com php-src: Fix use after free for doc_comment persist: ext/opcache/zend_persist.c
| From: | Nikita Popov | Date: | Mon, 05 May 2014 17:56:05 +0000 |
| Subject: | com php-src: Fix use after free for doc_comment persist: ext/opcache/zend_persist.c | ||
| Groups: | php.cvs | ||
| Request: | Send a blank email to php-cvs+get-78104@lists.php.net to get a copy of this message | ||
Commit: b9438a1ec7a2548e05b938f8034f74f9c7d490f0
Author: Nikita Popov <nikic@php.net> Mon, 5 May 2014 19:56:05 +0200
Parents: 592aa37f67921c92bc8d882c431d443e24fc1e52
Branches: phpng
Link: http://git.php.net/?p=php-src.git;a=commitdiff;h=b9438a1ec7a2548e05b938f8034f74f9c7d490f0
Log:
Fix use after free for doc_comment persist
Changed paths:
M ext/opcache/zend_persist.c
Diff:
diff --git a/ext/opcache/zend_persist.c b/ext/opcache/zend_persist.c
index 601849b..ca3c188 100644
--- a/ext/opcache/zend_persist.c
+++ b/ext/opcache/zend_persist.c
@@ -402,7 +402,12 @@ static void zend_persist_op_array_ex(zend_op_array *op_array,
zend_persistent_sc
if (op_array->doc_comment) {
if (ZCG(accel_directives).save_comments) {
- zend_accel_store_string(op_array->doc_comment);
+ if (already_stored) {
+ op_array->doc_comment = zend_shared_alloc_get_xlat_entry(op_array->doc_comment);
+ ZEND_ASSERT(op_array->doc_comment != NULL);
+ } else {
+ zend_accel_store_string(op_array->doc_comment);
+ }
} else {
if (!already_stored) {
STR_RELEASE(op_array->doc_comment);