Bug #81622 [NEW]: Read segmentation fault in zend_jit_helpers.c:360:20
| From: | swirsz at gmail dot com | Date: | Mon, 15 Nov 2021 02:00:49 +0000 |
| Subject: | Bug #81622 [NEW]: Read segmentation fault in zend_jit_helpers.c:360:20 | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-237757@lists.php.net to get a copy of this message | ||
From: swirsz at gmail dot com
Operating system: Ubuntu 20.04
PHP version: master-Git-2021-11-15 (Git)
Package: Scripting Engine problem
Bug Type: Bug
Bug description:Read segmentation fault in zend_jit_helpers.c:360:20
Description:
------------
Compiled with address sanitizer, reproducible by executing
php-fuzz-function-jit with the test script
==100149==ERROR: AddressSanitizer: SEGV on unknown address
0x000188396212 (pc 0x7eff82389697 bp 0x7ffc52ca1c00 sp 0x7ffc52ca1b20
T0)
==100149==The signal is caused by a READ memory access.
SUMMARY: AddressSanitizer: SEGV
/php/ext/opcache/jit/zend_jit_helpers.c:360:20 in
zend_jit_undefined_op_helper_write
==100149==ABORTING
Test script:
---------------
<?php
set_error_handler(function($_, $m){
throw new Exception($m);
});
function test() {
$Ãa = [];
$res = $a[$undef] += 1;
}
try {
test();
} catch (Exception $e) {
echo $e->getMessage(), "\n";
}
?>
Actual result:
--------------
#0 0x7fc87a889697 in zend_jit_undefined_op_helper_write
/src/php-src/ext/opcache/jit/zend_jit_helpers.c:360:20
#1 0x7fc87a889697 in zend_jit_fetch_dim_rw_helper
/src/php-src/ext/opcache/jit/zend_jit_helpers.c:586:9
#2 0x49a88237 (/dev/zero (deleted)+0x8001237)
#3 0xf17bab in zend_execute
/src/php-src/Zend/zend_vm_execute.h:59037:2
#4 0x12da9ad in fuzzer_do_request_from_buffer
/src/php-src/sapi/fuzzer/fuzzer-sapi.c:276:5
#5 0x12d9093 in LLVMFuzzerTestOneInput
/src/php-src/sapi/fuzzer/fuzzer-function-jit.c:42:3
#6 0x639823 in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*,
unsigned long) cxa_noexception.cpp
#7 0x625132 in fuzzer::RunOneTest(fuzzer::Fuzzer*, char const*,
unsigned long)
/src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:324:6
#8 0x62abfa in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned
char const*, unsigned long)) cxa_noexception.cpp
#9 0x653b22 in main
/src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10
#10 0x7fc87c2e30b2 in __libc_start_main
/build/glibc-eX1tMB/glibc-2.31/csu/../csu/libc-start.c:308:16
--
Edit bug report at https://bugs.php.net/bug.php?id=81622&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=81622&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=81622&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=81622&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=81622&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=81622&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=81622&r=support
Expected behavior: https://bugs.php.net/fix.php?id=81622&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=81622&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=81622&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=81622&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=81622&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=81622&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=81622&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=81622&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=81622&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=81622&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=81622&r=mysqlcfg