Skip to content

Optimizer/sccp.c: Fix NULL pointer dereference in ZEND_ASSIGN_OBJ_OP - #24194

Closed
Ti-Mis wants to merge 1 commit into
php:masterfrom
Ti-Mis:DAN-sccp0810
Closed

Ti-Mis wants to merge 1 commit into
php:masterfrom
Ti-Mis:DAN-sccp0810

Conversation

@Ti-Mis

@Ti-Mis Ti-Mis commented Oct 8, 2026

Copy link
Copy Markdown

get_op2_value() can return NULL when the SSA operand is unavailable. The ZEND_ASSIGN_OBJ_OP path did not check op2 before passing it to ct_eval_fetch_obj(), which eventually dereferences it in fetch_obj_prop().

Add a NULL check before calling ct_eval_fetch_obj() to prevent the invalid dereference.

Problem:
Potential NULL pointer dereference when op2 is NULL and is passed to ct_eval_fetch_obj().

Solution: Check op2 before calling ct_eval_fetch_obj().

Signed-off-by: Timofey Mishin <t.mishin@fobos-nt.ru>
Signed-off-by: Georgij Tsarin <crystarm@altlinux.org>
@ndossche

ndossche commented Oct 8, 2026

Copy link
Copy Markdown
Member

False positive

@ndossche ndossche closed this Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants