Bug #66783 [Opn->Ver]: Double free or corruption if appending DOMDocument to element

From: Date: Fri, 12 Mar 2021 14:51:38 +0000
Subject: Bug #66783 [Opn->Ver]: Double free or corruption if appending DOMDocument to element
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-232676@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66783&edit=1

 ID:                 66783
 Updated by:         cmb@php.net
 Reported by:        mfonda@php.net
 Summary:            Double free or corruption if appending DOMDocument
                     to element
-Status:             Open
+Status:             Verified
 Type:               Bug
 Package:            DOM XML related
 Operating System:   Linux
 PHP Version:        Irrelevant
-Assigned To:        
+Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

This use-after-free can easily be prevented, by following the DOM
standard, and not allowing that insertion in the first place.


Previous Comments:
------------------------------------------------------------------------
[2015-07-10 16:10:54] cmb@php.net

Related to bug #66551.

------------------------------------------------------------------------
[2014-02-27 17:10:39] krakjoe@php.net

https://bugs.php.net/bug.php?id=61797

It's because of that ... if anyone has input, I'm happy to patch it ...

------------------------------------------------------------------------
[2014-02-26 21:32:57] mfonda@php.net

Description:
------------
Occurs when attempting to append a DOMDocument to a node within the document.

Test script:
---------------
<?php
$dom = new DomDocument;
$dom->loadXML('<root></root>');
$e = $dom->createElement('e');
$e->appendChild($dom);

Actual result:
--------------
*** glibc detected *** php: double free or corruption (!prev): 0x0000000001bff0e0 ***
======= Backtrace: =========
/lib/x86_64-linux-gnu/libc.so.6(+0x7eb96)[0x7fbb1bf08b96]
/usr/lib/x86_64-linux-gnu/libxml2.so.2(xmlFreeDoc+0x169)[0x7fbb1c29cbb9]
php(php_libxml_decrement_doc_ref+0x35)[0x4a0b35]
php(dom_objects_free_storage+0x2f)[0x4c3d9f]
php(zend_objects_store_del_ref_by_handle_ex+0x257)[0x7088a7]
php(zend_objects_store_del_ref+0x13)[0x7088c3]
php(_zval_ptr_dtor+0x58)[0x6cff08]
php[0x6ecaf5]
php(zend_hash_reverse_apply+0x71)[0x6ee601]
php(shutdown_destructors+0x61)[0x6d0211]
php(zend_call_destructors+0x37)[0x6dfd07]
php(php_request_shutdown+0x385)[0x67e4f5]
php[0x78cc42]
php(main+0x531)[0x464ad1]
/lib/x86_64-linux-gnu/libc.so.6(__libc_start_main+0xed)[0x7fbb1beab76d]
php[0x464b5d]


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=66783&edit=1


Thread (6 messages)

« previous php.bugs (#232676) next »