Bug #72397 [NEW]: php_output_handler_init may cause null pointer dereference
From: shm
Operating system: Linux
PHP version: 7.0Git-2016-06-13 (Git)
Package: Reproducible crash
Bug Type: Bug
Bug description:php_output_handler_init may cause null pointer dereference
Description:
------------
In case of USE_ZEND_ALLOC=0, function:
php_output_handler_init which looks as follows:
863static inline php_output_handler *php_output_handler_init(zend_string
*name, size_t chunk_size, int flags)
864{
865 php_output_handler *handler;
866
867 handler = ecalloc(1, sizeof(php_output_handler));
868 handler->name = zend_string_copy(name);
869 handler->size = chunk_size;
870 handler->flags = flags;
871 handler->buffer.size = PHP_OUTPUT_HANDLER_INITBUF_SIZE(chunk_size);
872 handler->buffer.data = emalloc(handler->buffer.size);
873
874 return handler;
875}
may return in buffer.data NULL if buffer.size is large enough to fail,
then it can be deferred later (when buffer.data is used) i.e. in
php_output_handler_append as presented below:
$ ASAN_OPTIONS=symbolize=1 ./php minerva.147.1053581631
==2035== WARNING: AddressSanitizer failed to allocate 0x10e0829ff7e000
bytes
ASAN:SIGSEGV
=================================================================
==2035== ERROR: AddressSanitizer: SEGV on unknown address 0x000000000000
(pc 0x7f79f3d819a5 sp 0x7fff83d32038 bp 0x7fff83d32880 T0)
AddressSanitizer can not provide additional info.
#0 0x7f79f3d819a4 (/usr/lib/x86_64-linux-gnu/libasan.so.0+0x199a4)
#1 0x7f79f3d763a2 (/usr/lib/x86_64-linux-gnu/libasan.so.0+0xe3a2)
#2 0xedf3f7 in php_output_handler_append
/home/shm/src/php-src/main/output.c:893
#3 0xedf5de in php_output_handler_op
/home/shm/src/php-src/main/output.c:941
#4 0xee043e in php_output_op
/home/shm/src/php-src/main/output.c:1057
#5 0xedbd51 in php_output_write
/home/shm/src/php-src/main/output.c:257
#6 0xe9995e in php_printf /home/shm/src/php-src/main/main.c:692
#7 0xe9bef0 in php_error_cb /home/shm/src/php-src/main/main.c:1127
#8 0x1010b45 in zend_error_noreturn
/home/shm/src/php-src/Zend/zend.c:1154
#9 0x10122af in zend_internal_type_error
/home/shm/src/php-src/Zend/zend.c:1348
#10 0x1016e57 in zend_wrong_paramer_type_error
/home/shm/src/php-src/Zend/zend_API.c:226
#11 0xd1c570 in zif_fread
/home/shm/src/php-src/ext/standard/file.c:1808
#12 0x10fe845 in ZEND_DO_ICALL_SPEC_HANDLER
/home/shm/src/php-src/Zend/zend_vm_execute.h:586
#13 0x10fd8be in execute_ex
/home/shm/src/php-src/Zend/zend_vm_execute.h:414
#14 0x10fdb19 in zend_execute
/home/shm/src/php-src/Zend/zend_vm_execute.h:458
#15 0x1012aee in zend_execute_scripts
/home/shm/src/php-src/Zend/zend.c:1427
#16 0xea2158 in php_execute_script
/home/shm/src/php-src/main/main.c:2494
#17 0x122931b in do_cli
/home/shm/src/php-src/sapi/cli/php_cli.c:974
#18 0x122b8f7 in main /home/shm/src/php-src/sapi/cli/php_cli.c:1344
#19 0x7f79f2481ec4 (/lib/x86_64-linux-gnu/libc.so.6+0x21ec4)
#20 0x42dc48 in _start (/home/shm/src/php-src/sapi/cli/php+0x42dc48)
Test script:
---------------
<?php
$var0 = mt_rand();
$var5 = mktime($var0,$var2,$var1,$var0,$var2);
$var7 = ob_start($var4,$var5,$var2);
$var8 = posix_seteuid($var7);
$var10 = gzread($var8,$var8);
Expected result:
----------------
No NPD happens
Actual result:
--------------
NPD happens
--
Edit bug report at https://bugs.php.net/bug.php?id=72397&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=72397&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=72397&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=72397&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=72397&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=72397&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=72397&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=72397&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=72397&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=72397&r=support
Expected behavior: https://bugs.php.net/fix.php?id=72397&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=72397&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=72397&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=72397&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=72397&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=72397&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=72397&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=72397&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=72397&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=72397&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=72397&r=mysqlcfg
Thread (7 messages)
- shm@php.net