#34277 [NEW]: Segmentation fault with array_filter
| From: | andreas dot ettner at freenet dot de | Date: | Sat, 27 Aug 2005 01:44:25 +0000 |
| Subject: | #34277 [NEW]: Segmentation fault with array_filter | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-84055@lists.php.net to get a copy of this message | ||
From: andreas dot ettner at freenet dot de
Operating system: Debian GNU/Linux
PHP version: 4.4.0
PHP Bug Type: Reproducible crash
Bug description: Segmentation fault with array_filter
Description:
------------
PHP crashes with a segmentation fault when executing the provided code.
This problem has been observed with various setups. The provided
backtrace of a crash was generated with PHP version 4.4.0 CGI, configured
with
'./configure' '--prefix=/home/eta/data/php-4.4.0' '--enable-debug' ,
compiled and run on a Debian GNU/Linux system with GCC version 3.3.5 and
GNU C Library version 2.3.2. In this setup PHP crashed on every
invocation.
In order to facilitate the task of fixing this defect I have tried to find
out its reason, and I think I have succeeded:
In the implementation of zif_array_filter (resp. array_filter) in
ext/standard/array.c the local variables input and callback are set to
point to locations in the elements array of the executor's argument_stack
(l. 3312). Calling the callback later on in zif_array_filter (l. 3340)
might cause the elements array of the stack to be moved in memory (through
reallocation when growing the stack). When this happens, the local
variables input and callback become invalid (dangling pointers), but are
possibly used later on (in l. 3354 in our situation).
I hope this helps.
Reproduce code:
---------------
The code is unfortunately a bit long. It can be found at
http://people.freenet.de/aettner/crash.txt
Expected result:
----------------
No output (CGI version invoked with -q flag)
Actual result:
--------------
Segmentation fault (core dumped)
Backtrace generated with gdb:
Using host libthread_db library "/lib/libthread_db.so.1".
Core was generated by `php -q crash.txt'.
Program terminated with signal 11, Segmentation fault.
#0 0x081715a9 in _zend_is_inconsistent (ht=0xfb8277dc,
file=0x81bd880 "/home/eta/data/src-php-4.4.0/Zend/zend_hash.c",
line=1064)
at /home/eta/data/src-php-4.4.0/Zend/zend_hash.c:94
94 if (ht->inconsistent==HT_OK) {
#0 0x081715a9 in _zend_is_inconsistent (ht=0xfb8277dc,
file=0x81bd880 "/home/eta/data/src-php-4.4.0/Zend/zend_hash.c",
line=1064)
at /home/eta/data/src-php-4.4.0/Zend/zend_hash.c:94
#1 0x08174262 in zend_hash_get_current_key_ex (ht=0xfb8277dc,
str_index=0xbfffca6c, str_length=0xbfffca68, num_index=0xbfffca64,
duplicate=0 '\0', pos=0xbfffca60)
at /home/eta/data/src-php-4.4.0/Zend/zend_hash.c:1064
#2 0x080add21 in zif_array_filter (ht=2, return_value=0x821b7d4,
this_ptr=0x0, return_value_used=1)
at /home/eta/data/src-php-4.4.0/ext/standard/array.c:3354
#3 0x0818134a in execute (op_array=0x8220490)
at /home/eta/data/src-php-4.4.0/Zend/zend_execute.c:1672
#4 0x08181576 in execute (op_array=0x8220890)
at /home/eta/data/src-php-4.4.0/Zend/zend_execute.c:1716
#5 0x08181576 in execute (op_array=0x82209e0)
at /home/eta/data/src-php-4.4.0/Zend/zend_execute.c:1716
#6 0x08181576 in execute (op_array=0x8220b30)
at /home/eta/data/src-php-4.4.0/Zend/zend_execute.c:1716
#7 0x08181576 in execute (op_array=0x8220c80)
at /home/eta/data/src-php-4.4.0/Zend/zend_execute.c:1716
#8 0x08181576 in execute (op_array=0x8217234)
at /home/eta/data/src-php-4.4.0/Zend/zend_execute.c:1716
#9 0x0816d298 in zend_execute_scripts (type=8, retval=0x0, file_count=3)
at /home/eta/data/src-php-4.4.0/Zend/zend.c:938
#10 0x0813707b in php_execute_script (primary_file=0xbffffa10)
at /home/eta/data/src-php-4.4.0/main/main.c:1751
#11 0x0818820c in main (argc=3, argv=0xbffffac4)
at /home/eta/data/src-php-4.4.0/sapi/cgi/cgi_main.c:1606
--
Edit bug report at http://bugs.php.net/?id=34277&edit=1
--
Try a CVS snapshot (php4): http://bugs.php.net/fix.php?id=34277&r=trysnapshot4
Try a CVS snapshot (php5.0): http://bugs.php.net/fix.php?id=34277&r=trysnapshot50
Try a CVS snapshot (php5.1): http://bugs.php.net/fix.php?id=34277&r=trysnapshot51
Fixed in CVS: http://bugs.php.net/fix.php?id=34277&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=34277&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=34277&r=needtrace
Need Reproduce Script: http://bugs.php.net/fix.php?id=34277&r=needscript
Try newer version: http://bugs.php.net/fix.php?id=34277&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=34277&r=support
Expected behavior: http://bugs.php.net/fix.php?id=34277&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=34277&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=34277&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=34277&r=globals
PHP 3 support discontinued: http://bugs.php.net/fix.php?id=34277&r=php3
Daylight Savings: http://bugs.php.net/fix.php?id=34277&r=dst
IIS Stability: http://bugs.php.net/fix.php?id=34277&r=isapi
Install GNU Sed: http://bugs.php.net/fix.php?id=34277&r=gnused
Floating point limitations: http://bugs.php.net/fix.php?id=34277&r=float
No Zend Extensions: http://bugs.php.net/fix.php?id=34277&r=nozend
MySQL Configuration Error: http://bugs.php.net/fix.php?id=34277&r=mysqlcfg