Bug #71861 [Opn]: RE-OPENED, MORE INFO, Buffer Overrun in curl_exec() causing hang

From: Date: Sun, 20 Mar 2016 13:27:01 +0000
Subject: Bug #71861 [Opn]: RE-OPENED, MORE INFO, Buffer Overrun in curl_exec() causing hang
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-199964@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71861&edit=1 ID: 71861 User updated by: paul at salesintel dot com Reported by: paul at salesintel dot com Summary: RE-OPENED, MORE INFO, Buffer Overrun in curl_exec() causing hang Status: Open Type: Bug Package: cURL related Operating System: Windows 10 x64 PHP Version: 7.0.4 Block user comment: N Private report: N New Comment: If the curl library is different between 5.6 and 7.0, than maybe there's a bug in curl; there is no hanging when running repro() in 5.6 as noted in the original bug report. However, I would be surprised curl is coupling anything of their implementation to php cadence, and given the significant change in memory management and access between 5.6 and 7.0, and that the exception is saying something is uninitialized, I would think it more likely there's something the 7.0 curl wrapper is doing differently that is the underlying cause, and the exception occurring in the curl library is merely a symptom of it. curl_exec() requires certain state to be configured before it's called, and that state is being set through the php curl wrapper, which could be de-allocating or moving something around between the state setting calls curl_init() & curl_setop(), and the curl_exec() call. What's also suspect is that minor changes to several different curl_setop() arguments can either expose or hide the problem. I'm saying all this in hopes this issue isn't being 'punted' over to there being something wrong with curl, without first empirically ruling out php, given the aforementioned observations. Previous Comments: ------------------------------------------------------------------------ [2016-03-20 12:41:24] laruence@php.net Seems like a curl bug? ==95176== Conditional jump or move depends on uninitialised value(s) ==95176== at 0x79128CD: gnutls_session_get_data (in /usr/lib/x86_64-linux-gnu/libgnutls.so.26.22.6) ==95176== by 0x63A0819: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0) ==95176== by 0x63A0D29: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0) ==95176== by 0x63A17EF: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0) ==95176== by 0x63650DD: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0) ==95176== by 0x63877F0: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0) ==95176== by 0x6388440: curl_multi_perform (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0) ==95176== by 0x637FBA2: curl_easy_perform (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0) ==95176== by 0x5F121B: zif_curl_exec (interface.c:2880) ==95176== by 0x9F2902: ZEND_DO_ICALL_SPEC_HANDLER (zend_vm_execute.h:586) ==95176== by 0x9F2331: execute_ex (zend_vm_execute.h:414) ==95176== by 0x9F2443: zend_execute (zend_vm_execute.h:458) ==95176== Uninitialised value was created by a stack allocation ==95176== at 0x63A0100: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0) ------------------------------------------------------------------------ [2016-03-19 20:15:50] paul at salesintel dot com I could not reopen the original bug # 71563 ------------------------------------------------------------------------ [2016-03-19 20:14:32] paul at salesintel dot com Description: ------------ When a couple of cURL options are set in a specific and valid way, and the curl.cainfo is set in php.ini, curl_exec() never returns and PHP does not throw any exception, causing indefinite hang. Same code in php 5.6.x (in each x32/x64 ts/nts) worked as expected. In php 7.0.4 x32/x64 nts builds, hang occurs (ts versions not tried). Test script: --------------- FILE php.ini: ;change root path of your php accordingly extension_dir = "C:\bin\php\7.0.4\nts-x32\ext\" extension=php_curl.dll curl.cainfo = "C:\bin\php\cacert.pem" ;cacert.pem downloaded from "https://curl.haxx.se/ca/cacert.pem" FILE repro.php <?php repro(); function repro() { $location = 'https://mail.microsoft.com/ews/exchange.asmx'; $request = str_repeat(' ', 1025); $ch = curl_init($location); curl_setopt($ch, CURLOPT_POSTFIELDS, $request); curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC | CURLAUTH_NTLM); curl_setopt($ch, CURLOPT_USERPWD, ' '); $response = curl_exec($ch); } Expected result: ---------------- Call to curl_exec($ch) returns. Actual result: -------------- Call to curl_exec($ch) never returns. However.... If you comment out the "curl.cainfo=" setting in php.ini, curl_exec($ch) returns. If you change $location to an invalid endpoint or one that does not require NTLM, curl_exec() returns. If you remove the 'CURLAUTH_BASIC' leaving only 'CURLAUTH_NTLM', curl_exec() returns; If you remove 'CURLAUTH_NTLM' leaving only 'CURLAUTH_BASIC', curl_exec() returns; If you set an empty string ('') instead of one with one or more characters to CURLOPT_USERPWD, curl_exec() returns. $request is a string with 1025 characters. If you remove one character, leaving a (suspiciously sized) 1024 character length $request, curl_exec($ch) returns. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=71861&edit=1

« previous php.bugs (#199964) next »