php / php/php-src

sqlite segv

Open
#23,728 1 comment 0 reactions 1 assignee View on GitHub

@iliaal is already working on this.

Since Sep 17, 2026.

Bug Extension: sqlite3 Status: Verified
Dominant language
C
Stars
40.4k
Forks
8.1k
Avg merge
2d 13h
Merged PRs (30d)
96

Description

Description

The following code:

<?php
$db = new SQLite3(':memory:');
$db->createFunction('evil', function () {
    global $stmt;
    $stmt->close();       
    return 1;
});
$stmt = $db->prepare("SELECT evil()");
$res = $stmt->execute();

Resulted in this output (truncated):

==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000063 ... READ
    #0 sqlite3ApiExit  (libsqlite3.so.0+0x912b4)
    #1 sqlite3_step    (libsqlite3.so.0+0xe1fb0)
    #2 zim_SQLite3Stmt_execute  ext/sqlite3/sqlite3.c:1901:16
PHP Version
8.6.0-dev
Operating System

Ubuntu 22.04

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.