Bug #81252 [Opn]: PDO_ODBC doesn't account for SQL_NO_TOTAL

From: Date: Tue, 13 Jul 2021 08:51:20 +0000
Subject: Bug #81252 [Opn]: PDO_ODBC doesn't account for SQL_NO_TOTAL
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234997@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81252&edit=1

 ID:                 81252
 Updated by:         cmb@php.net
 Reported by:        calvin at cmpct dot info
 Summary:            PDO_ODBC doesn't account for SQL_NO_TOTAL
 Status:             Open
 Type:               Bug
 Package:            PDO ODBC
 Operating System:   Fedora 34
 PHP Version:        7.4.21
-Assigned To:        
+Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

Hmm, seems there is also a memory leak (at least in case of
failure).


Previous Comments:
------------------------------------------------------------------------
[2021-07-12 16:40:28] calvin at cmpct dot info

Description:
------------
Similar to #80460 for procedural ODBC (which was fixed, though perhaps with not an ideal solution).
This will manifest as PDO_ODBC getting -4 as the length back from the driver, and blindly trying to
memcpy that length, crashing.

Test script:
---------------
https://gist.github.com/NattyNarwhal/e1209fc967b0f4dcdfba7d2405557077

Includes reproduction for Db2i.

Expected result:
----------------
object(stdClass)#3 (4) {
  ["ID"]=>
  &string(1) "1"
  ["Data1"]=>
  &string(20) "5char               "
  ["Data2"]=>
  &string(25) "xxxxxxxxxxxxxxxxxxx      "
  ["Data3"]=>
  &string(2) "19"
}

Actual result:
--------------
Program received signal SIGSEGV, Segmentation fault.
0x00007ffff77cbac6 in __memcpy_avx_unaligned_erms () from /lib64/libc.so.6
(gdb) where
#0  0x00007ffff77cbac6 in __memcpy_avx_unaligned_erms () from /lib64/libc.so.6
#1  0x00007fffe419a274 in memcpy (__len=18446744073709551612, __src=0x7ffff72010c0,
__dest=<optimized out>) at /usr/include/bits/string_fortified.h:29
#2  odbc_stmt_param_hook (stmt=<optimized out>, param=<optimized out>,
event_type=<optimized out>) at
/usr/src/debug/php-7.4.21-1.fc34.x86_64/ext/pdo_odbc/odbc_stmt.c:522
#3  0x00007fffe44b51ee in dispatch_param_event (event_type=PDO_PARAM_EVT_EXEC_POST,
stmt=0x7ffff7287000) at /usr/src/debug/php-7.4.21-1.fc34.x86_64/ext/pdo/pdo_stmt.c:179
#4  dispatch_param_event (stmt=0x7ffff7287000, event_type=PDO_PARAM_EVT_EXEC_POST) at
/usr/src/debug/php-7.4.21-1.fc34.x86_64/ext/pdo/pdo_stmt.c:160
#5  0x00007fffe44b5e6d in zim_PDOStatement_execute (execute_data=<optimized out>,
return_value=0x7fffffff9d10) at /usr/src/debug/php-7.4.21-1.fc34.x86_64/ext/pdo/pdo_stmt.c:520
#6  0x0000555555855e0b in ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER () at
/usr/src/debug/php-7.4.21-1.fc34.x86_64/Zend/zend_vm_execute.h:1618
#7  execute_ex (ex=0x7ffff72010f0) at
/usr/src/debug/php-7.4.21-1.fc34.x86_64/Zend/zend_vm_execute.h:53897
#8  0x00005555558583af in zend_execute (op_array=0x7ffff72812a0, return_value=0x0) at
/usr/src/debug/php-7.4.21-1.fc34.x86_64/Zend/zend_vm_execute.h:57993
#9  0x00005555557cf42c in zend_execute_scripts (type=type@entry=8, retval=0x7fffdc8695a0,
retval@entry=0x0, file_count=-148819936, file_count@entry=3) at
/usr/src/debug/php-7.4.21-1.fc34.x86_64/Zend/zend.c:1679
#10 0x000055555576cf88 in php_execute_script (primary_file=<optimized out>) at
/usr/src/debug/php-7.4.21-1.fc34.x86_64/main/main.c:2650
#11 0x000055555585a537 in do_cli (argc=2, argv=0x555555e21020) at
/usr/src/debug/php-7.4.21-1.fc34.x86_64/sapi/cli/php_cli.c:964
#12 0x000055555563c44b in main (argc=2, argv=0x555555e21020) at
/usr/src/debug/php-7.4.21-1.fc34.x86_64/sapi/cli/php_cli.c:1359


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=81252&edit=1


Thread (6 messages)

« previous php.bugs (#234997) next »