Bug #73188 [Opn]: Use after free in user_wrapper_opener()
| From: | admin at fullspace dot ru | Date: | Tue, 27 Sep 2016 19:22:23 +0000 |
| Subject: | Bug #73188 [Opn]: Use after free in user_wrapper_opener() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-204306@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73188&edit=1
ID: 73188
User updated by: admin at fullspace dot ru
Reported by: admin at fullspace dot ru
Summary: Use after free in user_wrapper_opener()
Status: Open
Type: Bug
Package: Streams related
Operating System: Gentoo
PHP Version: 5.6.26
Block user comment: N
Private report: N
New Comment:
There is use after free bug in streams.
apache 2.2.31 (prefork) + mod_php (5.6.26)
This is production site and I can't reproduce bug in short script, but it appears all the time.
Core was generated by `/usr/sbin/apache2 -D PHP5.6 -D MACRO -D RPAF -d /usr/lib64/apache2 -f
/etc/apac'.
Program terminated with signal SIGSEGV, Segmentation fault.
#0 0x00007f5c23af639e in ?? () from /lib64/libc.so.6
(gdb) bt
#0 0x00007f5c23af639e in ?? () from /lib64/libc.so.6
#1 0x00007f5c1f214f8f in user_wrapper_opener (wrapper=0x2133828,
filename=0x2cce9b8
"udata://custom/getMyDelivCity/%D0%9C%D0%BE%D1%81%D0%BA%D0%B2%D0%B0/.json",
mode=0x7f5c1f8019c3 "rb", options=0, opened_path=0x0,
context=0x257df30, __php_stream_call_depth=1,
__zend_filename=0x7f5c1f82a198
"/var/tmp/portage/dev-lang/php-5.6.26/work/sapis-build/apache2/main/streams/streams.c",
__zend_lineno=2061,
__zend_orig_filename=0x7f5c1f801288
"/var/tmp/portage/dev-lang/php-5.6.26/work/sapis-build/apache2/ext/standard/file.c",
__zend_orig_lineno=550)
at /usr/src/debug/dev-lang/php-5.6.26/sapis-build/apache2/main/streams/userspace.c:347
#2 0x00007f5c1f20c892 in _php_stream_open_wrapper_ex (path=0x2cce9b8
"udata://custom/getMyDelivCity/%D0%9C%D0%BE%D1%81%D0%BA%D0%B2%D0%B0/.json",
mode=0x7f5c1f8019c3 "rb", options=8, opened_path=0x0, context=0x257df30,
__php_stream_call_depth=0,
__zend_filename=0x7f5c1f801288
"/var/tmp/portage/dev-lang/php-5.6.26/work/sapis-build/apache2/ext/standard/file.c",
__zend_lineno=550,
__zend_orig_filename=0x0, __zend_orig_lineno=0) at
/usr/src/debug/dev-lang/php-5.6.26/sapis-build/apache2/main/streams/streams.c:2059
#3 0x00007f5c1f0b61f6 in zif_file_get_contents (ht=1, return_value=0x2cd1658,
return_value_ptr=0x7f5c25bb01b8, this_ptr=0x0, return_value_used=1)
at /usr/src/debug/dev-lang/php-5.6.26/sapis-build/apache2/ext/standard/file.c:548
#4 0x00007f5c1ef77327 in phar_file_get_contents (ht=1, return_value=0x2cd1658,
return_value_ptr=0x7f5c25bb01b8, this_ptr=0x0, return_value_used=1)
at /usr/src/debug/dev-lang/php-5.6.26/sapis-build/apache2/ext/phar/func_interceptors.c:225
#5 0x00007f5c1f2d1910 in zend_do_fcall_common_helper_SPEC (execute_data=0x7f5c25bb0210)
at /usr/src/debug/dev-lang/php-5.6.26/sapis-build/apache2/Zend/zend_vm_execute.h:558
#6 0x00007f5c1f2d7422 in ZEND_DO_FCALL_SPEC_CONST_HANDLER (execute_data=0x7f5c25bb0210)
at /usr/src/debug/dev-lang/php-5.6.26/sapis-build/apache2/Zend/zend_vm_execute.h:2602
#7 0x00007f5c1f2d0f79 in execute_ex (execute_data=0x7f5c25bb0210) at
/usr/src/debug/dev-lang/php-5.6.26/sapis-build/apache2/Zend/zend_vm_execute.h:363
#8 0x00007f5c1f2d1002 in zend_execute (op_array=0x7f5c25be5bb0) at
/usr/src/debug/dev-lang/php-5.6.26/sapis-build/apache2/Zend/zend_vm_execute.h:388
#9 0x00007f5c1f289010 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at
/usr/src/debug/dev-lang/php-5.6.26/sapis-build/apache2/Zend/zend.c:1341
#10 0x00007f5c1f1eb211 in php_execute_script (primary_file=0x7ffc4d68bcf0) at
/usr/src/debug/dev-lang/php-5.6.26/sapis-build/apache2/main/main.c:2613
#11 0x00007f5c1f345fb3 in php_handler (r=0x2018de0) at
/usr/src/debug/dev-lang/php-5.6.26/sapis-build/apache2/sapi/apache2handler/sapi_apache2.c:667
#12 0x0000000000438df0 in ap_run_handler ()
#13 0x00000000004391b9 in ap_invoke_handler ()
#14 0x00000000004454ec in ap_internal_redirect ()
#15 0x00007f5c207f2462 in ?? () from /usr/lib64/apache2/modules/mod_rewrite.so
#16 0x0000000000438df0 in ap_run_handler ()
#17 0x00000000004391b9 in ap_invoke_handler ()
#18 0x0000000000445d90 in ap_process_request ()
#19 0x0000000000442f30 in ?? ()
#20 0x000000000043f1e0 in ap_run_process_connection ()
#21 0x000000000044a3af in ?? ()
#22 0x000000000044a7d4 in ?? ()
#23 0x000000000044b6e4 in ap_mpm_run ()
#24 0x0000000000424c21 in main ()
Segfault is in strcmp() here:
(gdb) up
#1 0x00007f5c1f214f8f in user_wrapper_opener (wrapper=0x2133828,
filename=0x2cce9b8
"udata://custom/getMyDelivCity/%D0%9C%D0%BE%D1%81%D0%BA%D0%B2%D0%B0/.json",
mode=0x7f5c1f8019c3 "rb", options=0, opened_path=0x0,
context=0x257df30, __php_stream_call_depth=1,
__zend_filename=0x7f5c1f82a198
"/var/tmp/portage/dev-lang/php-5.6.26/work/sapis-build/apache2/main/streams/streams.c",
__zend_lineno=2061,
__zend_orig_filename=0x7f5c1f801288
"/var/tmp/portage/dev-lang/php-5.6.26/work/sapis-build/apache2/ext/standard/file.c",
__zend_orig_lineno=550)
at /usr/src/debug/dev-lang/php-5.6.26/sapis-build/apache2/main/streams/userspace.c:347
347 if (FG(user_stream_current_filename) != NULL && strcmp(filename,
FG(user_stream_current_filename)) == 0) {
(gdb) print file_globals.user_stream_current_filename
$1 = 0x7f5c15714ab0 <error: Cannot access memory at address 0x7f5c15714ab0>
Previous Comments:
------------------------------------------------------------------------
[2016-09-27 19:15:47] admin at fullspace dot ru
Description:
------------
There is use after free bug in streams.
This is production site and I can't reproduce bug in short script, but it appears all the time.
Core was generated by `/usr/sbin/apache2 -D PHP5.6 -D MACRO -D RPAF -d /usr/lib64/apache2 -f
/etc/apac'.
Program terminated with signal SIGSEGV, Segmentation fault.
#0 0x00007f5c23af639e in ?? () from /lib64/libc.so.6
(gdb) bt
#0 0x00007f5c23af639e in ?? () from /lib64/libc.so.6
#1 0x00007f5c1f214f8f in user_wrapper_opener (wrapper=0x2133828,
filename=0x2cce9b8
"udata://custom/getMyDelivCity/%D0%9C%D0%BE%D1%81%D0%BA%D0%B2%D0%B0/.json",
mode=0x7f5c1f8019c3 "rb", options=0, opened_path=0x0,
context=0x257df30, __php_stream_call_depth=1,
__zend_filename=0x7f5c1f82a198
"/var/tmp/portage/dev-lang/php-5.6.26/work/sapis-build/apache2/main/streams/streams.c",
__zend_lineno=2061,
__zend_orig_filename=0x7f5c1f801288
"/var/tmp/portage/dev-lang/php-5.6.26/work/sapis-build/apache2/ext/standard/file.c",
__zend_orig_lineno=550)
at /usr/src/debug/dev-lang/php-5.6.26/sapis-build/apache2/main/streams/userspace.c:347
#2 0x00007f5c1f20c892 in _php_stream_open_wrapper_ex (path=0x2cce9b8
"udata://custom/getMyDelivCity/%D0%9C%D0%BE%D1%81%D0%BA%D0%B2%D0%B0/.json",
mode=0x7f5c1f8019c3 "rb", options=8, opened_path=0x0, context=0x257df30,
__php_stream_call_depth=0,
__zend_filename=0x7f5c1f801288
"/var/tmp/portage/dev-lang/php-5.6.26/work/sapis-build/apache2/ext/standard/file.c",
__zend_lineno=550,
__zend_orig_filename=0x0, __zend_orig_lineno=0) at
/usr/src/debug/dev-lang/php-5.6.26/sapis-build/apache2/main/streams/streams.c:2059
#3 0x00007f5c1f0b61f6 in zif_file_get_contents (ht=1, return_value=0x2cd1658,
return_value_ptr=0x7f5c25bb01b8, this_ptr=0x0, return_value_used=1)
at /usr/src/debug/dev-lang/php-5.6.26/sapis-build/apache2/ext/standard/file.c:548
#4 0x00007f5c1ef77327 in phar_file_get_contents (ht=1, return_value=0x2cd1658,
return_value_ptr=0x7f5c25bb01b8, this_ptr=0x0, return_value_used=1)
at /usr/src/debug/dev-lang/php-5.6.26/sapis-build/apache2/ext/phar/func_interceptors.c:225
#5 0x00007f5c1f2d1910 in zend_do_fcall_common_helper_SPEC (execute_data=0x7f5c25bb0210)
at /usr/src/debug/dev-lang/php-5.6.26/sapis-build/apache2/Zend/zend_vm_execute.h:558
#6 0x00007f5c1f2d7422 in ZEND_DO_FCALL_SPEC_CONST_HANDLER (execute_data=0x7f5c25bb0210)
at /usr/src/debug/dev-lang/php-5.6.26/sapis-build/apache2/Zend/zend_vm_execute.h:2602
#7 0x00007f5c1f2d0f79 in execute_ex (execute_data=0x7f5c25bb0210) at
/usr/src/debug/dev-lang/php-5.6.26/sapis-build/apache2/Zend/zend_vm_execute.h:363
#8 0x00007f5c1f2d1002 in zend_execute (op_array=0x7f5c25be5bb0) at
/usr/src/debug/dev-lang/php-5.6.26/sapis-build/apache2/Zend/zend_vm_execute.h:388
#9 0x00007f5c1f289010 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at
/usr/src/debug/dev-lang/php-5.6.26/sapis-build/apache2/Zend/zend.c:1341
#10 0x00007f5c1f1eb211 in php_execute_script (primary_file=0x7ffc4d68bcf0) at
/usr/src/debug/dev-lang/php-5.6.26/sapis-build/apache2/main/main.c:2613
#11 0x00007f5c1f345fb3 in php_handler (r=0x2018de0) at
/usr/src/debug/dev-lang/php-5.6.26/sapis-build/apache2/sapi/apache2handler/sapi_apache2.c:667
#12 0x0000000000438df0 in ap_run_handler ()
#13 0x00000000004391b9 in ap_invoke_handler ()
#14 0x00000000004454ec in ap_internal_redirect ()
#15 0x00007f5c207f2462 in ?? () from /usr/lib64/apache2/modules/mod_rewrite.so
#16 0x0000000000438df0 in ap_run_handler ()
#17 0x00000000004391b9 in ap_invoke_handler ()
#18 0x0000000000445d90 in ap_process_request ()
#19 0x0000000000442f30 in ?? ()
#20 0x000000000043f1e0 in ap_run_process_connection ()
#21 0x000000000044a3af in ?? ()
#22 0x000000000044a7d4 in ?? ()
#23 0x000000000044b6e4 in ap_mpm_run ()
#24 0x0000000000424c21 in main ()
Segfault is in strcmp() here:
(gdb) up
#1 0x00007f5c1f214f8f in user_wrapper_opener (wrapper=0x2133828,
filename=0x2cce9b8
"udata://custom/getMyDelivCity/%D0%9C%D0%BE%D1%81%D0%BA%D0%B2%D0%B0/.json",
mode=0x7f5c1f8019c3 "rb", options=0, opened_path=0x0,
context=0x257df30, __php_stream_call_depth=1,
__zend_filename=0x7f5c1f82a198
"/var/tmp/portage/dev-lang/php-5.6.26/work/sapis-build/apache2/main/streams/streams.c",
__zend_lineno=2061,
__zend_orig_filename=0x7f5c1f801288
"/var/tmp/portage/dev-lang/php-5.6.26/work/sapis-build/apache2/ext/standard/file.c",
__zend_orig_lineno=550)
at /usr/src/debug/dev-lang/php-5.6.26/sapis-build/apache2/main/streams/userspace.c:347
347 if (FG(user_stream_current_filename) != NULL && strcmp(filename,
FG(user_stream_current_filename)) == 0) {
(gdb) print file_globals.user_stream_current_filename
$1 = 0x7f5c15714ab0 <error: Cannot access memory at address 0x7f5c15714ab0>
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73188&edit=1