[php-src] Issue #10634: Lexing memory corruption
| From: | iluuu1994 | Date: | Mon, 20 Feb 2023 11:06:26 +0000 |
| Subject: | [php-src] Issue #10634: Lexing memory corruption | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-243755@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/10634
Author: iluuu1994
### Description
https://github.com/php/php-src/commit/f291d37a1a7d78e841f40a4410359548bc73de1b
The following code:
https://oss-fuzz.com/testcase-detail/6445949468934144
```php
<?php
$classlist = [
'A'=> 'class A { const HW = "this is A"; }',
'B'=> 'class B extends A { const HW = parent::HW." extended by B";
}',
'space1\C' => 'namespace space1; class C { const HW = "this is
space32769\C"; }',
'D' => 'class D { const HW = \space1\C::HW." extended by D"; }',
'trE' => 'trait trE { public static function getHW() { return parent::HW; }
}',
'E' => 'class E extends B { use trE; }',
'F' => 'class F { const HW = \space1\C::HW." extended by D"; }',
'trE' => 'trait trE { public static function getHW() { return parent::HW; }
}',
'E' => 'class E extends B { use trE; }',
'F' => 'class F { const XX = "this is F"; }',
'G' => 'class G extends F { const XX = parent::XX." extended by G";
public static function get_me($x = "got ".self::XX) { return $x; } }',
];
spl_autoload_register(function ($class) use ($classlist) {
if (isset($classlist[$class])) {
eval($classlist[$class]);
printf("D::HW = %s\n", D::HW);
} else {
die("Cannot autoload $class\n");
}
});
printf("B::HW = %s\n", B::HW);
printf("D::HW = %s\n", D::HW);
printf("E::getHW() = %s\n", E::getHW());
printf("G::get_me() = %s\n", G::get_me());
printf("G::get_me() = %s\n", G::get_me());
?>
```
Resulted in this output:
```
use-after-free
```
Another one:
oss-fuzz Issue 55793
```php
<?yyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyy&#
```
```
heap-buffer-overflow
```
But I expected this output instead:
```
```
### PHP Version
master
### Operating System
_No response_