Skip to content

Add NULL check on zend_hash_index_find() return value in extract_token_id_to_replace() - #23707

Closed
ushevchenko wants to merge 1 commit into
php:masterfrom
ushevchenko:fix/extract-token-null-check
Closed

ushevchenko wants to merge 1 commit into
php:masterfrom
ushevchenko:fix/extract-token-null-check

Conversation

@ushevchenko

Copy link
Copy Markdown

Fixes #23704

Adds a NULL check on the return value of zend_hash_index_find() in extract_token_id_to_replace() (ext/tokenizer/tokenizer.c), consistent with how this function's return value is checked at other call sites in the codebase, and consistent with how this same function already returns NULL for other malformed-input cases. See the linked issue for details — this was flagged by static analysis (statistical NULL-deref checker), not by an observed crash.

Problem:
Return value of zend_hash_index_find() is dereferenced in extract_token_id_to_replace() without checking for NULL.
Solution: added NULL check for text_zv before dereference.
Signed-off-by: u.shevchenko@fobos-nt.ru
Signed-off-by: crystarm@altlinux.org
@ndossche

Copy link
Copy Markdown
Member

These tokens arrays are created by this extension and is always an array of 3 elements; so this is a bogus bug report.

But note that even if this were not the case then this patch doesn't make much sense as you'd have to signal to userland that something went wrong.

@ndossche ndossche closed this Sep 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Missing NULL check on zend_hash_index_find() return value in extract_token_id_to_replace() (ext/tokenizer/tokenizer.c)

2 participants