Bug #71861 [Opn->Ver]: Buffer Overrun in curl_exec() causing hang

From: Date: Mon, 28 Mar 2016 19:55:13 +0000
Subject: Bug #71861 [Opn->Ver]: Buffer Overrun in curl_exec() causing hang
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-200192@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71861&edit=1

 ID:                 71861
 Updated by:         nikic@php.net
 Reported by:        paul at salesintel dot com
 Summary:            Buffer Overrun in curl_exec() causing hang
-Status:             Open
+Status:             Verified
 Type:               Bug
 Package:            cURL related
 Operating System:   Windows 10 x64
 PHP Version:        7.0.4
 Block user comment: N
 Private report:     N

 New Comment:

Curl confirmed that these warnings are indirectly caused by openssl, so we can ignore those.

I was not able to reproduce the original issue on Ubuntu 14.04.

I am able to reproduce the hang on Windows, but cannot help beyond that.


Previous Comments:
------------------------------------------------------------------------
[2016-03-28 17:12:41] paul at salesintel dot com

That it can be reproduced even more simply in both 5 and 7 starts pointing the finger to something
other than the php curl wrapper, should it not still be a bug, or problem, that an exception is
never thrown? That the program just hangs?

------------------------------------------------------------------------
[2016-03-28 15:07:41] nikic@php.net

I've opened an issue at libcurl: https://github.com/curl/curl/issues/734

------------------------------------------------------------------------
[2016-03-28 14:52:35] nikic@php.net

These valgrind warnings are definitely not related to PHP. E.g. this is what I get running curl
directly from the CLI: https://gist.github.com/nikic/b7af10da8f73923a46a0

This does not necessarily mean that there is an issue in curl, as all of this starts with libssl,
which is notoriously valgrind unsafe (don't ask unless you want to hear an answer). However,
given the number of warnings originating in libcurl I'm inclined it doesn't seem unlikely
that there is a genuine issue there.

------------------------------------------------------------------------
[2016-03-28 13:57:56] krakjoe@php.net

Also, I forgot to mention, that I don't need cainfo set in php.ini, just used defaults.

------------------------------------------------------------------------
[2016-03-28 13:56:10] krakjoe@php.net

I am using a slightly different kind of build to laurence, libssl.

I can reproduce memory errors in PHP 5 and 7 using the following:

<?php
$ch = curl_init('https://mail.microsoft.com/ews/exchange.asmx');

curl_exec($ch);

Here's one from 5:

==22050== Conditional jump or move depends on uninitialised value(s)
==22050==    at 0x6DC7A42: ??? (in /usr/lib/x86_64-linux-gnu/libcurl.so.4.3.0)
==22050==    by 0x6DCB253: ??? (in /usr/lib/x86_64-linux-gnu/libcurl.so.4.3.0)
==22050==    by 0x6DDFC27: ??? (in /usr/lib/x86_64-linux-gnu/libcurl.so.4.3.0)
==22050==    by 0x6DE9ACB: ??? (in /usr/lib/x86_64-linux-gnu/libcurl.so.4.3.0)
==22050==    by 0x6DEA270: curl_multi_perform (in /usr/lib/x86_64-linux-gnu/libcurl.so.4.3.0)
==22050==    by 0x6DE18A2: curl_easy_perform (in /usr/lib/x86_64-linux-gnu/libcurl.so.4.3.0)
==22050==    by 0x515CF5: zif_curl_exec (interface.c:2978)
==22050==    by 0xA2AA64: zend_do_fcall_common_helper_SPEC (zend_vm_execute.h:558)
==22050==    by 0xA31592: ZEND_DO_FCALL_SPEC_CONST_HANDLER (zend_vm_execute.h:2602)
==22050==    by 0xA29CBD: execute_ex (zend_vm_execute.h:363)
==22050==    by 0xA29DA3: zend_execute (zend_vm_execute.h:388)
==22050==    by 0x9DD2CE: zend_execute_scripts (zend.c:1341)

Here's one from 7:

==22058== Conditional jump or move depends on uninitialised value(s)
==22058==    at 0x6C5CA42: ??? (in /usr/lib/x86_64-linux-gnu/libcurl.so.4.3.0)
==22058==    by 0x6C60253: ??? (in /usr/lib/x86_64-linux-gnu/libcurl.so.4.3.0)
==22058==    by 0x6C74C27: ??? (in /usr/lib/x86_64-linux-gnu/libcurl.so.4.3.0)
==22058==    by 0x6C7EACB: ??? (in /usr/lib/x86_64-linux-gnu/libcurl.so.4.3.0)
==22058==    by 0x6C7F270: curl_multi_perform (in /usr/lib/x86_64-linux-gnu/libcurl.so.4.3.0)
==22058==    by 0x6C768A2: curl_easy_perform (in /usr/lib/x86_64-linux-gnu/libcurl.so.4.3.0)
==22058==    by 0x607D99: zif_curl_exec (interface.c:2875)
==22058==    by 0xACA4F0: ZEND_DO_FCALL_BY_NAME_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:795)
==22058==    by 0xAC9360: execute_ex (zend_vm_execute.h:424)
==22058==    by 0xAC9562: zend_execute (zend_vm_execute.h:468)
==22058==    by 0xA63628: zend_execute_scripts (zend.c:1427)
==22058==    by 0x9A11AC: php_execute_script (main.c:2494)

This really does feel like a cURL bug, it would be best to make the cURL maintainers aware of the
problem.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=71861


--
Edit this bug report at https://bugs.php.net/bug.php?id=71861&edit=1


Thread (15 messages)

« previous php.bugs (#200192) next »