diff --git a/.github/workflows/test-suite.yml b/.github/workflows/test-suite.yml index 2046a3d816c8..b444caf6b820 100644 --- a/.github/workflows/test-suite.yml +++ b/.github/workflows/test-suite.yml @@ -919,6 +919,7 @@ jobs: with: ref: ${{ fromJson(inputs.branch).ref }} fetch-depth: 0 + filter: blob:none # ASLR can cause a lot of noise due to missed sse opportunities for memcpy # and other operations, so we disable it during benchmarking. - name: Disable ASLR diff --git a/NEWS b/NEWS index df22c2cea467..1ed1362f3557 100644 --- a/NEWS +++ b/NEWS @@ -39,6 +39,10 @@ PHP NEWS . Fixed bug GH-23117 (Stack overflow when normalizing a deeply nested Dom\XMLDocument). (Lazizbek Ergashev) +- Exif: + . Fixed exif_read_data() allocating a HEIF meta box larger than the file + it came from. (iliaal) + - GMP: . Added optional $definitely_prime output parameter to gmp_prevprime(). (Weilin Du) diff --git a/docs/source/miscellaneous/writing-tests.rst b/docs/source/miscellaneous/writing-tests.rst index 4339e042e6a4..40e273b6fd71 100644 --- a/docs/source/miscellaneous/writing-tests.rst +++ b/docs/source/miscellaneous/writing-tests.rst @@ -596,9 +596,10 @@ Example 1 (full): :ref:`sample001.phpt` on the first line. If the test was part of a TestFest event, then # followed by the name of the event and the date (YYYY-MM-DD) on the second line. -**Required:** No. For newly created tests this section should no longer be included, as test -authorship is already accurately tracked by Git. If multiple authors should be credited, the -`Co-authored-by` tag in the commit message may be used. +**Required:** No. For newly created tests the section should no longer be used for simple authorship +claims or listing all contributors who edited the test; as it is already accurately tracked by Git. +It may be used if more specific attribution is useful, for example to credit the original reporter +of a bug or a contributor who is not credited via `Co-authored-by` tag. **Format:** Name Email [Event] diff --git a/ext/exif/exif.c b/ext/exif/exif.c index a156a3a63ad2..503cf3609e83 100644 --- a/ext/exif/exif.c +++ b/ext/exif/exif.c @@ -4412,7 +4412,7 @@ static bool exif_scan_HEIF_header(image_info_type *ImageInfo, unsigned char *buf } if (box.type == FOURCC("meta")) { limit = box.size - box_header_size; - if (limit < 36) { + if (limit < 36 || limit > ImageInfo->FileSize) { break; } data = (unsigned char *)emalloc(limit); diff --git a/ext/exif/tests/heic_meta_box_alloc.phpt b/ext/exif/tests/heic_meta_box_alloc.phpt new file mode 100644 index 000000000000..0a07d4c29bf0 --- /dev/null +++ b/ext/exif/tests/heic_meta_box_alloc.phpt @@ -0,0 +1,23 @@ +--TEST-- +HEIC meta box size must be bounded by the file size +--EXTENSIONS-- +exif +--INI-- +memory_limit=32M +--FILE-- + +--CLEAN-- + +--EXPECTF-- +Warning: exif_read_data(): Invalid HEIF file in %s on line %d +bool(false) diff --git a/ext/opcache/ZendAccelerator.c b/ext/opcache/ZendAccelerator.c index 8685fb564150..cf62765d9e1d 100644 --- a/ext/opcache/ZendAccelerator.c +++ b/ext/opcache/ZendAccelerator.c @@ -4742,11 +4742,11 @@ static void preload_load(size_t orig_map_ptr_static_last) size_t old_map_ptr_last = CG(map_ptr_last); if (zend_map_ptr_static_last != ZCSG(map_ptr_static_last) || old_map_ptr_last != ZCSG(map_ptr_last)) { CG(map_ptr_last) = ZCSG(map_ptr_last); - CG(map_ptr_size) = ZEND_MM_ALIGNED_SIZE_EX(ZCSG(map_ptr_last) + 1, 4096); + CG(map_ptr_size) = ZEND_MM_ALIGNED_SIZE_EX(ZCSG(map_ptr_last) + 1, ZEND_MAP_PTR_CHUNK_SIZE); zend_map_ptr_static_last = ZCSG(map_ptr_static_last); /* Grow map_ptr table as needed, but allocate once for static + regular map_ptrs */ - size_t new_static_size = ZEND_MM_ALIGNED_SIZE_EX(zend_map_ptr_static_last, 4096); + size_t new_static_size = ZEND_MM_ALIGNED_SIZE_EX(zend_map_ptr_static_last, ZEND_MAP_PTR_CHUNK_SIZE); if (zend_map_ptr_static_size != new_static_size) { void *new_base = pemalloc((new_static_size + CG(map_ptr_size)) * sizeof(void *), 1); if (CG(map_ptr_real_base)) {