Hacktoberfest 2026:維護者為十月標記出來的 issue,仍然開放、適合新手。 瀏覽 Hacktoberfest issue

NULL pointer dereference in php_ini.c (PHP 8.3)

未關閉 適合新手
#24,139 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

維護者通常 1 天內回覆

@lazerg 已經在處理了。

開始於 2026年10月5日。

  • #24141 來自 @lazerg —— 未關閉

評估

難度
2/5
預估耗時
1-3 小時
新手友好度
82/100
Issue 類型
缺陷
描述清晰度
描述清楚
活躍度
活躍
技術堆疊
c, php
領域
backend

研究方向

閱讀main/php_ini.c中第 565 行expand_filepath()呼叫附近的程式碼,以及約第 610 行後續的strlen(filename)呼叫附近的程式碼。執行相關測試套件之前,先檢查現有的 PHP INI 測試。完成標準是:失敗路徑無法對 NULL 的filename進行解參照,且有適當的測試涵蓋此行為。

由索引模型根據 Issue 內容生成。

描述

Bug Status: Needs Triage
Description

At main/php_ini.c:565 the return value of expand_filepath() is assigned to pointer filename without checking whether the function returned NULL:

https://github.com/php/php-src/blob/PHP-8.3/main/php_ini.c#L563-L566

The expand_filepath() function may return NULL if path expansion fails. However, later pointer filename is dereferenced by calling strlen(filename) without an additional NULL check:

https://github.com/php/php-src/blob/PHP-8.3/main/php_ini.c#L599-L609

In the analyzed PHP 8.3 source this operation corresponds to php_ini.c:610.

This may lead to a NULL pointer dereference if expand_filepath() fails.

Possible solution

Checking the return value of expand_filepath() before using filename may prevent unexpected behavior:

filename = expand_filepath(php_ini_file_name, NULL);
if (filename) {
    free_filename = true;
} else {
    filename = php_ini_file_name;
}

Found by Linux Verification Center (https://portal.linuxtesting.ru/) using SVACE.
Author E. Tretiakov.

PHP Version
8.3.24 (found with static analysis)
Operating System

N/A

主要語言
C
星號
40.4k
分支
8.2k
平均合併
2 天 3 小時
30 天內合併 PR
151

環境準備

  • 沒有 Dockerfile 或 Docker Compose 檔案
  • 沒有 Pull Request 範本
  • 閱讀貢獻指南

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

php/php-src 的其他 Issue

查看 php/php-src 的全部 Issue

相似的 Issue

更多 C Issue

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。