Bug #71584 [NEW]: Possible use-after-free of ZCG(cwd) in Zend Opcache

From: Date: Sat, 13 Feb 2016 17:43:19 +0000
Subject: Bug #71584 [NEW]: Possible use-after-free of ZCG(cwd) in Zend Opcache
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-199195@lists.php.net to get a copy of this message
From: dev at pp3345 dot net Operating system: Any PHP version: master-Git-2016-02-13 (Git) Package: opcache Bug Type: Bug Bug description:Possible use-after-free of ZCG(cwd) in Zend Opcache Description: ------------ Zend Opcache caches the current working directory in ZCG(cwd) and therefore overrides chdir() in order to update the cached directory name when a script switches directories. The hook on chdir() is set in accel_startup() if opcache.enable is true. ZCG(cwd) is free'd in accel_deactivate(), but only if opcache.enable *still* is true. Since Zend extension shutdown functions are called before resetting INI configuration state, a script (or, for example, php_admin_flag in fpm SAPI) may disable Opcache at runtime by setting opcache.enable to false. In this case, the pointer is not correctly free'd and will be reused in the next request, although it became invalid due to being free'd by the Zend allocator. This leads to a use-after-free error and may cause a segmentation fault. I am going to attach two pull requests that fix the problem by freeing ZCG(cwd) in accel_deactivate() even if Opcache is disabled. Test script: --------------- Due to the nature of this bug, it's impossible to create a test script that will *always* crash. For testing, I've set opcache.enable=1 in php.ini and php_admin_flag[opcache_enable]=off in my FPM pool. Afterwards, I've made requests to two scripts that simply chdir() to different directories. At some point of time, the FPM workers segfaulted. -- Edit bug report at https://bugs.php.net/bug.php?id=71584&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=71584&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=71584&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=71584&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=71584&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=71584&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=71584&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=71584&r=needscript Try newer version: https://bugs.php.net/fix.php?id=71584&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=71584&r=support Expected behavior: https://bugs.php.net/fix.php?id=71584&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=71584&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=71584&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=71584&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=71584&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=71584&r=dst IIS Stability: https://bugs.php.net/fix.php?id=71584&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=71584&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=71584&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=71584&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=71584&r=mysqlcfg

« previous php.bugs (#199195) next »