[php-src] Issue #24139: NULL pointer dereference in php_ini.c (PHP 8.3)
| From: | Georg1o | Date: | Mon, 05 Oct 2026 16:51:42 +0000 |
| Subject: | [php-src] Issue #24139: NULL pointer dereference in php_ini.c (PHP 8.3) | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-252906@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/24139
Author: Georg1o
### Description
At
main/php_ini.c:565 the return value of expand_filepath() is assigned to
pointer filename without checking whether the function returned NULL:
https://github.com/php/php-src/blob/PHP-8.3/main/php_ini.c#L563-L566
The expand_filepath() function may return NULL if path expansion fails.
However, later pointer filename is dereferenced by calling
strlen(filename) without an additional NULL check:
https://github.com/php/php-src/blob/PHP-8.3/main/php_ini.c#L599-L609
In the analyzed PHP 8.3 source this operation corresponds to php_ini.c:610.
This may lead to a NULL pointer dereference if expand_filepath() fails.
## Possible solution
Checking the return value of expand_filepath() before using filename may
prevent unexpected behavior:
```c
filename = expand_filepath(php_ini_file_name, NULL);
if (filename) {
free_filename = true;
} else {
filename = php_ini_file_name;
}
```
Found by Linux Verification Center (https://portal.linuxtesting.ru/) using SVACE.
Author E. Tretiakov.
### PHP Version
```plain
8.3.24 (found with static analysis)
```
### Operating System
N/A