From 257016d4603dbb08bc26bc3d8626430610b1449f Mon Sep 17 00:00:00 2001 From: ushevchenko Date: Thu, 1 Oct 2026 11:35:09 +0300 Subject: [PATCH] Fix: DEREF_AFTER_NULL.EX.COND Problem: PHPDBG_COMMAND(list) passes a NULL param to PHPDBG_LIST(lines), which dereferences it in switch (param->type) without a NULL check. A NULL pointer may be dereferenced. Solution: add a NULL check at the beginning of PHPDBG_LIST(lines): report an error and return SUCCESS. Signed-off-by: u.shevchenko@fobos-nt.ru Signed-off-by: crystarm@altlinux.org --- sapi/phpdbg/phpdbg_list.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/sapi/phpdbg/phpdbg_list.c b/sapi/phpdbg/phpdbg_list.c index 3931fc9c1525..fb4f091ab8ca 100644 --- a/sapi/phpdbg/phpdbg_list.c +++ b/sapi/phpdbg/phpdbg_list.c @@ -44,6 +44,11 @@ const phpdbg_command_t phpdbg_list_commands[] = { PHPDBG_LIST(lines) /* {{{ */ { + if (!param) { + phpdbg_error("A line number or file is required"); + return SUCCESS; + } + if (!PHPDBG_G(exec) && !zend_is_executing()) { phpdbg_error("Not executing, and execution context not set"); return SUCCESS;