[PHP-CVS] [php-src] PHP-8.4: Fix mbregex search state after cache invalidation

[email protected] (Matthias Goergens via Yuya Hamada) Sat, 1 Aug 2026 03:02:28 +0000
Newsgroups php.cvs
Message-ID <[email protected]>
Author: Matthias Goergens (matthiasgoergens)
Committer: Yuya Hamada (youkidearitai)
Date: 2026-08-01T12:01:58+09:00

Commit: https://github.com/php/php-src/commit/da4b67604772297e1f0d14125f5efb07319d09fb
Raw diff: https://github.com/php/php-src/commit/da4b67604772297e1f0d14125f5efb07319d09fb.diff

Fix mbregex search state after cache invalidation

Closes GH-22954

Changed paths:
  A  ext/mbstring/tests/gh21036.phpt
  M  NEWS
  M  ext/mbstring/php_mbregex.c


Diff:

diff --git a/NEWS b/NEWS
index 7f4d24f6b0a6..d9c71758bf28 100644
--- a/NEWS
+++ b/NEWS
@@ -15,6 +15,8 @@ PHP                                                                        NEWS
 - MBString:
   . Fixed bug GH-22779 (mb_strrpos() returns the wrong position for a negative
     offset in a non-UTF-8 encoding). (Eyüp Can Akman)
+  . Fixed bug GH-21036 (mb_ereg_search_getregs() crashes after mb_eregi()
+    invalidates the regex cache). (Matthias Goergens)
 
 - PCRE:
   . Fixed bug GH-21134 (Crash with \C + UTF-8). Using \C in UTF-8 patterns is
diff --git a/ext/mbstring/php_mbregex.c b/ext/mbstring/php_mbregex.c
index 0a62b6c22898..e823b5529818 100644
--- a/ext/mbstring/php_mbregex.c
+++ b/ext/mbstring/php_mbregex.c
@@ -481,6 +481,10 @@ static php_mb_regex_t *php_mbregex_compile_pattern(const char *pattern, size_t p
 		if (rc == MBREX(search_re)) {
 			/* reuse the new rc? see bug #72399 */
 			MBREX(search_re) = NULL;
+			if (MBREX(search_regs) != NULL) {
+				onig_region_free(MBREX(search_regs), 1);
+				MBREX(search_regs) = NULL;
+			}
 		}
 		zend_hash_str_update_ptr(&MBREX(ht_rc), (char *)pattern, patlen, retval);
 	} else {
diff --git a/ext/mbstring/tests/gh21036.phpt b/ext/mbstring/tests/gh21036.phpt
new file mode 100644
index 000000000000..60c63038510c
--- /dev/null
+++ b/ext/mbstring/tests/gh21036.phpt
@@ -0,0 +1,17 @@
+--TEST--
+GH-21036 (mb_ereg_search_getregs() after regex cache invalidation)
+--EXTENSIONS--
+mbstring
+--FILE--
+<?php
+error_reporting(E_ALL & ~E_DEPRECATED);
+
+$pattern = '(?<name>a)';
+mb_ereg_search_init('a', $pattern);
+mb_ereg_search_pos();
+mb_eregi($pattern, 'a');
+
+var_dump(mb_ereg_search_getregs());
+?>
+--EXPECT--
+bool(false)