[php-src] Issue #11295: preg_match with \m modifier has unexpected behavior

From: Date: Mon, 22 May 2023 13:45:49 +0000
Subject: [php-src] Issue #11295: preg_match with \m modifier has unexpected behavior
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-244503@lists.php.net to get a copy of this message
Issue: https://github.com/php/php-src/issues/11295 Author: Geompse ### Description The following code: ```php <?php var_dump(preg_match('#^a$#m','a'."\n".'b')); ``` Resulted in this output: ``` int(1) ``` But I expected this output instead: ``` false ``` There is no technical bug as the implementation is valid, but there is a fonctional bug as the developer is mislead. This can lead to security breaches because you might believe that some user input would be sanitize while it is not. Example : ```php <?php $_REQUEST['username'] = '%%%'."\n".'lol'; if(!preg_match('#^[a-z]+$#m',(string)($_REQUEST['username']??null))) die(); echo 'did not die'; ``` **I think it would be nice to throw a E_DEPRECATED when \m is used with preg_match** Note : the \m modifier is working as expected with preg_match_all ### PHP Version PHP 8.1.17 ### Operating System _No response_

« previous php.bugs (#244503) next »