ZendEngine 2 - Double Free BUG

From: Date: Wed, 02 Jun 2004 11:43:09 +0000
Subject: ZendEngine 2 - Double Free BUG
Groups: php.internals 
Request: Send a blank email to internals+get-10241@lists.php.net to get a copy of this message
Hi, I ported Hardened-PHP to PHP5 yesterday night and got into the problem that there were some crashes. While one of the crashes is a problem in the port (at least I guess so), the other one was a detected double efree() in __set__get_001.phpt I tracked this double free down to static void zend_post_incdec_property(...) where z is passed to Z_OBJ_HT_P(object)->write_property(object, property, z TSRMLS_CC); within this function z is freed and
               if (z->refcount == 0) {
                        zval_dtor(z);
                        FREE_ZVAL(z);
                }
will free it again. I fixed this by adding a z->refcount++ after *retval = *z; but I do not know if this is the correct place, because I am not really into ZE2 internals. Stefan Esser

« previous php.internals (#10241) next »