[php-src] Issue #10634: Lexing memory corruption

From: Date: Mon, 20 Feb 2023 11:06:26 +0000
Subject: [php-src] Issue #10634: Lexing memory corruption
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-243755@lists.php.net to get a copy of this message
Issue: https://github.com/php/php-src/issues/10634 Author: iluuu1994 ### Description https://github.com/php/php-src/commit/f291d37a1a7d78e841f40a4410359548bc73de1b The following code: https://oss-fuzz.com/testcase-detail/6445949468934144 ```php <?php $classlist = [ 'A'=> 'class A { const HW = "this is A"; }', 'B'=> 'class B extends A { const HW = parent::HW." extended by B"; }', 'space1\C' => 'namespace space1; class C { const HW = "this is space32769\C"; }', 'D' => 'class D { const HW = \space1\C::HW." extended by D"; }', 'trE' => 'trait trE { public static function getHW() { return parent::HW; } }', 'E' => 'class E extends B { use trE; }', 'F' => 'class F { const HW = \space1\C::HW." extended by D"; }', 'trE' => 'trait trE { public static function getHW() { return parent::HW; } }', 'E' => 'class E extends B { use trE; }', 'F' => 'class F { const XX = "this is F"; }', 'G' => 'class G extends F { const XX = parent::XX." extended by G"; public static function get_me($x = "got ".self::XX) { return $x; } }', ]; spl_autoload_register(function ($class) use ($classlist) { if (isset($classlist[$class])) { eval($classlist[$class]); printf("D::HW = %s\n", D::HW); } else { die("Cannot autoload $class\n"); } }); printf("B::HW = %s\n", B::HW); printf("D::HW = %s\n", D::HW); printf("E::getHW() = %s\n", E::getHW()); printf("G::get_me() = %s\n", G::get_me()); printf("G::get_me() = %s\n", G::get_me()); ?> ``` Resulted in this output: ``` use-after-free ``` Another one: oss-fuzz Issue 55793 ```php <?yyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyy&# ``` ``` heap-buffer-overflow ``` But I expected this output instead: ``` ``` ### PHP Version master ### Operating System _No response_

« previous php.bugs (#243755) next »