Bug #69139 [NEW]: Crash in gc_zval_possible_root on unserialize
| From: | emilio dot pinn at gmail dot com | Date: | Fri, 27 Feb 2015 16:39:29 +0000 |
| Subject: | Bug #69139 [NEW]: Crash in gc_zval_possible_root on unserialize | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-190993@lists.php.net to get a copy of this message | ||
From: emilio dot pinn at gmail dot com
Operating system: Ubuntu 14.04.2 LTS
PHP version: 5.6.6
Package: Reproducible crash
Bug Type: Bug
Bug description:Crash in gc_zval_possible_root on unserialize
Description:
------------
PHP versions: 5.6.6, reproduced also in 5.6.5 and 5.5.9(-1ubuntu4.6)
Reproduction:
The PHP interpreter (tested both on CLI and on apache module) crashes
when unserializing a specific string.
$ cat payload
a:1126666:{i:0;r:1;i:-09610;r:1;i:-0;i:0;i:0;O:1:"A":2119X:i:0;i:0;i:0;i:0;i:0;O:1:"A":2116:{i:0;r:5;i:-096766610;r:1;i:-610;r:1;i:-0;i:0;i:0;O:1:"A":2119X:i:0;i:0;i:0;i:0;i:0;O:1:"A":-0;i:00;i:0;i:0;O:1:""A
$ gdb sapi/cli/php
(gdb) run -r 'unserialize(file_get_contents("payload"));'
Starting program: /archivio/assessments/afl-php/php-5.6.6/sapi/cli/php
-r 'unserialize(file_get_contents("payload"));'
Program received signal SIGSEGV, Segmentation fault.
0x00000000007e7653 in gc_zval_possible_root (zv=0x7ffff7fc3c70) at
/archivio/assessments/afl-php/php-5.6.6/Zend/zend_gc.c:143
143 GC_ZOBJ_CHECK_POSSIBLE_ROOT(zv);
(gdb) bt
#0 0x00000000007e7653 in gc_zval_possible_root (zv=0x7ffff7fc3c70) at
/archivio/assessments/afl-php/php-5.6.6/Zend/zend_gc.c:143
#1 0x00000000007a8501 in gc_zval_check_possible_root (z=0x7ffff7fc3c70)
at /archivio/assessments/afl-php/php-5.6.6/Zend/zend_gc.h:183
#2 i_zval_ptr_dtor (zval_ptr=0x7ffff7fc3c70) at
/archivio/assessments/afl-php/php-5.6.6/Zend/zend_execute.h:86
#3 _zval_ptr_dtor (zval_ptr=0x7ffff7fc6d90) at
/archivio/assessments/afl-php/php-5.6.6/Zend/zend_execute_API.c:424
#4 0x0000000000704495 in var_destroy (var_hashx=0x7fffffffc368) at
/archivio/assessments/afl-php/php-5.6.6/ext/standard/var_unserializer.c:174
#5 0x00000000006f2079 in zif_unserialize (ht=1,
return_value=0x7ffff7fc2e48, return_value_ptr=0x7ffff7f8e0a0,
this_ptr=0x0, return_value_used=0)
at /archivio/assessments/afl-php/php-5.6.6/ext/standard/var.c:966
#6 0x0000000000805c2a in zend_do_fcall_common_helper_SPEC
(execute_data=0x7ffff7f8e0d8) at
/archivio/assessments/afl-php/php-5.6.6/Zend/zend_vm_execute.h:558
#7 0x000000000080da25 in ZEND_DO_FCALL_SPEC_CONST_HANDLER
(execute_data=0x7ffff7f8e0d8) at
/archivio/assessments/afl-php/php-5.6.6/Zend/zend_vm_execute.h:2595
#8 0x0000000000803fed in execute_ex (execute_data=0x7ffff7f8e0d8) at
/archivio/assessments/afl-php/php-5.6.6/Zend/zend_vm_execute.h:363
#9 0x0000000000804a2a in zend_execute (op_array=0x7ffff7fc35d0) at
/archivio/assessments/afl-php/php-5.6.6/Zend/zend_vm_execute.h:388
#10 0x00000000007ab4cd in zend_eval_stringl (str=0xf8a520
"unserialize(file_get_contents(\"payload\"));", str_len=42,
retval_ptr=0x0,
string_name=0xc6f564 "Command line code") at
/archivio/assessments/afl-php/php-5.6.6/Zend/zend_execute_API.c:1077
#11 0x00000000007ab79e in zend_eval_stringl_ex (str=0xf8a520
"unserialize(file_get_contents(\"payload\"));", str_len=42,
retval_ptr=0x0,
string_name=0xc6f564 "Command line code", handle_exceptions=1) at
/archivio/assessments/afl-php/php-5.6.6/Zend/zend_execute_API.c:1124
#12 0x00000000007ab820 in zend_eval_string_ex (str=0xf8a520
"unserialize(file_get_contents(\"payload\"));", retval_ptr=0x0,
string_name=0xc6f564 "Command line code",
handle_exceptions=1) at
/archivio/assessments/afl-php/php-5.6.6/Zend/zend_execute_API.c:1135
#13 0x00000000008e43eb in do_cli (argc=3, argv=0xf8a490) at
/archivio/assessments/afl-php/php-5.6.6/sapi/cli/php_cli.c:1034
#14 0x00000000008e550b in main (argc=3, argv=0xf8a490) at
/archivio/assessments/afl-php/php-5.6.6/sapi/cli/php_cli.c:1378
(gdb)
The crash has been found with afl-fuzz.
Test script:
---------------
Please find here a downloadable link of the payload above
https://www.dropbox.com/s/mnibxz6xga0dbcr/crash_payload?dl=0
--
Edit bug report at https://bugs.php.net/bug.php?id=69139&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=69139&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=69139&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=69139&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=69139&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=69139&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=69139&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=69139&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=69139&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=69139&r=support
Expected behavior: https://bugs.php.net/fix.php?id=69139&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=69139&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=69139&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=69139&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=69139&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=69139&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=69139&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=69139&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=69139&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=69139&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=69139&r=mysqlcfg