Description
Hi, It seemed to me that a null dereference could potentially occur here.
A NULL pointer dereference can occur in sccp_visit_instr() when processing ZEND_ASSIGN_OBJ_OP.
The op2 operand is obtained from get_op2_value(), which can return NULL when opline->op2_type is not IS_CONST and ssa_op->op2_use == -1.
The ZEND_ASSIGN_OBJ_OP path checks op2 before SKIP_IF_TOP(op2), but does not check it before passing it to ct_eval_fetch_obj():
if (op2) {
SKIP_IF_TOP(op2);
}
if (ct_eval_fetch_obj(&tmp, op1, op2) == SUCCESS) {
When op2 is NULL, it is passed to ct_eval_fetch_obj(). The function subsequently calls fetch_obj_prop(), where Z_TYPE_P(op2) dereferences the NULL pointer.
This can result in a NULL pointer dereference.
Proposed solution
Check that op2 is non-NULL before calling ct_eval_fetch_obj().
PHP Version
Operating System
Ubuntu 24.04
Description
Hi, It seemed to me that a null dereference could potentially occur here.
A NULL pointer dereference can occur in sccp_visit_instr() when processing ZEND_ASSIGN_OBJ_OP.
The op2 operand is obtained from get_op2_value(), which can return NULL when opline->op2_type is not IS_CONST and ssa_op->op2_use == -1.
The ZEND_ASSIGN_OBJ_OP path checks op2 before SKIP_IF_TOP(op2), but does not check it before passing it to ct_eval_fetch_obj():
if (op2) {
SKIP_IF_TOP(op2);
}
if (ct_eval_fetch_obj(&tmp, op1, op2) == SUCCESS) {
When op2 is NULL, it is passed to ct_eval_fetch_obj(). The function subsequently calls fetch_obj_prop(), where Z_TYPE_P(op2) dereferences the NULL pointer.
This can result in a NULL pointer dereference.
Proposed solution
Check that op2 is non-NULL before calling ct_eval_fetch_obj().
PHP Version
Operating System
Ubuntu 24.04