Sec Bug->Bug #71735 [Opn]: Double-free in SplDoublyLinkedList::offsetSet

From: Date: Mon, 21 Mar 2016 06:10:56 +0000
Subject: Sec Bug->Bug #71735 [Opn]: Double-free in SplDoublyLinkedList::offsetSet
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-199981@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71735&edit=1 ID: 71735 Updated by: stas@php.net Reported by: emmanuel dot law at gmail dot com Summary: Double-free in SplDoublyLinkedList::offsetSet Status: Open -Type: Security +Type: Bug Package: SPL related Operating System: * PHP Version: 7.0.4 Block user comment: N Private report: Y Previous Comments: ------------------------------------------------------------------------ [2016-03-21 05:17:25] stas@php.net Doesn't look like a security issue - requires specially crafted code to reproduce the bug. ------------------------------------------------------------------------ [2016-03-07 23:31:33] emmanuel dot law at gmail dot com Description: ------------ This issues only affects php 7.x branch. There exist a double-free vulnerability when calling SplDoublyLinkedList::offsetSet and passing in an invalid index. Example: $var_1=new SplStack(); $var_1->offsetSet(100,new DateTime('2000-01-01')); //DateTime will be double-freed The vulnerability is in ext/spl_dllist.c:833 where it is freed once: 832 if (index < 0 || index >= intern->llist->count) { 833 zval_ptr_dtor(value); 834 zend_throw_exception(spl_ce_OutOfRangeException, "Offset invalid or out of range", 0); 835 return; 836 } 837 The second free occurs in Zend/zend_vm_execute.h:855 when it cleans up the call stack: 854 EG(current_execute_data) = call->prev_execute_data; 855 zend_vm_stack_free_args(call); I've created a poc that exploits this to gain code execution: gdb --args php_7.0.4 doublefree.spl_dllist.poc.php .... Stopped reason: SIGSEGV 0x00000000deadbeef in ?? () gdb-peda$ p $rip $1 = (void (*)()) 0xdeadbeef POC can be obtained via https://www.dropbox.com/s/2tm8mlrdhfitymv/doublefree.SplStack.poc.php?dl=0 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=71735&edit=1

« previous php.bugs (#199981) next »