Merge branch 'PHP-8.3' into PHP-8.4
* PHP-8.3: Fix is_zend_ptr() huge block comparison
This commit is contained in:
1
NEWS
1
NEWS
@ -5,6 +5,7 @@ PHP NEWS
|
||||
- Core:
|
||||
. Fixed bug GH-16344 (setRawValueWithoutLazyInitialization() and
|
||||
skipLazyInitialization() may change initialized proxy). (Arnaud)
|
||||
. Fix is_zend_ptr() huge block comparison. (nielsdos)
|
||||
|
||||
- DOM:
|
||||
. Fixed bug GH-16906 (Reloading document can cause UAF in iterator).
|
||||
|
@ -2617,8 +2617,8 @@ ZEND_API bool is_zend_ptr(const void *ptr)
|
||||
|
||||
zend_mm_huge_list *block = AG(mm_heap)->huge_list;
|
||||
while (block) {
|
||||
if (ptr >= (void*)block
|
||||
&& ptr < (void*)((char*)block + block->size)) {
|
||||
if (ptr >= block->ptr
|
||||
&& ptr < (void*)((char*)block->ptr + block->size)) {
|
||||
return 1;
|
||||
}
|
||||
block = block->next;
|
||||
|
Reference in New Issue
Block a user