Bug #75128 [Opn->Csd]: Invalid write in zval_delref_p()
| From: | nikic@php.net | Date: | Fri, 02 Jul 2021 10:22:46 +0000 |
| Subject: | Bug #75128 [Opn->Csd]: Invalid write in zval_delref_p() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-234759@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75128&edit=1
ID: 75128
Updated by: nikic@php.net
Reported by: fumfi dot 255 at gmail dot com
Summary: Invalid write in zval_delref_p()
-Status: Open
+Status: Closed
Type: Bug
Package: Reproducible crash
Operating System: Ubuntu 16.04 x64
PHP Version: 7.1.8
-Assigned To:
+Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
This no longer reproduces, even after fixing the undefined constant issue.
Looking at the reproducer and the stack trace, this looks like an issue we had with hitting the
memory limit during a string reallocation, in which case refcount was not managed correctly. This
issue has since been fixed.
Previous Comments:
------------------------------------------------------------------------
[2017-09-02 03:56:21] laruence@php.net
this is an knew issue..... just don't have a good way to fix it yet
------------------------------------------------------------------------
[2017-08-28 08:52:34] fumfi dot 255 at gmail dot com
Description:
------------
After some fuzz testing I found a crashing test case.
Version: 7.18
Command: php php_iw_zval_delref_p.php
Faulting PHP script: https://frankowicz.me/storage/crashes/php_iw_zval_delref_p.txt
ASAN:
==32358==ERROR: AddressSanitizer: SEGV on unknown address 0x7ff1ff400000 (pc 0x0000017678cf bp
0x7ffc9544dc90 sp 0x7ffc9544daf0 T0)
==32358==The signal is caused by a WRITE memory access.
#0 0x17678ce in zval_delref_p XYZ/php-7.1.8/Zend/zend_types.h:838:9
#1 0x17678ce in i_zval_ptr_dtor XYZ/php-7.1.8/Zend/zend_variables.h:47
#2 0x17678ce in zend_unclean_zval_ptr_dtor XYZ/php-7.1.8/Zend/zend_execute_API.c:210
#3 0x1851027 in _zend_hash_del_el_ex XYZ/php-7.1.8/Zend/zend_hash.c:997:3
#4 0x1851027 in _zend_hash_del_el XYZ/php-7.1.8/Zend/zend_hash.c:1020
#5 0x1851027 in zend_hash_graceful_reverse_destroy XYZ/php-7.1.8/Zend/zend_hash.c:1476
#6 0x1767f89 in shutdown_executor XYZ/php-7.1.8/Zend/zend_execute_API.c:279:3
#7 0x17ce8ca in zend_deactivate XYZ/php-7.1.8/Zend/zend.c:999:2
#8 0x1564144 in php_request_shutdown XYZ/php-7.1.8/main/main.c:1877:2
#9 0x1c4215c in do_cli XYZ/php-7.1.8/sapi/cli/php_cli.c:1160:3
#10 0x1c418e5 in main XYZ/php-7.1.8/sapi/cli/php_cli.c:1381:18
#11 0x7ff20a65982f in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x2082f)
#12 0x43ac28 in _start (/usr/local/bin/php+0x43ac28)
AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV XYZ/php-7.1.8/Zend/zend_types.h:838:9 in zval_delref_p
==32358==ABORTING
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75128&edit=1