Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions ext/json/json_encoder.c
Original file line number Diff line number Diff line change
Expand Up @@ -581,6 +581,11 @@ static zend_result php_json_encode_serializable_object(smart_str *buf, zend_obje

ZEND_GUARD_PROTECT_RECURSION(guard, JSON);

/* jsonSerialize() may run a user error handler that drops the last
* reference to the object; keep it alive so the recursion guard and the
* identity check below stay valid. */
GC_ADDREF(obj);

zend_function *json_serialize_method = zend_hash_str_find_ptr(&ce->function_table, ZEND_STRL("jsonserialize"));
ZEND_ASSERT(json_serialize_method != NULL && "This should be guaranteed prior to calling this function");
zend_call_known_function(json_serialize_method, obj, ce, &retval, 0, NULL, NULL);
Expand All @@ -590,6 +595,7 @@ static zend_result php_json_encode_serializable_object(smart_str *buf, zend_obje
smart_str_appendl(buf, "null", 4);
}
ZEND_GUARD_UNPROTECT_RECURSION(guard, JSON);
OBJ_RELEASE(obj);
return FAILURE;
}

Expand All @@ -604,6 +610,7 @@ static zend_result php_json_encode_serializable_object(smart_str *buf, zend_obje
}

zval_ptr_dtor(&retval);
OBJ_RELEASE(obj);

return return_code;
}
Expand Down
21 changes: 21 additions & 0 deletions ext/json/tests/gh21024.phpt
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
--TEST--
GH-21024 (UAF in json_encode() when jsonSerialize()'s error handler frees the object)
--EXTENSIONS--
json
--FILE--
<?php
class Bar implements JsonSerializable {
public function jsonSerialize(): mixed {
echo $undefined;
return ['k' => 1];
}
}
$arr = [new Bar];
$ref = &$arr[0];
set_error_handler(function () use (&$ref) { $ref = null; });
var_dump(json_encode($arr));
echo "survived\n";
?>
--EXPECT--
string(9) "[{"k":1}]"
survived
Loading