Bug #80186 [PATCH]: Segfault when iterating over FFI object

From: Date: Sun, 04 Oct 2020 20:56:27 +0000
Subject: Bug #80186 [PATCH]: Segfault when iterating over FFI object
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-229377@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80186&edit=1 ID: 80186 Patch added by: as@php.net Reported by: as@php.net Summary: Segfault when iterating over FFI object Status: Open Type: Bug Package: Reproducible crash PHP Version: 8.0Git-2020-10-04 (Git) Block user comment: N Private report: N New Comment: The following pull request has been associated: Patch Name: Fix #80186: Prevent segfault when iterating FFI obj props On GitHub: https://github.com/php/php-src/pull/6270 Patch: https://github.com/php/php-src/pull/6270.patch Previous Comments: ------------------------------------------------------------------------ [2020-10-04 20:40:56] as@php.net Description: ------------ Currently zend_fake_get_properties in ext/ffi/ffi.c returns a pointer to const HashTable zend_empty_array. Attempting to iterate over this array in userland leads to a segfault because PHP tries to increment zend_empty_array's nIteratorsCount which is const memory. The proposed patch allows objects to return NULL for the get_properties handler. In this case, the VM skips the foreach block. If this approach is acceptable, there are other extensions and call sites[1][2] to fix where zend_empty_array leaks into userland. [1] https://github.com/php/php-src/blob/107962208a19d8b6dc1a190cb25fc37614411e71/ext/com_dotnet/com_handlers.c#L221-L229 [2] https://github.com/protocolbuffers/protobuf/issues/7319 Test script: --------------- <?php $ffi = FFI::cdef(''); foreach ($ffi as $_) { } Expected result: ---------------- no segfault Actual result: -------------- segfault ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=80186&edit=1

« previous php.bugs (#229377) next »