From: nguyenluan dot vnn at gmail dot com
Operating system:
PHP version: 7.0.9
Package: Unknown/Other Function
Bug Type: Bug
Bug description:Buffer overflow in shmop_write function
Description:
------------
There is an error for non-checking string length of "data" in
shmop_write function leads to memory corruption when doing memcpy.
PHP_FUNCTION(shmop_write)
{
struct php_shmop *shmop;
int writesize;
[...]
writesize = (ZSTR_LEN(data) < shmop->size - offset) ? ZSTR_LEN(data) :
shmop->size - offset; (1)
memcpy(shmop->addr + offset, ZSTR_VAL(data), writesize);
[...]
}
(1) There should be a check for "writesize" to prevent negative number.
Test script:
---------------
<?php
ini_set('memory_limit', '-1');
$str = str_repeat("a", 0x90000000);
$shmid = shmop_open("111", 'c', 0644, 0x1000);
shmop_write($shmid, $str, 0);
?>
Expected result:
----------------
No crash
Actual result:
--------------
Starting program: /home/user/Desktop/php-7.0.9/sapi/cli/php
../test_shmop.php
[Thread debugging using libthread_db enabled]
Using host libthread_db library
"/lib/x86_64-linux-gnu/libthread_db.so.1".
[----------------------------------registers-----------------------------------]
RAX: 0x7fffed001680 --> 0x6f026d0007
RBX: 0x7fffed013100 --> 0x0
RCX: 0x90000000
RDX: 0x80000000
RSI: 0x7fff5cc00000 --> 0x600000002
RDI: 0x0
RBP: 0xeeaa80 --> 0x0
RSP: 0x7fffffffa800 --> 0x3dd400003b93
RIP: 0x5f61f9 (<zif_shmop_write+121>: add rdi,QWORD PTR [rax+0x10])
R8 : 0x0
R9 : 0x6ff520 (<zend_parse_va_args+416>: add rsi,0x1)
R10: 0xba85ec --> 0xffb56f8cffb56def
R11: 0x202
R12: 0x7fffed083000 --> 0x800000000000002
R13: 0x7fffed013110 --> 0x0
R14: 0x7fffed013030 --> 0x7fffed088280 --> 0x741510
(<ZEND_DO_ICALL_SPEC_HANDLER>: push r13)
R15: 0x7fffed088280 --> 0x741510 (<ZEND_DO_ICALL_SPEC_HANDLER>: push
r13)
EFLAGS: 0x287 (CARRY PARITY adjust zero SIGN trap INTERRUPT direction
overflow)
[-------------------------------------code-------------------------------------]
0x5f61ee <zif_shmop_write+110>: mov rcx,QWORD PTR [rsi+0x10]
0x5f61f2 <zif_shmop_write+114>: cmp rdx,rcx
0x5f61f5 <zif_shmop_write+117>: cmova rdx,rcx
=> 0x5f61f9 <zif_shmop_write+121>: add rdi,QWORD PTR [rax+0x10]
0x5f61fd <zif_shmop_write+125>: add rsi,0x18
0x5f6201 <zif_shmop_write+129>: movsxd rbp,edx
0x5f6204 <zif_shmop_write+132>: mov rdx,rbp
0x5f6207 <zif_shmop_write+135>: call 0x423ca0 <memcpy@plt>
[------------------------------------stack-------------------------------------]
0000| 0x7fffffffa800 --> 0x3dd400003b93
0008| 0x7fffffffa808 --> 0x0
0016| 0x7fffffffa810 --> 0x7fff5cc00000 --> 0x600000002
0024| 0x7fffffffa818 --> 0x7fffed013170 --> 0x7fffed055060 -->
0x900000002
0032| 0x7fffffffa820 --> 0x7fffed083190 --> 0xf209e0 --> 0x70600000001
0040| 0x7fffffffa828 --> 0x7fffed083000 --> 0x800000000000002
0048| 0x7fffffffa830 --> 0xeeaa80 --> 0x0
0056| 0x7fffffffa838 --> 0x74155d (<ZEND_DO_ICALL_SPEC_HANDLER+77>: mov
rax,QWORD PTR [r13+0x38])
[------------------------------------------------------------------------------]
Legend: code, data, rodata, value
Breakpoint 1, zif_shmop_write (execute_data=<optimized out>,
return_value=0x7fffed013100)
at /home/user/Desktop/php-7.0.9/ext/shmop/shmop.c:332
332 memcpy(shmop->addr + offset, ZSTR_VAL(data), writesize);
gdb-peda$ p shmop->size
$5 = 0x80000000
gdb-peda$ p offset
$6 = 0x0
gdb-peda$ p writesize
$7 = 0x80000000
gdb-peda$ c
Continuing.
Program received signal SIGSEGV, Segmentation fault.
[----------------------------------registers-----------------------------------]
RAX: 0xffffffff80000000
RBX: 0x7fffed013100 --> 0x0
RCX: 0x90000fe0
RDX: 0xffffffff80000000
RSI: 0x7fff5cc00018 ('a' <repeats 200 times>...)
RDI: 0x7ffedcc00000 ('a' <repeats 200 times>...)
RBP: 0xffffffff80000000
RSP: 0x7fffffffa7f8 --> 0x5f620c (<zif_shmop_write+140>: mov QWORD
PTR [rbx],rbp)
RIP: 0x7ffff39b9034 (<__memcpy_sse2_unaligned+372>: )
R8 : 0x90000fe
R9 : 0xffffffff8000000
R10: 0xba85ec --> 0xffb56f8cffb56def
R11: 0x202
R12: 0x7fffed083000 --> 0x800000000000002
R13: 0x7fffed013110 --> 0x0
R14: 0x7fffed013030 --> 0x7fffed088280 --> 0x741510
(<ZEND_DO_ICALL_SPEC_HANDLER>: push r13)
R15: 0x7fffed088280 --> 0x741510 (<ZEND_DO_ICALL_SPEC_HANDLER>: push
r13)
EFLAGS: 0x10212 (carry parity ADJUST zero sign trap INTERRUPT direction
overflow)
[-------------------------------------code-------------------------------------]
0x7ffff39b9029 <__memcpy_sse2_unaligned+361>:
je 0x7ffff39b90c2 <__memcpy_sse2_unaligned+514>
0x7ffff39b902f <__memcpy_sse2_unaligned+367>: xor ecx,ecx
0x7ffff39b9031 <__memcpy_sse2_unaligned+369>: xor r8d,r8d
=> 0x7ffff39b9034 <__memcpy_sse2_unaligned+372>:
movdqu xmm8,XMMWORD PTR [rsi+rcx*1]
0x7ffff39b903a <__memcpy_sse2_unaligned+378>: add r8,0x1
0x7ffff39b903e <__memcpy_sse2_unaligned+382>:
movdqu XMMWORD PTR [rdi+rcx*1],xmm8
0x7ffff39b9044 <__memcpy_sse2_unaligned+388>: add rcx,0x10
0x7ffff39b9048 <__memcpy_sse2_unaligned+392>: cmp r9,r8
[------------------------------------stack-------------------------------------]
0000| 0x7fffffffa7f8 --> 0x5f620c (<zif_shmop_write+140>: mov QWORD
PTR [rbx],rbp)
0008| 0x7fffffffa800 --> 0x3dd400003b93
0016| 0x7fffffffa808 --> 0x0
0024| 0x7fffffffa810 --> 0x7fff5cc00000 ('a' <repeats 200 times>...)
0032| 0x7fffffffa818 --> 0x7fffed013170 --> 0x7fffed055060 -->
0x900000002
0040| 0x7fffffffa820 --> 0x7fffed083190 --> 0xf209e0 --> 0x70600000001
0048| 0x7fffffffa828 --> 0x7fffed083000 --> 0x800000000000002
0056| 0x7fffffffa830 --> 0xeeaa80 --> 0x0
[------------------------------------------------------------------------------]
Legend: code, data, rodata, value
Stopped reason: SIGSEGV
__memcpy_sse2_unaligned ()
at ../sysdeps/x86_64/multiarch/memcpy-sse2-unaligned.S:116
116 ../sysdeps/x86_64/multiarch/memcpy-sse2-unaligned.S: No such file or
directory.
gdb-peda$ bt
#0 __memcpy_sse2_unaligned ()
at ../sysdeps/x86_64/multiarch/memcpy-sse2-unaligned.S:116
#1 0x00000000005f620c in memcpy (__len=0xffffffff80000000,
__src=<optimized out>, __dest=<optimized out>)
at /usr/include/x86_64-linux-gnu/bits/string3.h:51
#2 zif_shmop_write (execute_data=<optimized out>,
return_value=0x7fffed013100)
at /home/user/Desktop/php-7.0.9/ext/shmop/shmop.c:332
#3 0x000000000074155d in ZEND_DO_ICALL_SPEC_HANDLER ()
at /home/user/Desktop/php-7.0.9/Zend/zend_vm_execute.h:586
#4 0x0000000000733aab in execute_ex (ex=<optimized out>)
at /home/user/Desktop/php-7.0.9/Zend/zend_vm_execute.h:414
#5 0x000000000077cdd7 in zend_execute (op_array=0x7fffed083000,
op_array@entry=0x7fffed088280,
return_value=return_value@entry=0x7fffed013030)
at /home/user/Desktop/php-7.0.9/Zend/zend_vm_execute.h:458
#6 0x00000000006f7494 in zend_execute_scripts (type=type@entry=0x8,
retval=0x7fffed013030, retval@entry=0x0,
file_count=file_count@entry=0x3)
at /home/user/Desktop/php-7.0.9/Zend/zend.c:1427
#7 0x000000000069b338 in php_execute_script (
primary_file=primary_file@entry=0x7fffffffccc0)
at /home/user/Desktop/php-7.0.9/main/main.c:2494
#8 0x000000000077e9a8 in do_cli (argc=0x2, argv=0xeef300)
at /home/user/Desktop/php-7.0.9/sapi/cli/php_cli.c:974
#9 0x00000000004331e0 in main (argc=argc@entry=0x2, argv=0xeef300,
argv@entry=0x7fffffffe0b8)
at /home/user/Desktop/php-7.0.9/sapi/cli/php_cli.c:1344
#10 0x00007ffff3942f45 in __libc_start_main (main=0x432cd0 <main>,
argc=0x2,
argv=0x7fffffffe0b8, init=<optimized out>, fini=<optimized out>,
rtld_fini=<optimized out>, stack_end=0x7fffffffe0a8) at
libc-start.c:287
#11 0x000000000043327b in _start ()
--
Edit bug report at https://bugs.php.net/bug.php?id=72766&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=72766&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=72766&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=72766&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=72766&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=72766&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=72766&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=72766&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=72766&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=72766&r=support
Expected behavior: https://bugs.php.net/fix.php?id=72766&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=72766&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=72766&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=72766&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=72766&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=72766&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=72766&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=72766&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=72766&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=72766&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=72766&r=mysqlcfg