[php-src] Issue #12508: Potential memory leak in addslashes
| From: | oleg-andreyev | Date: | Tue, 24 Oct 2023 12:21:40 +0000 |
| Subject: | [php-src] Issue #12508: Potential memory leak in addslashes | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-245633@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/12508
Author: oleg-andreyev
### Description
The following code:
No leak
```php
<?php
function encode() {
return addslashes('stdClass');
}
function decode(string $str) {
return stripslashes($str);
}
for ($ctr = 0; $ctr < 1_000_000; $ctr++) {
$php = encode();
decode($php);
}
```
Resulted in this output:
https://gist.github.com/oleg-andreyev/0cb275e5945061f00560f0fe07a7e068
**Potential memory leak**
```php
function encode() {
return addslashes('\stdClass');
}
function decode(string $str) {
return stripslashes($str);
}
for ($ctr = 0; $ctr < 1_000_000; $ctr++) {
$php = encode();
decode($php);
}
```
Resulted in this output:
https://gist.github.com/oleg-andreyev/bd85f9441e1b12e603a8592553d6ec69

As you can see (first example):
encode and decode functions are using 0 because there is no slash in
string
but in second example (the only difference in slash) from total allocated bytes, 0 is free
### PHP Version
8.1.22
### Operating System
Alpine Linux v3.18