Skip to content

Fix GH-24139: NULL dereference in php_ini.c when expand_filepath() fails - #24141

Open
lazerg wants to merge 1 commit into
php:PHP-8.4from
lazerg:fix/gh-24139-ini-expand-filepath
Open

lazerg wants to merge 1 commit into
php:PHP-8.4from
lazerg:fix/gh-24139-ini-expand-filepath

Conversation

@lazerg

@lazerg lazerg commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

When the ini file passed with -c (or PHPRC) is a relative path, it can be opened fine while expand_filepath() still returns NULL, because the cwd plus the relative path goes over MAXPATHLEN. filename then ends up NULL and the strlen(filename) for cfg_file_path segfaults. Falling back to the path as given avoids the crash. The test reproduces it with a long run of ./ in front of the ini name.

Fixes #24139

@lazerg
lazerg requested a review from bukka as a code owner October 5, 2026 17:43
Comment thread main/php_ini.c
if (filename) {
free_filename = true;
} else {
filename = php_ini_file_name;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What should be done instead is to reject the file so it behaves like ZTS ("disagreement" between ZTS and NTS is shown through partial CI failures).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants