Bug #81009 [NEW]: PDO statement segfault on invalid param
| From: | theo dot fidry at gmail dot com | Date: | Mon, 03 May 2021 16:45:42 +0000 |
| Subject: | Bug #81009 [NEW]: PDO statement segfault on invalid param | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-233668@lists.php.net to get a copy of this message | ||
From: theo dot fidry at gmail dot com
Operating system: OSX 11.2.3
PHP version: 7.4.18
Package: PDO PgSQL
Bug Type: Bug
Bug description:PDO statement segfault on invalid param
Description:
------------
We have in our code the following statement (done via Doctrine):
```
$stmt->bindValue(6, null, 1);
```
coming from an entity property of the type
?int and for which the
corresponding DB column is a nullable integer (PostgreSQL 12.3).
When upgrading from PHP 7.4.13 to 7.4.18 the above statement results in
a segfault once executing the query.
changing the null value into an int value or keeping the value null
and changing the param type 1 to 0 both results in a successful
execution on 7.4.18.
The related Doctrie code is
https://github.com/doctrine/dbal/blob/2.13.x/lib/Doctrine/DBAL/Statement.php#L101-L121
as you can see it did not change in a log time and even if a failure is
expected with an invalid type, I suspect a segfault is not the desired
outcome.
Test script:
---------------
We are using the following except locally:
```
$kernel = new Kernel($_SERVER['APP_ENV'], (bool)
$_SERVER['APP_DEBUG']);
$kernel->boot();
/** @var PDOStatement $stmt */
$stmt = $kernel->getContainer()
->get('doctrine.dbal.default_connection')
->prepare('INSERT INTO foo (col1, col2, col3, col4, col5, col6,
col7) VALUES (?, ?, ?, ?, ?, ?, ?)');
$stmt->bindValue(1, 16527, 1);
$stmt->bindValue(2, 'ee3b3a2d-f01a-4455-a509-629bf2780ca6', 2);
$stmt->bindValue(3, '2021-05-03T16:09:31Z', 2);
$stmt->bindValue(4, 'certificationGranted', 2);
$stmt->bindValue(5, 'foo', 2);
$stmt->bindValue(6, null, 1);
$stmt->bindValue(7, '3e2456b7-49c2-46de-ad7d-1b3f4c1b5663', 2);
$stmt = $stmt->execute(null);
```
Expected result:
----------------
Not a segfault.
--
Edit bug report at https://bugs.php.net/bug.php?id=81009&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=81009&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=81009&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=81009&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=81009&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=81009&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=81009&r=support
Expected behavior: https://bugs.php.net/fix.php?id=81009&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=81009&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=81009&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=81009&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=81009&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=81009&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=81009&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=81009&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=81009&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=81009&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=81009&r=mysqlcfg