Bug #80602 [PATCH]: Segfault when using DOMChildNode::before()

From: Date: Tue, 14 Jun 2022 17:06:35 +0000
Subject: Bug #80602 [PATCH]: Segfault when using DOMChildNode::before()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-241732@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80602&edit=1 ID: 80602 Patch added by: cmb@php.net Reported by: jules dot bernable at gmail dot com Summary: Segfault when using DOMChildNode::before() Status: Verified Type: Bug Package: DOM XML related Operating System: debian PHP Version: 8.0.0 Assigned To: beberlei Block user comment: N Private report: N New Comment: The following pull request has been associated: Patch Name: Fix bug #80602 On GitHub: https://github.com/php/php-src/pull/8729 Patch: https://github.com/php/php-src/pull/8729.patch Previous Comments: ------------------------------------------------------------------------ [2021-02-01 22:25:59] beberlei@php.net Confusingly, it segfaults with $target->before('bar', $doc->documentElement->firstChild, 'baz'); but it works with $target->before($doc->documentElement->firstChild, 'baz'); or even $target->before($doc->documentElement->firstChild); ------------------------------------------------------------------------ [2021-01-18 16:14:04] beberlei@php.net Confirmed, will take a look asap. ------------------------------------------------------------------------ [2021-01-18 16:05:28] nikic@php.net I believe this happens because https://github.com/php/php-src/blob/d340be0d3246542c1ae34d632f36510fb1792852/ext/dom/parentnode.c#L184 can free "newNode" according to libxml docs: > Add a new node to @parent, at the end of the child (or property) list merging adjacent TEXT > nodes (in which case @cur is freed) This seems like rather peculiar behavior, guess that it's necessary to handle text nodes in some other way that does not end up destroying them? ------------------------------------------------------------------------ [2021-01-06 20:34:13] jules dot bernable at gmail dot com Description: ------------ When calling DOMChildNode::before() on an element, if one of the parameters is a text node that is the previous sibling of that element, the program segfaults. Test script: --------------- <?php declare(strict_types=1); $doc = new \DOMDocument(); $doc->loadXML('<a>foo<last/></a>'); $target = $doc->documentElement->lastChild; $target->before('bar', $doc->documentElement->firstChild, 'baz'); echo $doc->saveXML($doc->documentElement); Expected result: ---------------- <a>barfoobaz<last/></a> Actual result: -------------- free(): double free detected in tcache 2 Aborted ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=80602&edit=1

« previous php.bugs (#241732) next »