Bug #68996 [Opn]: Invalid free of CG(interned_empty_string)

From: Date: Sat, 07 Feb 2015 18:06:54 +0000
Subject: Bug #68996 [Opn]: Invalid free of CG(interned_empty_string)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-190509@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68996&edit=1

 ID:                 68996
 User updated by:    manuel-php at mausz dot at
 Reported by:        manuel-php at mausz dot at
 Summary:            Invalid free of CG(interned_empty_string)
 Status:             Open
 Type:               Bug
 Package:            Reproducible crash
 PHP Version:        5.6.6RC1
 Block user comment: N
 Private report:     N

 New Comment:

Err, #68214 is another invalid free. Looks like main/main.c#L790 is an issue. Will update my PR in a
minute.


Previous Comments:
------------------------------------------------------------------------
[2015-02-07 17:57:51] manuel-php at mausz dot at

Btw, I've just found an existing bug report covering the first invalid free: https://bugs.php.net/bug.php?id=68214

------------------------------------------------------------------------
[2015-02-06 16:03:13] manuel-php at mausz dot at

PR: https://github.com/php/php-src/pull/1060

------------------------------------------------------------------------
[2015-02-06 15:58:17] manuel-php at mausz dot at

Description:
------------
If php_escape_html_entities fails CG(interned_empty_string) will be freed:

* If interned strings are enabled (default) STR_EMPTY_ALLOC is an alias for
CG(interned_empty_string)
see https://github.com/php/php-src/blob/PHP-5.6/Zend/zend.h#L682

* php_escape_html_entities_ex returns STR_EMPTY_ALLOC in case of failure
see https://github.com/php/php-src/blob/PHP-5.6/ext/standard/html.c#L1307

* php_escape_html_entities is used in php_verror if display_errors is enabled
see https://github.com/php/php-src/blob/PHP-5.6/main/main.c#L848

* Thus CG(interned_empty_string) gets freed
see https://github.com/php/php-src/blob/PHP-5.6/main/main.c#L921

This issue is even worse when opcache is enabled.

Sample script:
fopen("\xfc\x63", "r");

https://github.com/php/php-src/blob/PHP-5.6/ext/wddx/wddx.c#L408:
wddx_serialize_value("\xfc\x63");

https://github.com/php/php-src/blob/PHP-5.6/ext/wddx/wddx.c#L633:
wddx_serialize_value([ "\xfc\x63" => "foo" ]);

https://github.com/php/php-src/blob/PHP-5.6/ext/soap/soap.c#L3997
https://github.com/php/php-src/blob/PHP-5.6/ext/soap/soap.c#L4022
(new SoapServer(NULL, [ "location" => "http://foo", "uri" => "http://foo" ]))->fault("\xfc\x63", "foo");

No issues (imho):
https://github.com/php/php-src/blob/PHP-5.6/main/main.c#L790
https://github.com/php/php-src/blob/PHP-5.6/sapi/fpm/fpm/fpm_status.c#L421
https://github.com/php/php-src/blob/PHP-5.6/sapi/cli/php_cli_server.c#L1929
php_escape_html_entities calls in https://github.com/php/php-src/blob/PHP-5.6/info/info.c
are safe too



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=68996&edit=1


Thread (5 messages)

« previous php.bugs (#190509) next »