[GIT-PULLS] [php-src] PR #23360: Detect immediate double-frees of zend_mm small slots
[email protected] (jvoisin)
| Newsgroups | php.git-pulls |
|---|---|
| Message-ID | <[email protected]> |
Pull Request: https://github.com/php/php-src/pull/23360 Author: jvoisin Freeing the same small pointer twice in a row pushed it onto the freelist twice, so the next two allocations of that bin returned the same address. That's a nifty primitive to obtain two live pointers of different types to the same object. The shadow-pointer check does not catch it, as both links are consistent. This commit adds a simple check for when the freed pointer already is the head of the freelist. heap->free_slot[bin_num] is loaded by the very next line, so the check costs a single comparison on an already-hot value. This only catches consecutive double-frees, not a free after other activity on the same bin, but it doesn't cost ~anything performance wise, and catches real bugs like error/cleanup paths freeing the same value twice. A quick look at `git log --grep='double.free'` shows that this is a popular bug pattern.