ZendEngine 2 - Double Free BUG
| From: | Stefan Esser | Date: | Wed, 02 Jun 2004 11:43:09 +0000 |
| Subject: | ZendEngine 2 - Double Free BUG | ||
| Groups: | php.internals | ||
| Request: | Send a blank email to internals+get-10241@lists.php.net to get a copy of this message | ||
Hi,
I ported Hardened-PHP to PHP5 yesterday night and got into the problem that there were some crashes. While one of the crashes is a problem in the port (at least I guess so), the other one was a detected double efree() in __set__get_001.phpt
I tracked this double free down to
static void zend_post_incdec_property(...)
where z is passed to
Z_OBJ_HT_P(object)->write_property(object, property, z TSRMLS_CC);
within this function z is freed and
if (z->refcount == 0) {
zval_dtor(z);
FREE_ZVAL(z);
}
will free it again.
I fixed this by adding a z->refcount++ after
*retval = *z; but I do not know if this is the correct place,
because I am not really into ZE2 internals.
Stefan Esser