Skip to content

Commit e4e663c

Browse files
committed
Merge branch 'PHP-8.4'
* PHP-8.4: Use-after-free in extract() with EXTR_REFS
2 parents 4e44efa + 3ffb310 commit e4e663c

File tree

2 files changed

+26
-1
lines changed

2 files changed

+26
-1
lines changed

ext/standard/array.c

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1957,8 +1957,10 @@ static zend_long php_extract_ref_overwrite(zend_array *arr, zend_array *symbol_t
19571957
} else {
19581958
ZVAL_MAKE_REF_EX(entry, 2);
19591959
}
1960-
zval_ptr_dtor(orig_var);
1960+
zval garbage;
1961+
ZVAL_COPY_VALUE(&garbage, orig_var);
19611962
ZVAL_REF(orig_var, Z_REF_P(entry));
1963+
zval_ptr_dtor(&garbage);
19621964
} else {
19631965
if (Z_ISREF_P(entry)) {
19641966
Z_ADDREF_P(entry);

ext/standard/tests/gh18209.phpt

Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
--TEST--
2+
GH-18209: Use-after-free in extract() with EXTR_REFS
3+
--CREDITS--
4+
Noam Rathaus (nrathaus)
5+
--FILE--
6+
<?php
7+
8+
class C {
9+
public function __destruct() {
10+
var_dump($GLOBALS['b']);
11+
$GLOBALS['b'] = 43;
12+
}
13+
}
14+
15+
$b = new C;
16+
$array = ['b' => 42];
17+
extract($array, EXTR_REFS);
18+
var_dump($b);
19+
20+
?>
21+
--EXPECT--
22+
int(42)
23+
int(43)

0 commit comments

Comments
 (0)