Bug #81619 [Com]: Read segmentation fault in zend_hash.c:54:7

From: Date: Fri, 23 Dec 2022 12:18:08 +0000
Subject: Bug #81619 [Com]: Read segmentation fault in zend_hash.c:54:7
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-243230@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81619&edit=1 ID: 81619 Comment by: barrykaau74 at gmail dot com Reported by: swirsz at gmail dot com Summary: Read segmentation fault in zend_hash.c:54:7 Status: Open Type: Bug Package: Scripting Engine problem Operating System: Ubuntu 20.04 PHP Version: master-Git-2021-11-12 (Git) Block user comment: N Private report: N New Comment: A commitment of appreciation is all together for sharing, I found a tremendous store of stimulating information here. A striking post, incredibly grateful and obliging that you will make on a very major level more posts like this one. (https://www.flying-together.net/)github.com Previous Comments: ------------------------------------------------------------------------ [2022-11-29 05:57:51] robesonldspj11 at gmail dot com I totally like your gave limits as the post you passed on has some uncommon information which is totally essential for me. A commitment of appreciation is all together for the data. I will endeavor to figure it out for extra. (https://www.acaeronet.net/)github.com ------------------------------------------------------------------------ [2022-03-03 11:58:16] fasdn132 at protonmail dot com Thanks https://altosaxo.net/products/the-grateful-a-mogaaaz-t-shirt-men https://altosaxo.net/products/robert-palmer-t-shirt-men https://altosaxo.net/products/superchunk-t-shirt-men https://altosaxo.net/products/unloco-t-shirt-men https://altosaxo.net/products/36-crazyfists-t-shirt-men ------------------------------------------------------------------------ [2022-03-03 11:56:16] agsj443 at protonmail dot com Thanks https://altosaxo.net/products/hands-off-gretel-t-shirt-men https://altosaxo.net/products/misthyrming-t-shirt-men https://altosaxo.net/products/sigue-sigue-sputnik-t-shirt-men https://altosaxo.net/products/teenage-bottlerocket-t-shirt-men ------------------------------------------------------------------------ [2022-03-03 11:55:36] mctyj4dd32 at protonmail dot com Thanks https://altosaxo.net/products/alphoenix-t-shirt-men https://altosaxo.net/products/invsn-t-shirt-men https://altosaxo.net/products/noumena-t-shirt-men https://altosaxo.net/products/onmyo-za-t-shirt-men https://altosaxo.net/products/the-buttertones-t-shirt-men ------------------------------------------------------------------------ [2021-11-12 21:39:58] swirsz at gmail dot com Description: ------------ Running OSS-FUZZ locally on the master branch of github. Compiled with address sanitizer, reproducible by executing php-fuzz-tracing-jit with the test script AddressSanitizer:DEADLYSIGNAL ================================================================= ==327001==ERROR: AddressSanitizer: SEGV on unknown address (pc 0x000000ebeee3 bp 0x7ffda218bb60 sp 0x7ffda218bb40 T0) ==327001==The signal is caused by a READ memory access. ==327001==Hint: this fault was caused by a dereference of a high value address (see register values below). Disassemble the provided pc to learn which register was used. AddressSanitizer can not provide additional info. SUMMARY: AddressSanitizer: SEGV /src/php-src/Zend/zend_hash.c:54:7 in _zend_is_inconsistent ==327001==ABORTING Test script: --------------- https://www.wirsz.com/script/crash-260.txt Expected result: ---------------- n/a Actual result: -------------- #0 0xebeee3 in _zend_is_inconsistent /src/php-src/Zend/zend_hash.c:54:7 #1 0xec6b82 in _zend_hash_add_or_update_i /src/php-src/Zend/zend_hash.c:749:2 #2 0xec6b05 in zend_hash_update /src/php-src/Zend/zend_hash.c:922:9 #3 0xfc47db in ZEND_ADD_ARRAY_ELEMENT_SPEC_TMP_TMPVAR_HANDLER /src/php-src/Zend/zend_vm_execute.h:20118:4 #4 0x12d9869 in fuzzer_execute_ex /src/php-src/sapi/fuzzer/fuzzer-execute-common.h:53:14 #5 0xf17bab in zend_execute /src/php-src/Zend/zend_vm_execute.h:59037:2 #6 0x12da9ad in fuzzer_do_request_from_buffer /src/php-src/sapi/fuzzer/fuzzer-sapi.c:276:5 #7 0x12d9005 in LLVMFuzzerTestOneInput /src/php-src/sapi/fuzzer/fuzzer-function-jit.c:34:2 #8 0x639823 in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long) cxa_noexception.cpp #9 0x625132 in fuzzer::RunOneTest(fuzzer::Fuzzer*, char const*, unsigned long) /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:324:6 #10 0x62abfa in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long)) cxa_noexception.cpp #11 0x653b22 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10 #12 0x7f69932480b2 in __libc_start_main /build/glibc-eX1tMB/glibc-2.31/csu/../csu/libc-start.c:308:16 #13 0x6023bd in _start (/home/sw/oss-fuzz-master/build/out/php/php-fuzz-function-jit+0x6023bd) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=81619&edit=1

« previous php.bugs (#243230) next »