Skip to content

Commit aebd3ee

Browse files
committed
Merge branch 'PHP-8.4' into PHP-8.5
2 parents 0e88a4b + c88c89e commit aebd3ee

2 files changed

Lines changed: 37 additions & 1 deletion

File tree

‎main/php_ini.c‎

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -562,7 +562,13 @@ void php_init_config(void)
562562
fp = VCWD_FOPEN(php_ini_file_name, "r");
563563
if (fp) {
564564
filename = expand_filepath(php_ini_file_name, NULL);
565-
free_filename = true;
565+
if (filename) {
566+
free_filename = true;
567+
} else {
568+
/* Reject the file, like ZTS where VCWD_STAT() already fails */
569+
fclose(fp);
570+
fp = NULL;
571+
}
566572
}
567573
}
568574
}

‎sapi/cli/tests/gh24139.phpt‎

Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,30 @@
1+
--TEST--
2+
GH-24139 (NULL pointer dereference in php_ini.c when expand_filepath() fails)
3+
--SKIPIF--
4+
<?php
5+
include "skipif.inc";
6+
if (PHP_OS_FAMILY === "Windows") die("skip not for Windows");
7+
?>
8+
--FILE--
9+
<?php
10+
$ini_file = __DIR__ . "/gh24139.ini";
11+
file_put_contents($ini_file, "gh24139=ok\n");
12+
13+
$relative = str_repeat("./", intdiv(PHP_MAXPATHLEN - strlen(__DIR__), 2)) . "gh24139.ini";
14+
15+
$proc = proc_open(
16+
[getenv("TEST_PHP_EXECUTABLE"), "-c", $relative, "-r", 'var_dump(get_cfg_var("gh24139"));'],
17+
[1 => ["pipe", "w"]],
18+
$pipes,
19+
__DIR__
20+
);
21+
echo stream_get_contents($pipes[1]);
22+
var_dump(proc_close($proc));
23+
?>
24+
--CLEAN--
25+
<?php
26+
@unlink(__DIR__ . "/gh24139.ini");
27+
?>
28+
--EXPECT--
29+
bool(false)
30+
int(0)

0 commit comments

Comments
 (0)