Commit 026bb4e1ffa for php
commit 026bb4e1ffa64534be77e146b7979404c57c9efc
Author: Daniel Scherzer <daniel.e.scherzer+phpf@gmail.com>
Date: Fri Oct 2 18:28:08 2026 -0700
ext/soap: fix leak when `load_wsdl_ex()` fails to load (#24066)
diff --git a/NEWS b/NEWS
index 38a3f909e85..326a9fe7986 100644
--- a/NEWS
+++ b/NEWS
@@ -182,6 +182,7 @@ PHP NEWS
- SOAP:
. Fixed bug GH-22895 (Heap use-after-free while encoding a Traversable with
an illegal key). (David Carlier)
+ . Fixed memory leak when load_wsdl_ex() failed to load. (DanielEScherzer)
- Sockets:
. Fixed socket_select() silently truncating sets larger than FD_SETSIZE on
diff --git a/ext/soap/php_sdl.c b/ext/soap/php_sdl.c
index 7aa9e9fae25..e53da38c33f 100644
--- a/ext/soap/php_sdl.c
+++ b/ext/soap/php_sdl.c
@@ -364,7 +364,12 @@ static void load_wsdl_ex(zval *this_ptr, char *struri, sdlCtx *ctx, int include)
xmlAttrPtr tmp = get_attribute(trav->properties, "location");
if (tmp) {
xmlChar *uri = schema_location_construct_uri(tmp);
- load_wsdl_ex(this_ptr, (char*)uri, ctx, 1);
+ zend_try {
+ load_wsdl_ex(this_ptr, (char*)uri, ctx, 1);
+ } zend_catch {
+ xmlFree(uri);
+ zend_bailout();
+ } zend_end_try();
xmlFree(uri);
}
diff --git a/ext/soap/tests/load_wsdl_ex-failure-leak.phpt b/ext/soap/tests/load_wsdl_ex-failure-leak.phpt
new file mode 100644
index 00000000000..b71c6183a51
--- /dev/null
+++ b/ext/soap/tests/load_wsdl_ex-failure-leak.phpt
@@ -0,0 +1,18 @@
+--TEST--
+load_wsdl_ex() leaks the import location if imported WSDL fails to load
+--EXTENSIONS--
+soap
+--INI--
+soap.wsdl_cache_enabled=0
+--FILE--
+<?php
+
+try {
+ $client = new SoapClient(__DIR__ . '/load_wsdl_ex-failure-leak.wsdl');
+} catch (SoapFault $e) {
+ echo get_class($e) . ': ' . $e->getMessage() . "\n";
+}
+
+?>
+--EXPECTF--
+SoapFault: SOAP-ERROR: Parsing WSDL: Couldn't load from '%sload_wsdl_ex-failure-leak-missing.wsdl' : %s
diff --git a/ext/soap/tests/load_wsdl_ex-failure-leak.wsdl b/ext/soap/tests/load_wsdl_ex-failure-leak.wsdl
new file mode 100644
index 00000000000..b9065bbeb1d
--- /dev/null
+++ b/ext/soap/tests/load_wsdl_ex-failure-leak.wsdl
@@ -0,0 +1,7 @@
+<?xml version="1.0" encoding="utf-8"?>
+<definitions
+ xmlns:soap="http://schemas.xmlsoap.org/wsdl/soap/"
+ xmlns="http://schemas.xmlsoap.org/wsdl/"
+>
+ <import location="load_wsdl_ex-failure-leak-missing.wsdl"/>
+</definitions>