Bug #71861 [Fbk->Opn]: Buffer Overrun in curl_exec() causing hang
| From: | nikic@php.net | Date: | Mon, 28 Mar 2016 15:07:42 +0000 |
| Subject: | Bug #71861 [Fbk->Opn]: Buffer Overrun in curl_exec() causing hang | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-200188@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71861&edit=1
ID: 71861
Updated by: nikic@php.net
Reported by: paul at salesintel dot com
-Summary: RE-OPENED, MORE INFO, Buffer Overrun in curl_exec()
causing hang
+Summary: Buffer Overrun in curl_exec() causing hang
-Status: Feedback
+Status: Open
Type: Bug
Package: cURL related
Operating System: Windows 10 x64
PHP Version: 7.0.4
Block user comment: N
Private report: N
New Comment:
I've opened an issue at libcurl: https://github.com/curl/curl/issues/734
Previous Comments:
------------------------------------------------------------------------
[2016-03-28 14:52:35] nikic@php.net
These valgrind warnings are definitely not related to PHP. E.g. this is what I get running curl
directly from the CLI: https://gist.github.com/nikic/b7af10da8f73923a46a0
This does not necessarily mean that there is an issue in curl, as all of this starts with libssl,
which is notoriously valgrind unsafe (don't ask unless you want to hear an answer). However,
given the number of warnings originating in libcurl I'm inclined it doesn't seem unlikely
that there is a genuine issue there.
------------------------------------------------------------------------
[2016-03-28 13:57:56] krakjoe@php.net
Also, I forgot to mention, that I don't need cainfo set in php.ini, just used defaults.
------------------------------------------------------------------------
[2016-03-28 13:56:10] krakjoe@php.net
I am using a slightly different kind of build to laurence, libssl.
I can reproduce memory errors in PHP 5 and 7 using the following:
<?php
$ch = curl_init('https://mail.microsoft.com/ews/exchange.asmx');
curl_exec($ch);
Here's one from 5:
==22050== Conditional jump or move depends on uninitialised value(s)
==22050== at 0x6DC7A42: ??? (in /usr/lib/x86_64-linux-gnu/libcurl.so.4.3.0)
==22050== by 0x6DCB253: ??? (in /usr/lib/x86_64-linux-gnu/libcurl.so.4.3.0)
==22050== by 0x6DDFC27: ??? (in /usr/lib/x86_64-linux-gnu/libcurl.so.4.3.0)
==22050== by 0x6DE9ACB: ??? (in /usr/lib/x86_64-linux-gnu/libcurl.so.4.3.0)
==22050== by 0x6DEA270: curl_multi_perform (in /usr/lib/x86_64-linux-gnu/libcurl.so.4.3.0)
==22050== by 0x6DE18A2: curl_easy_perform (in /usr/lib/x86_64-linux-gnu/libcurl.so.4.3.0)
==22050== by 0x515CF5: zif_curl_exec (interface.c:2978)
==22050== by 0xA2AA64: zend_do_fcall_common_helper_SPEC (zend_vm_execute.h:558)
==22050== by 0xA31592: ZEND_DO_FCALL_SPEC_CONST_HANDLER (zend_vm_execute.h:2602)
==22050== by 0xA29CBD: execute_ex (zend_vm_execute.h:363)
==22050== by 0xA29DA3: zend_execute (zend_vm_execute.h:388)
==22050== by 0x9DD2CE: zend_execute_scripts (zend.c:1341)
Here's one from 7:
==22058== Conditional jump or move depends on uninitialised value(s)
==22058== at 0x6C5CA42: ??? (in /usr/lib/x86_64-linux-gnu/libcurl.so.4.3.0)
==22058== by 0x6C60253: ??? (in /usr/lib/x86_64-linux-gnu/libcurl.so.4.3.0)
==22058== by 0x6C74C27: ??? (in /usr/lib/x86_64-linux-gnu/libcurl.so.4.3.0)
==22058== by 0x6C7EACB: ??? (in /usr/lib/x86_64-linux-gnu/libcurl.so.4.3.0)
==22058== by 0x6C7F270: curl_multi_perform (in /usr/lib/x86_64-linux-gnu/libcurl.so.4.3.0)
==22058== by 0x6C768A2: curl_easy_perform (in /usr/lib/x86_64-linux-gnu/libcurl.so.4.3.0)
==22058== by 0x607D99: zif_curl_exec (interface.c:2875)
==22058== by 0xACA4F0: ZEND_DO_FCALL_BY_NAME_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:795)
==22058== by 0xAC9360: execute_ex (zend_vm_execute.h:424)
==22058== by 0xAC9562: zend_execute (zend_vm_execute.h:468)
==22058== by 0xA63628: zend_execute_scripts (zend.c:1427)
==22058== by 0x9A11AC: php_execute_script (main.c:2494)
This really does feel like a cURL bug, it would be best to make the cURL maintainers aware of the
problem.
------------------------------------------------------------------------
[2016-03-20 13:26:55] paul at salesintel dot com
If the curl library is different between 5.6 and 7.0, than maybe there's a bug in curl; there
is no hanging when running repro() in 5.6 as noted in the original bug report.
However, I would be surprised curl is coupling anything of their implementation to php cadence, and
given the significant change in memory management and access between 5.6 and 7.0, and that the
exception is saying something is uninitialized, I would think it more likely there's something
the 7.0 curl wrapper is doing differently that is the underlying cause, and the exception occurring
in the curl library is merely a symptom of it.
curl_exec() requires certain state to be configured before it's called, and that state is being
set through the php curl wrapper, which could be de-allocating or moving something around between
the state setting calls curl_init() & curl_setop(), and the curl_exec() call. What's also
suspect is that minor changes to several different curl_setop() arguments can either expose or hide
the problem.
I'm saying all this in hopes this issue isn't being 'punted' over to there being
something wrong with curl, without first empirically ruling out php, given the aforementioned
observations.
------------------------------------------------------------------------
[2016-03-20 12:41:24] laruence@php.net
Seems like a curl bug?
==95176== Conditional jump or move depends on uninitialised value(s)
==95176== at 0x79128CD: gnutls_session_get_data (in
/usr/lib/x86_64-linux-gnu/libgnutls.so.26.22.6)
==95176== by 0x63A0819: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0)
==95176== by 0x63A0D29: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0)
==95176== by 0x63A17EF: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0)
==95176== by 0x63650DD: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0)
==95176== by 0x63877F0: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0)
==95176== by 0x6388440: curl_multi_perform (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0)
==95176== by 0x637FBA2: curl_easy_perform (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0)
==95176== by 0x5F121B: zif_curl_exec (interface.c:2880)
==95176== by 0x9F2902: ZEND_DO_ICALL_SPEC_HANDLER (zend_vm_execute.h:586)
==95176== by 0x9F2331: execute_ex (zend_vm_execute.h:414)
==95176== by 0x9F2443: zend_execute (zend_vm_execute.h:458)
==95176== Uninitialised value was created by a stack allocation
==95176== at 0x63A0100: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0)
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71861
--
Edit this bug report at https://bugs.php.net/bug.php?id=71861&edit=1