[php-src] Issue #8159: Apache / PHP segfaults (PHP 8.0 and 8.1, but also 7.4)
| From: | unix-world | Date: | Sat, 12 Mar 2022 10:42:13 +0000 |
| Subject: | [php-src] Issue #8159: Apache / PHP segfaults (PHP 8.0 and 8.1, but also 7.4) | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-240311@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/8159
Comment Author: unix-world
@devnexen I don't know why this ticket was closed without an answer.
More, this looks like a serious security issue to me.
In my opinion the bug I reported here is because of the new changes in the opcache, in PHP 7.4 / 8.0
and 8.1.
PHP 7.3 is working correctly, without this bug.
Somewhere in time it was fixed, but now appears that have come back.
https://bugzilla.redhat.com/show_bug.cgi?id=1314888
I am not a C expert, but this clear looks to me like a "use-after-free error" ...
And probabily is comming from this changed area:
In 7.3.33 the accel_activate method is called in ext/opcache/ZendAccelerator.c, line # 3156
https://github.com/php/php-src/blob/php-7.3.33/ext/opcache/ZendAccelerator.c#L3156
In 8.0.16 the accel_activate method is called in a completely different place:
ext/opcache/zend_accelerator_module.c, line # 507
https://github.com/php/php-src/blob/php-8.0.16/ext/opcache/zend_accelerator_module.c#L507
Please not that I included the PHP 7.4 in this discussion just to exclude the possibility this bug
have nothing to do with the opcache JIT (introduced only since 8.0) !
Thus, PHP 7.4 have no opcache JIT and still crashing because it uses a similar way of calling
accel_activate in ext/opcache/zend_accelerator_module.c just like PHP 8.0 and 8.1.