[php-src] Issue #13007: Segmentation fault in preg_match_all()
| From: | pk1234 | Date: | Sat, 23 Dec 2023 13:32:30 +0000 |
| Subject: | [php-src] Issue #13007: Segmentation fault in preg_match_all() | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-246109@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/13007
Author: pk1234
### Description
The following function:
```php
function get_bind_variables($sql){
$args=[];
$sql=preg_replace("/'[^']*'/", " ", $sql);
$sql=preg_replace('/"[^"]*"/', " ", $sql);
print "SQL=$sql\n";
preg_match_all("/q/", "sql", $match);
var_dump($match);
preg_match_all("/(?<=:)[0-9a-z_]+/i", $sql, $match);
var_dump($match);
foreach($match[0] as $v) $args[$v]=$v;
return $args;
}
```
is used in a very large php application that was upgraded from
php 5.6 to 8.2.7 lately. It detects bind-variables in SQL-statements.
Under some very rare conditions the application fails with SIGSEGV
and produces the follwoing output:
```
...
lots of SQL-Statements with correct var_dump()-output
...
SQL=select bsi_size, bsi_zeitpunkt_von, bsi_zeitpunkt_bis, bvo_basedir, bso_hostname from
ban_sicherungen, ban_volumes, ban_standorte where bsi_id = :1 and bvo_id = bsi_bvo_id and bso_id =
bvo_bso_id
array(1) {
[0]=>
array(1) {
[0]=>
string(1) "q"
}
}
array(1) {
[0]=>
array(1) {
[0]=>
string(1) "1"
}
}
SQL=select nvl(sum(trunc((bsi_size+131071)/131072)+1),0) bpos1, count(*)+1 pos from ban_inhalte,
ban_sicherungen where bih_ban_id = :1 and bsi_id = bih_bsi_id
array(1) {
[0]=>
array(1) {
[0]=>
string(1) "q"
}
}
array(1) {
[0]=>
array(1) {
[0]=>
string(1) "1"
}
}
SQL=update ban_jobs set bjo_status=:2, bjo_info=:3, bjo_heartbeat=to_date(:4, ) where bjo_id=:1
Segmentation fault (core dumped)
```
My first impression was that the segmentation violation was
caused by
preg_match_all("/(?<=:)[0-9a-z_]+/i", $sql, $match);
until I realized that the value of $sql does not matter. If I use
the string "sql" instead of $sql and try to match the single
letter q, even that simple regular match will cause SIGSEGV.
This is happening with php-8.2.7 and I just compiled a debug-version
of 8.3.1. No difference.
Any ideas how to fix this?
Kind regards
Peter
### PHP Version
PHP 8.3.1
### Operating System
Slackware Linux 15.0