Skip to content

Commit cc93bbb

Browse files
committed
Fix GH-19397: mb_list_encodings() can cause crashes on shutdown
The request shutdown does not necessarily hold the last reference, if there is still a CV that refers to the array. Closes GH-19405.
1 parent 5cf45ba commit cc93bbb

File tree

3 files changed

+17
-2
lines changed

3 files changed

+17
-2
lines changed

NEWS

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -46,6 +46,10 @@ PHP NEWS
4646
. Fixed bug GH-19098 (libxml<2.13 segmentation fault caused by
4747
php_libxml_node_free). (nielsdos)
4848

49+
- MbString:
50+
. Fixed bug GH-19397 (mb_list_encodings() can cause crashes on shutdown).
51+
(nielsdos)
52+
4953
- Opcache:
5054
. Reset global pointers to prevent use-after-free in zend_jit_status().
5155
(Florian Engelhardt)

ext/mbstring/mbstring.c

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1165,8 +1165,8 @@ PHP_RSHUTDOWN_FUNCTION(mbstring)
11651165
MBSTRG(outconv_state) = 0;
11661166

11671167
if (MBSTRG(all_encodings_list)) {
1168-
GC_DELREF(MBSTRG(all_encodings_list));
1169-
zend_array_destroy(MBSTRG(all_encodings_list));
1168+
/* must be *array* release to remove from GC root buffer and free the hashtable itself */
1169+
zend_array_release(MBSTRG(all_encodings_list));
11701170
MBSTRG(all_encodings_list) = NULL;
11711171
}
11721172

ext/mbstring/tests/gh19397.phpt

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
--TEST--
2+
GH-19397 (mb_list_encodings() can cause crashes on shutdown)
3+
--EXTENSIONS--
4+
mbstring
5+
--FILE--
6+
<?php
7+
$doNotDeleteThisVariableAssignment = mb_list_encodings();
8+
var_dump(count($doNotDeleteThisVariableAssignment) > 0);
9+
?>
10+
--EXPECT--
11+
bool(true)

0 commit comments

Comments
 (0)