Bug #71584 [NEW]: Possible use-after-free of ZCG(cwd) in Zend Opcache
| From: | dev at pp3345 dot net | Date: | Sat, 13 Feb 2016 17:43:19 +0000 |
| Subject: | Bug #71584 [NEW]: Possible use-after-free of ZCG(cwd) in Zend Opcache | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-199195@lists.php.net to get a copy of this message | ||
From: dev at pp3345 dot net
Operating system: Any
PHP version: master-Git-2016-02-13 (Git)
Package: opcache
Bug Type: Bug
Bug description:Possible use-after-free of ZCG(cwd) in Zend Opcache
Description:
------------
Zend Opcache caches the current working directory in ZCG(cwd) and
therefore overrides chdir() in order to update the cached directory name
when a script switches directories. The hook on chdir() is set in
accel_startup() if opcache.enable is true. ZCG(cwd) is free'd in
accel_deactivate(), but only if opcache.enable *still* is true. Since
Zend extension shutdown functions are called before resetting INI
configuration state, a script (or, for example, php_admin_flag in fpm
SAPI) may disable Opcache at runtime by setting opcache.enable to false.
In this case, the pointer is not correctly free'd and will be reused in
the next request, although it became invalid due to being free'd by the
Zend allocator. This leads to a use-after-free error and may cause a
segmentation fault.
I am going to attach two pull requests that fix the problem by freeing
ZCG(cwd) in accel_deactivate() even if Opcache is disabled.
Test script:
---------------
Due to the nature of this bug, it's impossible to create a test script
that will *always* crash. For testing, I've set opcache.enable=1 in
php.ini and php_admin_flag[opcache_enable]=off in my FPM pool.
Afterwards, I've made requests to two scripts that simply chdir() to
different directories. At some point of time, the FPM workers
segfaulted.
--
Edit bug report at https://bugs.php.net/bug.php?id=71584&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=71584&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=71584&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=71584&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=71584&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=71584&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=71584&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=71584&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=71584&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=71584&r=support
Expected behavior: https://bugs.php.net/fix.php?id=71584&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=71584&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=71584&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=71584&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=71584&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=71584&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=71584&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=71584&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=71584&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=71584&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=71584&r=mysqlcfg