Skip to content

SEGV Zend/zend_alloc.c #17772

Closed
Closed
@YuanchengJiang

Description

@YuanchengJiang

Description

The following code:

<?php
function setStyleAndThickness($im, $color, $thickness)
{
while ($i < 16 * $thickness) {
$style[$i++] = $color;
}
}
$im = imagecreate(800, 800);
setStyleAndThickness($im, $black, 6);
imagepalettetotruecolor($im);

Resulted in this output:

/home/phpfuzz/WorkSpace/flowfusion/php-src/Zend/zend_alloc.c:1528:35: runtime error: member access within null pointer of type 'zend_mm_chunk' (aka 'struct _zend_mm_chunk')
SUMMARY: UndefinedBehaviorSanitizer: undefined-behavior /home/phpfuzz/WorkSpace/flowfusion/php-src/Zend/zend_alloc.c:1528:35 in 

To reproduce:

-d "memory_limit=2M"

Commit:

commit 2acda557cd83fd72bc8dbe3756d29dbe779f7249
Author: Niels Dossche <[email protected]>
Date:   Mon Feb 10 08:43:35 2025 +0100

    Pack _php_sqlite3_db_object

Configurations:

CC="clang-12" CXX="clang++-12" CFLAGS="-DZEND_VERIFY_TYPE_INFERENCE" CXXFLAGS="-DZEND_VERIFY_TYPE_INFERENCE" ./configure --enable-debug --enable-address-sanitizer --enable-undefined-sanitizer --enable-re2c-cgoto --enable-fpm --enable-litespeed --enable-phpdbg-debug --enable-zts --enable-bcmath --enable-calendar --enable-dba --enable-dl-test --enable-exif --enable-ftp --enable-gd --enable-gd-jis-conv --enable-mbstring --enable-pcntl --enable-shmop --enable-soap --enable-sockets --enable-sysvmsg --enable-zend-test --with-zlib --with-bz2 --with-curl --with-enchant --with-gettext --with-gmp --with-mhash --with-ldap --with-libedit --with-readline --with-snmp --with-sodium --with-xsl --with-zip

Operating System:

Ubuntu 20.04 Host, Docker 0599jiangyc/flowfusion:latest

This report is automatically generated by FlowFusion

PHP Version

2acda55

Operating System

No response

Metadata

Metadata

Assignees

Type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions