[php-src] Issue #13007: Segmentation fault in preg_match_all()

From: Date: Sat, 23 Dec 2023 13:32:30 +0000
Subject: [php-src] Issue #13007: Segmentation fault in preg_match_all()
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-246109@lists.php.net to get a copy of this message
Issue: https://github.com/php/php-src/issues/13007 Author: pk1234 ### Description The following function: ```php function get_bind_variables($sql){ $args=[]; $sql=preg_replace("/'[^']*'/", " ", $sql); $sql=preg_replace('/"[^"]*"/', " ", $sql); print "SQL=$sql\n"; preg_match_all("/q/", "sql", $match); var_dump($match); preg_match_all("/(?<=:)[0-9a-z_]+/i", $sql, $match); var_dump($match); foreach($match[0] as $v) $args[$v]=$v; return $args; } ``` is used in a very large php application that was upgraded from php 5.6 to 8.2.7 lately. It detects bind-variables in SQL-statements. Under some very rare conditions the application fails with SIGSEGV and produces the follwoing output: ``` ... lots of SQL-Statements with correct var_dump()-output ... SQL=select bsi_size, bsi_zeitpunkt_von, bsi_zeitpunkt_bis, bvo_basedir, bso_hostname from ban_sicherungen, ban_volumes, ban_standorte where bsi_id = :1 and bvo_id = bsi_bvo_id and bso_id = bvo_bso_id array(1) { [0]=> array(1) { [0]=> string(1) "q" } } array(1) { [0]=> array(1) { [0]=> string(1) "1" } } SQL=select nvl(sum(trunc((bsi_size+131071)/131072)+1),0) bpos1, count(*)+1 pos from ban_inhalte, ban_sicherungen where bih_ban_id = :1 and bsi_id = bih_bsi_id array(1) { [0]=> array(1) { [0]=> string(1) "q" } } array(1) { [0]=> array(1) { [0]=> string(1) "1" } } SQL=update ban_jobs set bjo_status=:2, bjo_info=:3, bjo_heartbeat=to_date(:4, ) where bjo_id=:1 Segmentation fault (core dumped) ``` My first impression was that the segmentation violation was caused by preg_match_all("/(?<=:)[0-9a-z_]+/i", $sql, $match); until I realized that the value of $sql does not matter. If I use the string "sql" instead of $sql and try to match the single letter q, even that simple regular match will cause SIGSEGV. This is happening with php-8.2.7 and I just compiled a debug-version of 8.3.1. No difference. Any ideas how to fix this? Kind regards Peter ### PHP Version PHP 8.3.1 ### Operating System Slackware Linux 15.0

« previous php.bugs (#246109) next »