[php-src] Issue #24139: NULL pointer dereference in php_ini.c (PHP 8.3)

From: Date: Mon, 05 Oct 2026 16:51:42 +0000
Subject: [php-src] Issue #24139: NULL pointer dereference in php_ini.c (PHP 8.3)
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-252906@lists.php.net to get a copy of this message
Issue: https://github.com/php/php-src/issues/24139 Author: Georg1o ### Description At main/php_ini.c:565 the return value of expand_filepath() is assigned to pointer filename without checking whether the function returned NULL: https://github.com/php/php-src/blob/PHP-8.3/main/php_ini.c#L563-L566 The expand_filepath() function may return NULL if path expansion fails. However, later pointer filename is dereferenced by calling strlen(filename) without an additional NULL check: https://github.com/php/php-src/blob/PHP-8.3/main/php_ini.c#L599-L609 In the analyzed PHP 8.3 source this operation corresponds to php_ini.c:610. This may lead to a NULL pointer dereference if expand_filepath() fails. ## Possible solution Checking the return value of expand_filepath() before using filename may prevent unexpected behavior: ```c filename = expand_filepath(php_ini_file_name, NULL); if (filename) { free_filename = true; } else { filename = php_ini_file_name; } ``` Found by Linux Verification Center (https://portal.linuxtesting.ru/) using SVACE. Author E. Tretiakov. ### PHP Version ```plain 8.3.24 (found with static analysis) ``` ### Operating System N/A

« previous php.bugs (#252906) next »