[php-src] PR #24176: use-after-free when an error handler removes a failing zlib.inflate filter

From: Date: Wed, 07 Oct 2026 08:56:32 +0000
Subject: [php-src] PR #24176: use-after-free when an error handler removes a failing zlib.inflate filter
Groups: php.git-pulls 
Request: Send a blank email to git-pulls+get-39234@lists.php.net to get a copy of this message
Pull Request: https://github.com/php/php-src/pull/24176 Author: EdmondDantes On a corrupt input zlib.inflate raises E_NOTICE ("zlib: data error") and then resets its input pointers. A user error handler that calls stream_filter_remove() on that filter frees the filter's state first, so the reset writes to freed memory (Valgrind: invalid writes in php_zlib_inflate_filter()). The fix resets the state before raising the notice; nothing touches the filter after it. Test: ext/zlib/tests/zlib_filter_inflate_error_handler_removes_filter.phpt, as a write and as a read filter. Not covered, same family: an error handler that closes the stream itself during any filter's diagnostic (fclose() is only refused while a user filter runs), which would need PHP_STREAM_FLAG_NO_FCLOSE around the whole filter chain walk.

« previous php.git-pulls (#39234) next »