diff --git a/NEWS b/NEWS index 7f4d24f6b0a6..d9c71758bf28 100644 --- a/NEWS +++ b/NEWS @@ -15,6 +15,8 @@ PHP NEWS - MBString: . Fixed bug GH-22779 (mb_strrpos() returns the wrong position for a negative offset in a non-UTF-8 encoding). (Eyüp Can Akman) + . Fixed bug GH-21036 (mb_ereg_search_getregs() crashes after mb_eregi() + invalidates the regex cache). (Matthias Goergens) - PCRE: . Fixed bug GH-21134 (Crash with \C + UTF-8). Using \C in UTF-8 patterns is diff --git a/ext/mbstring/php_mbregex.c b/ext/mbstring/php_mbregex.c index 0a62b6c22898..e823b5529818 100644 --- a/ext/mbstring/php_mbregex.c +++ b/ext/mbstring/php_mbregex.c @@ -481,6 +481,10 @@ static php_mb_regex_t *php_mbregex_compile_pattern(const char *pattern, size_t p if (rc == MBREX(search_re)) { /* reuse the new rc? see bug #72399 */ MBREX(search_re) = NULL; + if (MBREX(search_regs) != NULL) { + onig_region_free(MBREX(search_regs), 1); + MBREX(search_regs) = NULL; + } } zend_hash_str_update_ptr(&MBREX(ht_rc), (char *)pattern, patlen, retval); } else { diff --git a/ext/mbstring/tests/gh21036.phpt b/ext/mbstring/tests/gh21036.phpt new file mode 100644 index 000000000000..495d261c36bb --- /dev/null +++ b/ext/mbstring/tests/gh21036.phpt @@ -0,0 +1,21 @@ +--TEST-- +GH-21036 (mb_ereg_search_getregs() after regex cache invalidation) +--EXTENSIONS-- +mbstring +--SKIPIF-- + +--FILE-- +a)'; +mb_ereg_search_init('a', $pattern); +mb_ereg_search_pos(); +mb_eregi($pattern, 'a'); + +var_dump(mb_ereg_search_getregs()); +?> +--EXPECT-- +bool(false)