Commit d5710aefdf9 for php
commit d5710aefdf95f119555264d3bb2d866ce60e9278
Merge: c2e9c098f39 303e6aa82f2
Author: Weilin Du <weilindu@php.net>
Date: Thu Oct 8 17:35:57 2026 +0800
Merge branch 'PHP-8.4' into PHP-8.5
* PHP-8.4:
ext/zip: Fix use-after-free in the archive destructor path (#23779)
diff --cc NEWS
index 061ecfdf74c,e1a0b5527c7..9b485ee4559
--- a/NEWS
+++ b/NEWS
@@@ -7,7 -13,19 +7,11 @@@ PH
root trace at the opcache.jit_max_root_traces limit, causing spurious
"Too few arguments" errors and crashes). (RV7PR)
-- SOAP:
- . Fixed use of uninitialized func in do_request() on OOM bailout.
- (David Carlier)
-
-- Standard:
- . Fixed chown() and lchown() failing to resolve user names in ZTS builds
- when getpwnam_r() needs a larger buffer. (Ilia Alshanetsky)
-
+ - Zip:
+ . Fixed use-after-free when re-entering ZipArchive during destruction or
+ a close warning, and rejected opening streams while closing. (jvoisin)
+
-22 Oct 2026, PHP 8.4.27
+22 Oct 2026, PHP 8.5.12
- BCMath:
. Fixed BcMath\Number results that truncate to zero keeping a negative sign
diff --cc ext/zip/php_zip.c
index 12d004cc27d,65f80743f1b..8fce5d4a2c2
--- a/ext/zip/php_zip.c
+++ b/ext/zip/php_zip.c
@@@ -1046,8 -1089,13 +1046,12 @@@ static void php_zip_progress_callback_f
{
php_zip_archive *archive = ptr;
+ if (UNEXPECTED(!EG(active))) {
+ return;
+ }
+
- if (!Z_ISUNDEF(archive->progress_callback)) {
- zval_ptr_dtor(&archive->progress_callback);
- ZVAL_UNDEF(&archive->progress_callback);
+ if (ZEND_FCC_INITIALIZED(archive->progress_callback)) {
+ zend_fcc_dtor(&archive->progress_callback);
}
}
#endif
@@@ -1057,8 -1105,13 +1061,12 @@@ static void php_zip_cancel_callback_fre
{
php_zip_archive *archive = ptr;
+ if (UNEXPECTED(!EG(active))) {
+ return;
+ }
+
- if (!Z_ISUNDEF(archive->cancel_callback)) {
- zval_ptr_dtor(&archive->cancel_callback);
- ZVAL_UNDEF(&archive->cancel_callback);
+ if (ZEND_FCC_INITIALIZED(archive->cancel_callback)) {
+ zend_fcc_dtor(&archive->cancel_callback);
}
}
#endif