Bug #72766 [NEW]: Buffer overflow in shmop_write function

From: Date: Fri, 05 Aug 2016 14:50:34 +0000
Subject: Bug #72766 [NEW]: Buffer overflow in shmop_write function
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202968@lists.php.net to get a copy of this message
From:             nguyenluan dot vnn at gmail dot com
Operating system: 
PHP version:      7.0.9
Package:          Unknown/Other Function
Bug Type:         Bug
Bug description:Buffer overflow in shmop_write function

Description:
------------
There is an error for non-checking string length of "data" in
shmop_write function leads to memory corruption when doing memcpy.

PHP_FUNCTION(shmop_write)
{
	struct php_shmop *shmop;
	int writesize;

	[...]

	writesize = (ZSTR_LEN(data) < shmop->size - offset) ? ZSTR_LEN(data) :
shmop->size - offset; (1)
	memcpy(shmop->addr + offset, ZSTR_VAL(data), writesize);

	[...]
}

(1) There should be a check for "writesize" to prevent negative number.

Test script:
---------------
<?php
	ini_set('memory_limit', '-1');
	$str = str_repeat("a", 0x90000000);
	
	$shmid = shmop_open("111", 'c', 0644, 0x1000);
	shmop_write($shmid, $str, 0);
?>

Expected result:
----------------
No crash

Actual result:
--------------
Starting program: /home/user/Desktop/php-7.0.9/sapi/cli/php
../test_shmop.php
[Thread debugging using libthread_db enabled]
Using host libthread_db library
"/lib/x86_64-linux-gnu/libthread_db.so.1".
[----------------------------------registers-----------------------------------]
RAX: 0x7fffed001680 --> 0x6f026d0007 
RBX: 0x7fffed013100 --> 0x0 
RCX: 0x90000000 
RDX: 0x80000000 
RSI: 0x7fff5cc00000 --> 0x600000002 
RDI: 0x0 
RBP: 0xeeaa80 --> 0x0 
RSP: 0x7fffffffa800 --> 0x3dd400003b93 
RIP: 0x5f61f9 (<zif_shmop_write+121>:	add    rdi,QWORD PTR [rax+0x10])
R8 : 0x0 
R9 : 0x6ff520 (<zend_parse_va_args+416>:	add    rsi,0x1)
R10: 0xba85ec --> 0xffb56f8cffb56def 
R11: 0x202 
R12: 0x7fffed083000 --> 0x800000000000002 
R13: 0x7fffed013110 --> 0x0 
R14: 0x7fffed013030 --> 0x7fffed088280 --> 0x741510
(<ZEND_DO_ICALL_SPEC_HANDLER>:	push   r13)
R15: 0x7fffed088280 --> 0x741510 (<ZEND_DO_ICALL_SPEC_HANDLER>:	push  
r13)
EFLAGS: 0x287 (CARRY PARITY adjust zero SIGN trap INTERRUPT direction
overflow)
[-------------------------------------code-------------------------------------]
   0x5f61ee <zif_shmop_write+110>:	mov    rcx,QWORD PTR [rsi+0x10]
   0x5f61f2 <zif_shmop_write+114>:	cmp    rdx,rcx
   0x5f61f5 <zif_shmop_write+117>:	cmova  rdx,rcx
=> 0x5f61f9 <zif_shmop_write+121>:	add    rdi,QWORD PTR [rax+0x10]
   0x5f61fd <zif_shmop_write+125>:	add    rsi,0x18
   0x5f6201 <zif_shmop_write+129>:	movsxd rbp,edx
   0x5f6204 <zif_shmop_write+132>:	mov    rdx,rbp
   0x5f6207 <zif_shmop_write+135>:	call   0x423ca0 <memcpy@plt>
[------------------------------------stack-------------------------------------]
0000| 0x7fffffffa800 --> 0x3dd400003b93 
0008| 0x7fffffffa808 --> 0x0 
0016| 0x7fffffffa810 --> 0x7fff5cc00000 --> 0x600000002 
0024| 0x7fffffffa818 --> 0x7fffed013170 --> 0x7fffed055060 -->
0x900000002 
0032| 0x7fffffffa820 --> 0x7fffed083190 --> 0xf209e0 --> 0x70600000001 
0040| 0x7fffffffa828 --> 0x7fffed083000 --> 0x800000000000002 
0048| 0x7fffffffa830 --> 0xeeaa80 --> 0x0 
0056| 0x7fffffffa838 --> 0x74155d (<ZEND_DO_ICALL_SPEC_HANDLER+77>:	mov 
  rax,QWORD PTR [r13+0x38])
[------------------------------------------------------------------------------]
Legend: code, data, rodata, value

Breakpoint 1, zif_shmop_write (execute_data=<optimized out>, 
    return_value=0x7fffed013100)
    at /home/user/Desktop/php-7.0.9/ext/shmop/shmop.c:332
332		memcpy(shmop->addr + offset, ZSTR_VAL(data), writesize);
gdb-peda$ p shmop->size
$5 = 0x80000000
gdb-peda$ p offset
$6 = 0x0
gdb-peda$ p writesize
$7 = 0x80000000
gdb-peda$ c
Continuing.

Program received signal SIGSEGV, Segmentation fault.
[----------------------------------registers-----------------------------------]
RAX: 0xffffffff80000000 
RBX: 0x7fffed013100 --> 0x0 
RCX: 0x90000fe0 
RDX: 0xffffffff80000000 
RSI: 0x7fff5cc00018 ('a' <repeats 200 times>...)
RDI: 0x7ffedcc00000 ('a' <repeats 200 times>...)
RBP: 0xffffffff80000000 
RSP: 0x7fffffffa7f8 --> 0x5f620c (<zif_shmop_write+140>:	mov    QWORD
PTR [rbx],rbp)
RIP: 0x7ffff39b9034 (<__memcpy_sse2_unaligned+372>:	)
R8 : 0x90000fe 
R9 : 0xffffffff8000000 
R10: 0xba85ec --> 0xffb56f8cffb56def 
R11: 0x202 
R12: 0x7fffed083000 --> 0x800000000000002 
R13: 0x7fffed013110 --> 0x0 
R14: 0x7fffed013030 --> 0x7fffed088280 --> 0x741510
(<ZEND_DO_ICALL_SPEC_HANDLER>:	push   r13)
R15: 0x7fffed088280 --> 0x741510 (<ZEND_DO_ICALL_SPEC_HANDLER>:	push  
r13)
EFLAGS: 0x10212 (carry parity ADJUST zero sign trap INTERRUPT direction
overflow)
[-------------------------------------code-------------------------------------]
   0x7ffff39b9029 <__memcpy_sse2_unaligned+361>:	
    je     0x7ffff39b90c2 <__memcpy_sse2_unaligned+514>
   0x7ffff39b902f <__memcpy_sse2_unaligned+367>:	xor    ecx,ecx
   0x7ffff39b9031 <__memcpy_sse2_unaligned+369>:	xor    r8d,r8d
=> 0x7ffff39b9034 <__memcpy_sse2_unaligned+372>:	
    movdqu xmm8,XMMWORD PTR [rsi+rcx*1]
   0x7ffff39b903a <__memcpy_sse2_unaligned+378>:	add    r8,0x1
   0x7ffff39b903e <__memcpy_sse2_unaligned+382>:	
    movdqu XMMWORD PTR [rdi+rcx*1],xmm8
   0x7ffff39b9044 <__memcpy_sse2_unaligned+388>:	add    rcx,0x10
   0x7ffff39b9048 <__memcpy_sse2_unaligned+392>:	cmp    r9,r8
[------------------------------------stack-------------------------------------]
0000| 0x7fffffffa7f8 --> 0x5f620c (<zif_shmop_write+140>:	mov    QWORD
PTR [rbx],rbp)
0008| 0x7fffffffa800 --> 0x3dd400003b93 
0016| 0x7fffffffa808 --> 0x0 
0024| 0x7fffffffa810 --> 0x7fff5cc00000 ('a' <repeats 200 times>...)
0032| 0x7fffffffa818 --> 0x7fffed013170 --> 0x7fffed055060 -->
0x900000002 
0040| 0x7fffffffa820 --> 0x7fffed083190 --> 0xf209e0 --> 0x70600000001 
0048| 0x7fffffffa828 --> 0x7fffed083000 --> 0x800000000000002 
0056| 0x7fffffffa830 --> 0xeeaa80 --> 0x0 
[------------------------------------------------------------------------------]
Legend: code, data, rodata, value
Stopped reason: SIGSEGV
__memcpy_sse2_unaligned ()
    at ../sysdeps/x86_64/multiarch/memcpy-sse2-unaligned.S:116
116	../sysdeps/x86_64/multiarch/memcpy-sse2-unaligned.S: No such file or
directory.
gdb-peda$ bt
#0  __memcpy_sse2_unaligned ()
    at ../sysdeps/x86_64/multiarch/memcpy-sse2-unaligned.S:116
#1  0x00000000005f620c in memcpy (__len=0xffffffff80000000, 
    __src=<optimized out>, __dest=<optimized out>)
    at /usr/include/x86_64-linux-gnu/bits/string3.h:51
#2  zif_shmop_write (execute_data=<optimized out>,
return_value=0x7fffed013100)
    at /home/user/Desktop/php-7.0.9/ext/shmop/shmop.c:332
#3  0x000000000074155d in ZEND_DO_ICALL_SPEC_HANDLER ()
    at /home/user/Desktop/php-7.0.9/Zend/zend_vm_execute.h:586
#4  0x0000000000733aab in execute_ex (ex=<optimized out>)
    at /home/user/Desktop/php-7.0.9/Zend/zend_vm_execute.h:414
#5  0x000000000077cdd7 in zend_execute (op_array=0x7fffed083000, 
    op_array@entry=0x7fffed088280, 
    return_value=return_value@entry=0x7fffed013030)
    at /home/user/Desktop/php-7.0.9/Zend/zend_vm_execute.h:458
#6  0x00000000006f7494 in zend_execute_scripts (type=type@entry=0x8, 
    retval=0x7fffed013030, retval@entry=0x0,
file_count=file_count@entry=0x3)
    at /home/user/Desktop/php-7.0.9/Zend/zend.c:1427
#7  0x000000000069b338 in php_execute_script (
    primary_file=primary_file@entry=0x7fffffffccc0)
    at /home/user/Desktop/php-7.0.9/main/main.c:2494
#8  0x000000000077e9a8 in do_cli (argc=0x2, argv=0xeef300)
    at /home/user/Desktop/php-7.0.9/sapi/cli/php_cli.c:974
#9  0x00000000004331e0 in main (argc=argc@entry=0x2, argv=0xeef300, 
    argv@entry=0x7fffffffe0b8)
    at /home/user/Desktop/php-7.0.9/sapi/cli/php_cli.c:1344
#10 0x00007ffff3942f45 in __libc_start_main (main=0x432cd0 <main>,
argc=0x2, 
    argv=0x7fffffffe0b8, init=<optimized out>, fini=<optimized out>, 
    rtld_fini=<optimized out>, stack_end=0x7fffffffe0a8) at
libc-start.c:287
#11 0x000000000043327b in _start ()

-- 
Edit bug report at https://bugs.php.net/bug.php?id=72766&edit=1
-- 
Try a snapshot (PHP 5.4):   https://bugs.php.net/fix.php?id=72766&r=trysnapshot54
Try a snapshot (PHP 5.5):   https://bugs.php.net/fix.php?id=72766&r=trysnapshot55
Try a snapshot (trunk):     https://bugs.php.net/fix.php?id=72766&r=trysnapshottrunk
Fixed in SVN:               https://bugs.php.net/fix.php?id=72766&r=fixed
Fixed in release:           https://bugs.php.net/fix.php?id=72766&r=alreadyfixed
Need backtrace:             https://bugs.php.net/fix.php?id=72766&r=needtrace
Need Reproduce Script:      https://bugs.php.net/fix.php?id=72766&r=needscript
Try newer version:          https://bugs.php.net/fix.php?id=72766&r=oldversion
Not developer issue:        https://bugs.php.net/fix.php?id=72766&r=support
Expected behavior:          https://bugs.php.net/fix.php?id=72766&r=notwrong
Not enough info:            https://bugs.php.net/fix.php?id=72766&r=notenoughinfo
Submitted twice:            https://bugs.php.net/fix.php?id=72766&r=submittedtwice
register_globals:           https://bugs.php.net/fix.php?id=72766&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=72766&r=php4
Daylight Savings:           https://bugs.php.net/fix.php?id=72766&r=dst
IIS Stability:              https://bugs.php.net/fix.php?id=72766&r=isapi
Install GNU Sed:            https://bugs.php.net/fix.php?id=72766&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=72766&r=float
No Zend Extensions:         https://bugs.php.net/fix.php?id=72766&r=nozend
MySQL Configuration Error:  https://bugs.php.net/fix.php?id=72766&r=mysqlcfg



Thread (1 message)

  • nguyenluan dot vnn at gmail dot com
« previous php.bugs (#202968) next »