Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

NULL pointer dereference in php_ini.c (PHP 8.3)

已关闭 适合新手
#24,139 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
2/5
预计耗时
1-3 小时
新手友好度
82/100
Issue 类型
缺陷
描述清晰度
描述清楚
活跃度
活跃
技术栈
c, php
领域
backend

调研方向

阅读main/php_ini.c中第 565 行expand_filepath()调用附近的代码,以及约第 610 行后续的strlen(filename)调用附近的代码。运行相关测试套件之前,先检查现有的 PHP INI 测试。完成标准是:失败路径无法对 NULL 的filename进行解引用,并且有适当的测试覆盖该行为。

由索引模型根据 Issue 内容生成。

描述

Bug Status: Needs Triage
Description

At main/php_ini.c:565 the return value of expand_filepath() is assigned to pointer filename without checking whether the function returned NULL:

https://github.com/php/php-src/blob/PHP-8.3/main/php_ini.c#L563-L566

The expand_filepath() function may return NULL if path expansion fails. However, later pointer filename is dereferenced by calling strlen(filename) without an additional NULL check:

https://github.com/php/php-src/blob/PHP-8.3/main/php_ini.c#L599-L609

In the analyzed PHP 8.3 source this operation corresponds to php_ini.c:610.

This may lead to a NULL pointer dereference if expand_filepath() fails.

Possible solution

Checking the return value of expand_filepath() before using filename may prevent unexpected behavior:

filename = expand_filepath(php_ini_file_name, NULL);
if (filename) {
    free_filename = true;
} else {
    filename = php_ini_file_name;
}

Found by Linux Verification Center (https://portal.linuxtesting.ru/) using SVACE.
Author E. Tretiakov.

PHP Version
8.3.24 (found with static analysis)
Operating System

N/A

主要语言
C
星标
40.4k
派生
8.2k
平均合并
1 天 23 小时
30 天内合并 PR
150

环境准备

  • 没有 Dockerfile 或 Docker Compose 文件
  • 没有 Pull Request 模板
  • 阅读贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

php/php-src 的其他 Issue

查看 php/php-src 的全部 Issue

相似的 Issue

更多 C Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。