Commit c88c89e351c for php

commit c88c89e351c2cce6c98d908e8ac5093060685d81
Author: lazerg <lazerg2@gmail.com>
Date:   Mon Oct 5 22:43:08 2026 +0500

    Fix GH-24139: NULL dereference in php_ini.c when expand_filepath() fails

    Close GH-24141

diff --git a/NEWS b/NEWS
index fd9ab08cd72..999d1f6fc5a 100644
--- a/NEWS
+++ b/NEWS
@@ -56,6 +56,8 @@ PHP                                                                        NEWS
     when (object) and use share an array). (David Carlier)
   . Fixed exception thrown by destructor during GC in a Fiber not being rethrown
     into the frame that triggered the GC. (Nicolas Grekas)
+  . Fixed bug GH-24139 (NULL pointer dereference in php_ini.c when
+    expand_filepath() fails). (lazerg)

 - DOM:
   . Fixed use-after-free when re-constructing a DOMXPath whose php:function
diff --git a/main/php_ini.c b/main/php_ini.c
index 5487564ec22..59b69a5d6fc 100644
--- a/main/php_ini.c
+++ b/main/php_ini.c
@@ -563,7 +563,13 @@ int php_init_config(void)
 					fp = VCWD_FOPEN(php_ini_file_name, "r");
 					if (fp) {
 						filename = expand_filepath(php_ini_file_name, NULL);
-						free_filename = true;
+						if (filename) {
+							free_filename = true;
+						} else {
+							/* Reject the file, like ZTS where VCWD_STAT() already fails */
+							fclose(fp);
+							fp = NULL;
+						}
 					}
 				}
 			}
diff --git a/sapi/cli/tests/gh24139.phpt b/sapi/cli/tests/gh24139.phpt
new file mode 100644
index 00000000000..503b853ecfd
--- /dev/null
+++ b/sapi/cli/tests/gh24139.phpt
@@ -0,0 +1,30 @@
+--TEST--
+GH-24139 (NULL pointer dereference in php_ini.c when expand_filepath() fails)
+--SKIPIF--
+<?php
+include "skipif.inc";
+if (PHP_OS_FAMILY === "Windows") die("skip not for Windows");
+?>
+--FILE--
+<?php
+$ini_file = __DIR__ . "/gh24139.ini";
+file_put_contents($ini_file, "gh24139=ok\n");
+
+$relative = str_repeat("./", intdiv(PHP_MAXPATHLEN - strlen(__DIR__), 2)) . "gh24139.ini";
+
+$proc = proc_open(
+    [getenv("TEST_PHP_EXECUTABLE"), "-c", $relative, "-r", 'var_dump(get_cfg_var("gh24139"));'],
+    [1 => ["pipe", "w"]],
+    $pipes,
+    __DIR__
+);
+echo stream_get_contents($pipes[1]);
+var_dump(proc_close($proc));
+?>
+--CLEAN--
+<?php
+@unlink(__DIR__ . "/gh24139.ini");
+?>
+--EXPECT--
+bool(false)
+int(0)