Bug #80602 [PATCH]: Segfault when using DOMChildNode::before()
| From: | cmb@php.net | Date: | Tue, 14 Jun 2022 17:06:35 +0000 |
| Subject: | Bug #80602 [PATCH]: Segfault when using DOMChildNode::before() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-241732@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80602&edit=1
ID: 80602
Patch added by: cmb@php.net
Reported by: jules dot bernable at gmail dot com
Summary: Segfault when using DOMChildNode::before()
Status: Verified
Type: Bug
Package: DOM XML related
Operating System: debian
PHP Version: 8.0.0
Assigned To: beberlei
Block user comment: N
Private report: N
New Comment:
The following pull request has been associated:
Patch Name: Fix bug #80602
On GitHub: https://github.com/php/php-src/pull/8729
Patch: https://github.com/php/php-src/pull/8729.patch
Previous Comments:
------------------------------------------------------------------------
[2021-02-01 22:25:59] beberlei@php.net
Confusingly, it segfaults with $target->before('bar',
$doc->documentElement->firstChild, 'baz');
but it works with $target->before($doc->documentElement->firstChild, 'baz'); or
even $target->before($doc->documentElement->firstChild);
------------------------------------------------------------------------
[2021-01-18 16:14:04] beberlei@php.net
Confirmed, will take a look asap.
------------------------------------------------------------------------
[2021-01-18 16:05:28] nikic@php.net
I believe this happens because https://github.com/php/php-src/blob/d340be0d3246542c1ae34d632f36510fb1792852/ext/dom/parentnode.c#L184
can free "newNode" according to libxml docs:
> Add a new node to @parent, at the end of the child (or property) list merging adjacent TEXT
> nodes (in which case @cur is freed)
This seems like rather peculiar behavior, guess that it's necessary to handle text nodes in
some other way that does not end up destroying them?
------------------------------------------------------------------------
[2021-01-06 20:34:13] jules dot bernable at gmail dot com
Description:
------------
When calling DOMChildNode::before() on an element, if one of the parameters is a text node that is
the previous sibling of that element, the program segfaults.
Test script:
---------------
<?php declare(strict_types=1);
$doc = new \DOMDocument();
$doc->loadXML('<a>foo<last/></a>');
$target = $doc->documentElement->lastChild;
$target->before('bar', $doc->documentElement->firstChild, 'baz');
echo $doc->saveXML($doc->documentElement);
Expected result:
----------------
<a>barfoobaz<last/></a>
Actual result:
--------------
free(): double free detected in tcache 2
Aborted
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80602&edit=1