Skip to content

Commit f5b0a9a

Browse files
committed
Merge branch 'PHP-8.3' into PHP-8.4
2 parents bfd9e0c + b28ded4 commit f5b0a9a

File tree

2 files changed

+30
-3
lines changed

2 files changed

+30
-3
lines changed

ext/sysvmsg/sysvmsg.c

+11-3
Original file line numberDiff line numberDiff line change
@@ -370,11 +370,19 @@ PHP_FUNCTION(msg_send)
370370
php_var_serialize(&msg_var, message, &var_hash);
371371
PHP_VAR_SERIALIZE_DESTROY(var_hash);
372372

373+
if (UNEXPECTED(EG(exception))) {
374+
smart_str_free(&msg_var);
375+
RETURN_THROWS();
376+
}
377+
378+
379+
zend_string *str = smart_str_extract(&msg_var);
380+
message_len = ZSTR_LEN(str);
373381
/* NB: php_msgbuf is 1 char bigger than a long, so there is no need to
374382
* allocate the extra byte. */
375-
messagebuffer = safe_emalloc(ZSTR_LEN(msg_var.s), 1, sizeof(struct php_msgbuf));
376-
memcpy(messagebuffer->mtext, ZSTR_VAL(msg_var.s), ZSTR_LEN(msg_var.s) + 1);
377-
message_len = ZSTR_LEN(msg_var.s);
383+
messagebuffer = safe_emalloc(message_len, 1, sizeof(struct php_msgbuf));
384+
memcpy(messagebuffer->mtext, ZSTR_VAL(str), message_len + 1);
385+
zend_string_release_ex(str, false);
378386
smart_str_free(&msg_var);
379387
} else {
380388
char *p;

ext/sysvmsg/tests/gh16592.phpt

+19
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
--TEST--
2+
msg_send() segfault when the type does not serialize as expected
3+
--EXTENSIONS--
4+
sysvmsg
5+
--FILE--
6+
<?php
7+
class Test {
8+
function __serialize() {}
9+
}
10+
11+
$q = msg_get_queue(1);
12+
try {
13+
msg_send($q, 1, new Test, true);
14+
} catch (\TypeError $e) {
15+
echo $e->getMessage();
16+
}
17+
?>
18+
--EXPECT--
19+
Test::__serialize() must return an array

0 commit comments

Comments
 (0)