Commit c88c89e351c for php
commit c88c89e351c2cce6c98d908e8ac5093060685d81
Author: lazerg <lazerg2@gmail.com>
Date: Mon Oct 5 22:43:08 2026 +0500
Fix GH-24139: NULL dereference in php_ini.c when expand_filepath() fails
Close GH-24141
diff --git a/NEWS b/NEWS
index fd9ab08cd72..999d1f6fc5a 100644
--- a/NEWS
+++ b/NEWS
@@ -56,6 +56,8 @@ PHP NEWS
when (object) and use share an array). (David Carlier)
. Fixed exception thrown by destructor during GC in a Fiber not being rethrown
into the frame that triggered the GC. (Nicolas Grekas)
+ . Fixed bug GH-24139 (NULL pointer dereference in php_ini.c when
+ expand_filepath() fails). (lazerg)
- DOM:
. Fixed use-after-free when re-constructing a DOMXPath whose php:function
diff --git a/main/php_ini.c b/main/php_ini.c
index 5487564ec22..59b69a5d6fc 100644
--- a/main/php_ini.c
+++ b/main/php_ini.c
@@ -563,7 +563,13 @@ int php_init_config(void)
fp = VCWD_FOPEN(php_ini_file_name, "r");
if (fp) {
filename = expand_filepath(php_ini_file_name, NULL);
- free_filename = true;
+ if (filename) {
+ free_filename = true;
+ } else {
+ /* Reject the file, like ZTS where VCWD_STAT() already fails */
+ fclose(fp);
+ fp = NULL;
+ }
}
}
}
diff --git a/sapi/cli/tests/gh24139.phpt b/sapi/cli/tests/gh24139.phpt
new file mode 100644
index 00000000000..503b853ecfd
--- /dev/null
+++ b/sapi/cli/tests/gh24139.phpt
@@ -0,0 +1,30 @@
+--TEST--
+GH-24139 (NULL pointer dereference in php_ini.c when expand_filepath() fails)
+--SKIPIF--
+<?php
+include "skipif.inc";
+if (PHP_OS_FAMILY === "Windows") die("skip not for Windows");
+?>
+--FILE--
+<?php
+$ini_file = __DIR__ . "/gh24139.ini";
+file_put_contents($ini_file, "gh24139=ok\n");
+
+$relative = str_repeat("./", intdiv(PHP_MAXPATHLEN - strlen(__DIR__), 2)) . "gh24139.ini";
+
+$proc = proc_open(
+ [getenv("TEST_PHP_EXECUTABLE"), "-c", $relative, "-r", 'var_dump(get_cfg_var("gh24139"));'],
+ [1 => ["pipe", "w"]],
+ $pipes,
+ __DIR__
+);
+echo stream_get_contents($pipes[1]);
+var_dump(proc_close($proc));
+?>
+--CLEAN--
+<?php
+@unlink(__DIR__ . "/gh24139.ini");
+?>
+--EXPECT--
+bool(false)
+int(0)