Skip to content

Fix use-after-free in ArrayObject::unset() with destructor #16653

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
wants to merge 2 commits into from

Conversation

iluuu1994
Copy link
Member

Fixes GH-16646

@iluuu1994
Copy link
Member Author

There are also some more issues with ArrayObject::exchangeArray(). I'll look at those while I'm at it.

@nielsdos
Copy link
Member

I didnt properly check when I wrote my comment that we could simply delay destructors, but indeed this seems to work too in this case.

Copy link
Member

@Girgias Girgias left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

global and $GLOBALS do be the bane of my existence with all the whack bugs it can create.

But this looks reasonable

@iluuu1994
Copy link
Member Author

Along with references, error handlers and destructors. ^^ Unfortunately, they are also kind of useful. 😄

@Girgias
Copy link
Member

Girgias commented Oct 31, 2024

Very true :')

@iluuu1994 iluuu1994 closed this in 8910ac8 Nov 4, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants