Bug #81622 [Com]: Read segmentation fault in zend_jit_helpers.c:360:20
Edit report at https://bugs.php.net/bug.php?id=81622&edit=1
ID: 81622
Comment by: robertgnldspj11 at gmail dot com
Reported by: swirsz at gmail dot com
Summary: Read segmentation fault in zend_jit_helpers.c:360:20
Status: Open
Type: Bug
Package: Scripting Engine problem
Operating System: Ubuntu 20.04
PHP Version: master-Git-2021-11-15 (Git)
Block user comment: N
Private report: N
New Comment:
I can see a lot of interesting information. Thankful for the little by little useful exercise. Has
conclusively the ordinary impact! (https://www.mypayments.plus/)github.com
Previous Comments:
------------------------------------------------------------------------
[2022-03-03 12:01:50] hdf4gs43 at protonmail dot com
Thanks
https://altosaxo.net/products/lagerstein-t-shirt-men
https://altosaxo.net/products/batushka-t-shirt-men
https://altosaxo.net/products/deez-nuts-t-shirt-men
https://altosaxo.net/products/kontrust-t-shirt-men
https://altosaxo.net/products/deathspell-omega-t-shirt-men
------------------------------------------------------------------------
[2022-03-03 12:01:11] fasd2353 at protonmail dot com
thanks
https://altosaxo.net/products/gregory-alan-isakov-t-shirt-men
https://altosaxo.net/products/skalmold-t-shirt-men
https://altosaxo.net/products/the-olivia-tremor-control-t-shirt-men
https://altosaxo.net/products/vita-imana-t-shirt-men
https://altosaxo.net/products/def-leppard-1977-2022-t-shirt-men
------------------------------------------------------------------------
[2022-03-03 12:00:19] 44fasfasdf32 at protonmail dot com
thanks
https://altosaxo.net/products/ensiferum-t-shirt-men
https://altosaxo.net/products/svn-seeker-t-shirt-men
https://altosaxo.net/products/turisas-t-shirt-men
https://altosaxo.net/products/wolfheart-t-shirt-men
https://altosaxo.net/products/fate-gear-t-shirt-men
------------------------------------------------------------------------
[2021-11-15 02:00:49] swirsz at gmail dot com
Description:
------------
Compiled with address sanitizer, reproducible by executing php-fuzz-function-jit with the test
script
==100149==ERROR: AddressSanitizer: SEGV on unknown address 0x000188396212 (pc 0x7eff82389697 bp
0x7ffc52ca1c00 sp 0x7ffc52ca1b20 T0)
==100149==The signal is caused by a READ memory access.
SUMMARY: AddressSanitizer: SEGV /php/ext/opcache/jit/zend_jit_helpers.c:360:20 in
zend_jit_undefined_op_helper_write
==100149==ABORTING
Test script:
---------------
<?php
set_error_handler(function($_, $m){
throw new Exception($m);
});
function test() {
$Ãa = [];
$res = $a[$undef] += 1;
}
try {
test();
} catch (Exception $e) {
echo $e->getMessage(), "\n";
}
?>
Actual result:
--------------
#0 0x7fc87a889697 in zend_jit_undefined_op_helper_write
/src/php-src/ext/opcache/jit/zend_jit_helpers.c:360:20
#1 0x7fc87a889697 in zend_jit_fetch_dim_rw_helper
/src/php-src/ext/opcache/jit/zend_jit_helpers.c:586:9
#2 0x49a88237 (/dev/zero (deleted)+0x8001237)
#3 0xf17bab in zend_execute /src/php-src/Zend/zend_vm_execute.h:59037:2
#4 0x12da9ad in fuzzer_do_request_from_buffer /src/php-src/sapi/fuzzer/fuzzer-sapi.c:276:5
#5 0x12d9093 in LLVMFuzzerTestOneInput /src/php-src/sapi/fuzzer/fuzzer-function-jit.c:42:3
#6 0x639823 in fuzzer::Fuzzer::ExecuteCallback(unsigned char const*, unsigned long)
cxa_noexception.cpp
#7 0x625132 in fuzzer::RunOneTest(fuzzer::Fuzzer*, char const*, unsigned long)
/src/llvm-project/compiler-rt/lib/fuzzer/FuzzerDriver.cpp:324:6
#8 0x62abfa in fuzzer::FuzzerDriver(int*, char***, int (*)(unsigned char const*, unsigned long))
cxa_noexception.cpp
#9 0x653b22 in main /src/llvm-project/compiler-rt/lib/fuzzer/FuzzerMain.cpp:20:10
#10 0x7fc87c2e30b2 in __libc_start_main
/build/glibc-eX1tMB/glibc-2.31/csu/../csu/libc-start.c:308:16
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=81622&edit=1
Thread (7 messages)