Bug #80173 [Opn->Csd]: Using return value of zend_assign_to_variable() is not safe
| From: | git@php.net | Date: | Fri, 02 Jul 2021 08:09:21 +0000 |
| Subject: | Bug #80173 [Opn->Csd]: Using return value of zend_assign_to_variable() is not safe | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-234751@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80173&edit=1
ID: 80173
Updated by: git@php.net
Reported by: nikic@php.net
Summary: Using return value of zend_assign_to_variable() is
not safe
-Status: Open
+Status: Closed
Type: Bug
Package: Scripting Engine problem
PHP Version: 7.4.11
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of nikic
Revision: https://github.com/php/php-src/commit/bdc60fa7da65d29ac603dd32f3824abf9e71f65f
Log: Fixed bug #80173
Previous Comments:
------------------------------------------------------------------------
[2020-10-02 10:33:27] nikic@php.net
Description:
------------
Reduced from oss-fuzz #25840:
<?php
$a = new stdClass;
$a->a =& $a;
var_dump($a->a = 0);
zend_assign_to_variable() returns variable_ptr, which might be destroyed by the assignment.
The root cause here is the same as in bug #80100, but the reproducer is more fundamental.
Probably the only way to address this is to add a separate version of zend_assign_to_variable() that
accepts a zval to copy the value into, and perform that copy before disposing garbage.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80173&edit=1