Skip to content

Potential NULL pointer dereference in sccp_visit_instr(sccp.c) #24193

Description

@Ti-Mis

Description

Hi, It seemed to me that a null dereference could potentially occur here.

A NULL pointer dereference can occur in sccp_visit_instr() when processing ZEND_ASSIGN_OBJ_OP.

The op2 operand is obtained from get_op2_value(), which can return NULL when opline->op2_type is not IS_CONST and ssa_op->op2_use == -1.

The ZEND_ASSIGN_OBJ_OP path checks op2 before SKIP_IF_TOP(op2), but does not check it before passing it to ct_eval_fetch_obj():

if (op2) {
SKIP_IF_TOP(op2);
}

if (ct_eval_fetch_obj(&tmp, op1, op2) == SUCCESS) {

When op2 is NULL, it is passed to ct_eval_fetch_obj(). The function subsequently calls fetch_obj_prop(), where Z_TYPE_P(op2) dereferences the NULL pointer.

This can result in a NULL pointer dereference.

Proposed solution

Check that op2 is non-NULL before calling ct_eval_fetch_obj().

PHP Version

PHP 8.3.31 (CLI)

Operating System

Ubuntu 24.04

Activity

  1. Ti-Mis commented on Oct 8, 2026

    @Ti-Mis
    Author
  2. ndossche commented on Oct 8, 2026

    @ndossche
    Member

    Please see #23796 (comment), which you should have since it's your own issue.
    Are these reports fully automated?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions