAL(haystack), ZSTR_VAL(needle),
ZSTR_LEN(needle), ZSTR_VAL(haustack) + ZSTR_LEN(haystack) );


-- 
Edit bug report at https://bugs.php.net/bug.php?id=80099&edit=1
-- 
Fix committed:                    https://bugs.php.net/fix.php?id=80099&r=fixed
Fixed in release:                 https://bugs.php.net/fix.php?id=80099&r=alreadyfixed
Need backtrace:                   https://bugs.php.net/fix.php?id=80099&r=needtrace
Need Reproduce Script:            https://bugs.php.net/fix.php?id=80099&r=needscript
Try newer version:                https://bugs.php.net/fix.php?id=80099&r=oldversion
Not developer issue:              https://bugs.php.net/fix.php?id=80099&r=support
Expected behavior:                https://bugs.php.net/fix.php?id=80099&r=notwrong
Not enough info:                  https://bugs.php.net/fix.php?id=80099&r=notenoughinfo
Submitted twice:                  https://bugs.php.net/fix.php?id=80099&r=submittedtwice
register_globals:                 https://bugs.php.net/fix.php?id=80099&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=80099&r=phptooold
Daylight Savings:                 https://bugs.php.net/fix.php?id=80099&r=dst
IIS Stability:                    https://bugs.php.net/fix.php?id=80099&r=isapi
Install GNU Sed:                  https://bugs.php.net/fix.php?id=80099&r=gnused
Floating point limitations:       https://bugs.php.net/fix.php?id=80099&r=float
No Zend Extensions:               https://bugs.php.net/fix.php?id=80099&r=nozend
MySQL Configuration Error:        https://bugs.php.net/fix.php?id=80099&r=mysqlcfg


Thread (3 messages)

« previous php.bugs (#228992) next »