Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

NULL pointer dereference in php_ini.c (PHP 8.3)

Open Beginner friendly
#24,139 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
82/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
c, php
Domain
backend

Research direction

Read main/php_ini.c around the expand_filepath() call at line 565 and the later strlen(filename) call around line 610. Check the existing PHP INI tests before running the relevant test suite. Done means the failure path cannot dereference a NULL filename, and the behavior is covered by an appropriate test.

Written by the indexing model from the issue text.

Description

Bug Status: Needs Triage
Description

At main/php_ini.c:565 the return value of expand_filepath() is assigned to pointer filename without checking whether the function returned NULL:

https://github.com/php/php-src/blob/PHP-8.3/main/php_ini.c#L563-L566

The expand_filepath() function may return NULL if path expansion fails. However, later pointer filename is dereferenced by calling strlen(filename) without an additional NULL check:

https://github.com/php/php-src/blob/PHP-8.3/main/php_ini.c#L599-L609

In the analyzed PHP 8.3 source this operation corresponds to php_ini.c:610.

This may lead to a NULL pointer dereference if expand_filepath() fails.

Possible solution

Checking the return value of expand_filepath() before using filename may prevent unexpected behavior:

filename = expand_filepath(php_ini_file_name, NULL);
if (filename) {
    free_filename = true;
} else {
    filename = php_ini_file_name;
}

Found by Linux Verification Center (https://portal.linuxtesting.ru/) using SVACE.
Author E. Tretiakov.

PHP Version
8.3.24 (found with static analysis)
Operating System

N/A

Dominant language
C
Stars
40.4k
Forks
8.2k
Avg merge
2d 3h
Merged PRs (30d)
151

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from php/php-src

All issues in php/php-src

Similar issues

More C issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.