Bug #75128 [Opn->Csd]: Invalid write in zval_delref_p()

From: Date: Fri, 02 Jul 2021 10:22:46 +0000
Subject: Bug #75128 [Opn->Csd]: Invalid write in zval_delref_p()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234759@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75128&edit=1 ID: 75128 Updated by: nikic@php.net Reported by: fumfi dot 255 at gmail dot com Summary: Invalid write in zval_delref_p() -Status: Open +Status: Closed Type: Bug Package: Reproducible crash Operating System: Ubuntu 16.04 x64 PHP Version: 7.1.8 -Assigned To: +Assigned To: nikic Block user comment: N Private report: N New Comment: This no longer reproduces, even after fixing the undefined constant issue. Looking at the reproducer and the stack trace, this looks like an issue we had with hitting the memory limit during a string reallocation, in which case refcount was not managed correctly. This issue has since been fixed. Previous Comments: ------------------------------------------------------------------------ [2017-09-02 03:56:21] laruence@php.net this is an knew issue..... just don't have a good way to fix it yet ------------------------------------------------------------------------ [2017-08-28 08:52:34] fumfi dot 255 at gmail dot com Description: ------------ After some fuzz testing I found a crashing test case. Version: 7.18 Command: php php_iw_zval_delref_p.php Faulting PHP script: https://frankowicz.me/storage/crashes/php_iw_zval_delref_p.txt ASAN: ==32358==ERROR: AddressSanitizer: SEGV on unknown address 0x7ff1ff400000 (pc 0x0000017678cf bp 0x7ffc9544dc90 sp 0x7ffc9544daf0 T0) ==32358==The signal is caused by a WRITE memory access. #0 0x17678ce in zval_delref_p XYZ/php-7.1.8/Zend/zend_types.h:838:9 #1 0x17678ce in i_zval_ptr_dtor XYZ/php-7.1.8/Zend/zend_variables.h:47 #2 0x17678ce in zend_unclean_zval_ptr_dtor XYZ/php-7.1.8/Zend/zend_execute_API.c:210 #3 0x1851027 in _zend_hash_del_el_ex XYZ/php-7.1.8/Zend/zend_hash.c:997:3 #4 0x1851027 in _zend_hash_del_el XYZ/php-7.1.8/Zend/zend_hash.c:1020 #5 0x1851027 in zend_hash_graceful_reverse_destroy XYZ/php-7.1.8/Zend/zend_hash.c:1476 #6 0x1767f89 in shutdown_executor XYZ/php-7.1.8/Zend/zend_execute_API.c:279:3 #7 0x17ce8ca in zend_deactivate XYZ/php-7.1.8/Zend/zend.c:999:2 #8 0x1564144 in php_request_shutdown XYZ/php-7.1.8/main/main.c:1877:2 #9 0x1c4215c in do_cli XYZ/php-7.1.8/sapi/cli/php_cli.c:1160:3 #10 0x1c418e5 in main XYZ/php-7.1.8/sapi/cli/php_cli.c:1381:18 #11 0x7ff20a65982f in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x2082f) #12 0x43ac28 in _start (/usr/local/bin/php+0x43ac28) AddressSanitizer can not provide additional info. SUMMARY: AddressSanitizer: SEGV XYZ/php-7.1.8/Zend/zend_types.h:838:9 in zval_delref_p ==32358==ABORTING ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=75128&edit=1

« previous php.bugs (#234759) next »