If the integer addition in `ZEND_MM_ALIGNED_SIZE_EX` overflows, the
macro evaluates to `0`, what we should catch early.
- Core:
. Fixed bug #78535 (auto_detect_line_endings value not parsed as bool).
(bugreportuser)
+ . Fixed bug #78620 (Out of memory error). (cmb)
- Exif:
. Fixed bug #78442 ('Illegal component' on exif_read_data since PHP7)
void *ptr;
#if ZEND_MM_LIMIT
+ if (UNEXPECTED(new_size == 0)) {
+ /* overflow in ZEND_MM_ALIGNED_SIZE_EX */
+ goto memory_limit_exhausted;
+ }
if (UNEXPECTED(new_size > heap->limit - heap->real_size)) {
if (zend_mm_gc(heap) && new_size <= heap->limit - heap->real_size) {
/* pass */
} else if (heap->overflow == 0) {
+memory_limit_exhausted:
#if ZEND_DEBUG
zend_mm_safe_error(heap, "Allowed memory size of %zu bytes exhausted at %s:%d (tried to allocate %zu bytes)", heap->limit, __zend_filename, __zend_lineno, size);
#else