Bug #81622 [NEW]: Read segmentation fault in zend_jit_helpers.c:360:20

From: Date: Mon, 15 Nov 2021 02:00:49 +0000
Subject: Bug #81622 [NEW]: Read segmentation fault in zend_jit_helpers.c:360:20
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-237757@lists.php.net to get a copy of this message
From: swirsz at gmail dot com Operating system: Ubuntu 20.04 PHP version: master-Git-2021-11-15 (Git) Package: Scripting Engine problem Bug Type: Bug Bug description:Read segmentation fault in zend_jit_helpers.c:360:20 Description: ------------ Compiled with address sanitizer, reproducible by executing php-fuzz-function-jit with the test script ==100149==ERROR: AddressSanitizer: SEGV on unknown address 0x000188396212 (pc 0x7eff82389697 bp 0x7ffc52ca1c00 sp 0x7ffc52ca1b20 T0) ==100149==The signal is caused by a READ memory access. SUMMARY: AddressSanitizer: SEGV /php/ext/opcache/jit/zend_jit_helpers.c:360:20 in zend_jit_undefined_op_helper_write ==100149==ABORTING Test script: --------------- <?php set_error_handler(function($_, $m){ throw new Exception($m); }); function test() { $Óa = []; $res = $a[$undef] += 1; } try { test(); } catch (Exception $e) { echo $e->getMessage(), "\n"; } ?> Actual result: -------------- #0 0x7fc87a889697 in zend_jit_undefined_op_helper_write /src/php-src/ext/opcache/jit/zend_jit_helpers.c:360:20 #1 0x7fc87a889697 in zend_jit_fetch_dim_rw_helper /src/php-src/ext/opcache/jit/zend_jit_helpers.c:586:9 #2 0x49a88237 (/dev/zero (deleted)+0x8001237) #3 0xf17bab in zend_execute /src/php-src/Zend/zend_vm_execute.h:59037:2 #4 0x12da9ad in fuzzer_do_request_from_buffer /src/php-src/sapi/fuzzer/fuzzer-sapi.c:276:5 #5 0x12d9093 in LLVMFuzzerTestOneInput /src/php-src/sapi/fuzzer/fuzzer-function-jit.c:42:3 #6 0x639823 in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) cxa_noexception.cpp #7 0x625132 in fuzzer::RunOneTest(fuzzer::Fuzzer*, char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:324:6 #8 0x62abfa in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) cxa_noexception.cpp #9 0x653b22 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 #10 0x7fc87c2e30b2 in __libc_start_main /build/glibc-eX1tMB/glibc-2.31/csu/../csu/libc-start.c:308:16 -- Edit bug report at https://bugs.php.net/bug.php?id=81622&edit=1 -- Fix committed: https://bugs.php.net/fix.php?id=81622&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=81622&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=81622&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=81622&r=needscript Try newer version: https://bugs.php.net/fix.php?id=81622&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=81622&r=support Expected behavior: https://bugs.php.net/fix.php?id=81622&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=81622&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=81622&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=81622&r=globals PHP version support discontinued: https://bugs.php.net/fix.php?id=81622&r=phptooold Daylight Savings: https://bugs.php.net/fix.php?id=81622&r=dst IIS Stability: https://bugs.php.net/fix.php?id=81622&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=81622&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=81622&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=81622&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=81622&r=mysqlcfg

« previous php.bugs (#237757) next »