[php-src] Issue #11187: segfault while `__unserialize()`
| From: | staabm | Date: | Thu, 04 May 2023 11:53:48 +0000 |
| Subject: | [php-src] Issue #11187: segfault while `__unserialize()` | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-244370@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/11187
Author: staabm
### Description
I had a already started session and let php unserialize a object of the following class:
```php
<?php
namespace ClxProductNet\PriceSwitch\Model;
use ClxProductNet_SessionNS;
final class PriceSwitchSession implements \Serializable
{
// php 7.x serialization
public function serialize()
{
return serialize($this->__serialize());
}
// php 7.x serialization
public function unserialize($data): void
{
$this->__unserialize(unserialize($data));
}
// php 8.1+ serialization
public function __unserialize(string $data): void /* <-- wrong data-type */
{
}
}
```
Resulted in this output:
- segmentation fault
But I expected this output instead:
- regular fatal error
the segfault goes away when I change the type of the parameter given to
__unserialize
from string to array.
array is of course the correct type, but a wrong type should not lead to a segfault
```
php -v
PHP 8.1.18 (cli) (built: Apr 14 2023 04:39:44) (NTS)
Copyright (c) The PHP Group
Zend Engine v4.1.18, Copyright (c) Zend Technologies
```
### PHP Version
8.1.18
### Operating System
Ubuntu22