Bug #73361 [Opn->Fbk]: Out-of-bounds reads issue of php 5.6.27

From: Date: Tue, 25 Oct 2016 15:16:46 +0000
Subject: Bug #73361 [Opn->Fbk]: Out-of-bounds reads issue of php 5.6.27
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204998@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73361&edit=1 ID: 73361 Updated by: cmb@php.net Reported by: 271193918 at qq dot com Summary: Out-of-bounds reads issue of php 5.6.27 -Status: Open +Status: Feedback Type: Bug Package: Scripting Engine problem Operating System: Ubuntu 16.04 x86 PHP Version: 5.6.27 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: To be able to debug this issue we need a copy of ./crashes/fuzzer01/id_000194,sig_11,src_024221+025505,op_splice,rep_2 Previous Comments: ------------------------------------------------------------------------ [2016-10-24 06:26:58] stas@php.net Maybe a weird parser bug, certainly not a security issue - nobody runs binary junk as PHP script. ------------------------------------------------------------------------ [2016-10-24 06:26:02] stas@php.net Wait, I just noticed. Why you use php -c option? This makes php read exif_read_data.php as config file and ./crashes/fuzzer01/id_000194,sig_11,src_024221+025505,op_splice,rep_2 as a script. That's not how it's usually supposed to work. ------------------------------------------------------------------------ [2016-10-24 06:24:49] stas@php.net I don't see any problem in the valgrind report what exactly are you reproducing? Also, could you provide a link to the file: ./crashes/fuzzer01/id_000194,sig_11,src_024221+025505,op_splice,rep_2 ------------------------------------------------------------------------ [2016-10-24 06:22:02] 271193918 at qq dot com If compile php 5.6.27 with Asan: run without USE_ZEND_ALLOC=0 , test log as follows: ./php -c ./crashes/exif_read_data.php ./crashes/fuzzer01/id_000194,sig_11,src_024221+025505,op_splice,rep_2 Fatal error: Allowed memory size of 134217728 bytes exhausted at /home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_vm_execute.h:12902 (tried to allocate 27751964 bytes) in /home/test/Desktop/php_test/php-5.6.27-gcc-Asan/sapi/cli/crashes/fuzzer01/id_000194,sig_11,src_024221+025505,op_splice,rep_2 on line 65 ASAN:SIGSEGV ================================================================= ==18377==ERROR: AddressSanitizer: SEGV on unknown address 0xa70bce4b (pc 0x08b06f17 bp 0xbfbf2b98 sp 0xbfbf2b70 T0) #0 0x8b06f16 in _zval_dtor_func /home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_variables.c:36 #1 0x8aca1af in _zval_dtor /home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_variables.h:35 #2 0x8aca2bd in i_zval_ptr_dtor /home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_execute.h:79 #3 0x8acd46f in _zval_ptr_dtor /home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_execute_API.c:424 #4 0x8b07ce6 in _zval_ptr_dtor_wrapper /home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_variables.c:188 #5 0x8b40672 in i_zend_hash_bucket_delete /home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_hash.c:182 #6 0x8b4082e in zend_hash_bucket_delete /home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_hash.c:192 #7 0x8b4639a in zend_hash_graceful_reverse_destroy /home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_hash.c:613 #8 0x8acc193 in shutdown_executor /home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_execute_API.c:244 #9 0x8b0dc11 in zend_deactivate /home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend.c:960 #10 0x89a6b76 in php_request_shutdown /home/test/Desktop/php_test/php-5.6.27-gcc-Asan/main/main.c:1899 #11 0x8d6e3d9 in do_cli /home/test/Desktop/php_test/php-5.6.27-gcc-Asan/sapi/cli/php_cli.c:1181 #12 0x8d6f0bd in main /home/test/Desktop/php_test/php-5.6.27-gcc-Asan/sapi/cli/php_cli.c:1382 #13 0xb6ba3636 in __libc_start_main (/lib/i386-linux-gnu/libc.so.6+0x18636) #14 0x8067730 (/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/sapi/cli/php+0x8067730) AddressSanitizer can not provide additional info. SUMMARY: AddressSanitizer: SEGV /home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_variables.c:36 _zval_dtor_func ==18377==ABORTING ------------------------------------------------------------------------ [2016-10-24 06:13:04] 271193918 at qq dot com Steps to reproduce: sudo apt-get install autoconf build-essential openssl libssl-dev make curl libcurl4-gnutls-dev libjpeg-dev libpng-dev libmcrypt-dev libxml2-dev libxml2 libreadline6 libreadline6-dev sqlite3 Compile source code of php 5.6.27 without Asan: CC=gcc CXX=g++ ./configure --enable-exif --enable-debug --disable-cgi --with-openssl make -j32 test@test:~/Desktop/php-5.6.27/sapi/cli$ ./php -v PHP 5.6.27 (cli) (built: Oct 24 2016 13:56:53) (DEBUG) Copyright (c) 1997-2016 The PHP Group Zend Engine v2.6.0, Copyright (c) 1998-2016 Zend Technologies USE_ZEND_ALLOC=0 valgrind --tool=memcheck --leak-check=full --show-leak-kinds=all --track-origins=yes -v ./php -c ./crashes/exif_read_data.php ./crashes/fuzzer01/id_000194,sig_11,src_024221+025505,op_splice,rep_2 test@test:~/Desktop/php-5.6.27/sapi/cli$ USE_ZEND_ALLOC=0 valgrind --tool=memcheck --leak-check=full --show-leak-kinds=all --track-origins=yes -v ./php -c ./crashes/exif_read_data.php ./crashes/fuzzer01/id_000194,sig_11,src_024221+025505,op_splice,rep_2 ==18251== HEAP SUMMARY: ==18251== in use at exit: 19,220 bytes in 10 blocks ==18251== total heap usage: 27,194 allocs, 27,184 frees, 233,024,408 bytes allocated ==18251== ==18251== Searching for pointers to 10 not-freed blocks ==18251== Checked 344,576 bytes ==18251== ==18251== 12 bytes in 1 blocks are still reachable in loss record 1 of 10 ==18251== at 0x402D1AE: malloc (vg_replace_malloc.c:299) ==18251== by 0x43444B6: ??? (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x4344A8E: CRYPTO_malloc (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x43460BF: ??? (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x434620A: ??? (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x4346486: CRYPTO_get_ex_new_index (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x42D6BE9: SSL_get_ex_new_index (in /lib/i386-linux-gnu/libssl.so.1.0.0) ==18251== by 0x80B6D14: zm_startup_openssl (openssl.c:1153) ==18251== by 0x841DF6A: zend_startup_module_ex (zend_API.c:1797) ==18251== by 0x841DFCF: zend_startup_module_int (zend_API.c:1810) ==18251== by 0x8426FA3: zend_hash_apply (zend_hash.c:641) ==18251== by 0x841E3FC: zend_startup_modules (zend_API.c:1930) ==18251== ==18251== 12 bytes in 1 blocks are still reachable in loss record 2 of 10 ==18251== at 0x402D1AE: malloc (vg_replace_malloc.c:299) ==18251== by 0x43444B6: ??? (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x4344A8E: CRYPTO_malloc (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x43C2DE9: lh_insert (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x43460EC: ??? (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x434620A: ??? (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x4346486: CRYPTO_get_ex_new_index (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x42D6BE9: SSL_get_ex_new_index (in /lib/i386-linux-gnu/libssl.so.1.0.0) ==18251== by 0x80B6D14: zm_startup_openssl (openssl.c:1153) ==18251== by 0x841DF6A: zend_startup_module_ex (zend_API.c:1797) ==18251== by 0x841DFCF: zend_startup_module_int (zend_API.c:1810) ==18251== by 0x8426FA3: zend_hash_apply (zend_hash.c:641) ==18251== ==18251== 16 bytes in 1 blocks are still reachable in loss record 3 of 10 ==18251== at 0x402D1AE: malloc (vg_replace_malloc.c:299) ==18251== by 0x43444B6: ??? (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x4344A8E: CRYPTO_malloc (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x43C21BF: sk_new (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x42DBE38: ??? (in /lib/i386-linux-gnu/libssl.so.1.0.0) ==18251== by 0x42DE083: SSL_COMP_get_compression_methods (in /lib/i386-linux-gnu/libssl.so.1.0.0) ==18251== by 0x42E3745: SSL_library_init (in /lib/i386-linux-gnu/libssl.so.1.0.0) ==18251== by 0x80B6CEB: zm_startup_openssl (openssl.c:1144) ==18251== by 0x841DF6A: zend_startup_module_ex (zend_API.c:1797) ==18251== by 0x841DFCF: zend_startup_module_int (zend_API.c:1810) ==18251== by 0x8426FA3: zend_hash_apply (zend_hash.c:641) ==18251== by 0x841E3FC: zend_startup_modules (zend_API.c:1930) ==18251== ==18251== 16 bytes in 1 blocks are still reachable in loss record 4 of 10 ==18251== at 0x402D1AE: malloc (vg_replace_malloc.c:299) ==18251== by 0x43444B6: ??? (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x4344A8E: CRYPTO_malloc (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x43C21BF: sk_new (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x43C2245: sk_new_null (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x43460D6: ??? (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x434620A: ??? (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x4346486: CRYPTO_get_ex_new_index (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x42D6BE9: SSL_get_ex_new_index (in /lib/i386-linux-gnu/libssl.so.1.0.0) ==18251== by 0x80B6D14: zm_startup_openssl (openssl.c:1153) ==18251== by 0x841DF6A: zend_startup_module_ex (zend_API.c:1797) ==18251== by 0x841DFCF: zend_startup_module_int (zend_API.c:1810) ==18251== ==18251== 20 bytes in 1 blocks are still reachable in loss record 5 of 10 ==18251== at 0x402D1AE: malloc (vg_replace_malloc.c:299) ==18251== by 0x43444B6: ??? (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x4344A8E: CRYPTO_malloc (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x43C21A6: sk_new (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x42DBE38: ??? (in /lib/i386-linux-gnu/libssl.so.1.0.0) ==18251== by 0x42DE083: SSL_COMP_get_compression_methods (in /lib/i386-linux-gnu/libssl.so.1.0.0) ==18251== by 0x42E3745: SSL_library_init (in /lib/i386-linux-gnu/libssl.so.1.0.0) ==18251== by 0x80B6CEB: zm_startup_openssl (openssl.c:1144) ==18251== by 0x841DF6A: zend_startup_module_ex (zend_API.c:1797) ==18251== by 0x841DFCF: zend_startup_module_int (zend_API.c:1810) ==18251== by 0x8426FA3: zend_hash_apply (zend_hash.c:641) ==18251== by 0x841E3FC: zend_startup_modules (zend_API.c:1930) ==18251== ==18251== 20 bytes in 1 blocks are still reachable in loss record 6 of 10 ==18251== at 0x402D1AE: malloc (vg_replace_malloc.c:299) ==18251== by 0x43444B6: ??? (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x4344A8E: CRYPTO_malloc (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x43C21A6: sk_new (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x43C2245: sk_new_null (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x43460D6: ??? (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x434620A: ??? (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x4346486: CRYPTO_get_ex_new_index (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x42D6BE9: SSL_get_ex_new_index (in /lib/i386-linux-gnu/libssl.so.1.0.0) ==18251== by 0x80B6D14: zm_startup_openssl (openssl.c:1153) ==18251== by 0x841DF6A: zend_startup_module_ex (zend_API.c:1797) ==18251== by 0x841DFCF: zend_startup_module_int (zend_API.c:1810) ==18251== ==18251== 20 bytes in 1 blocks are still reachable in loss record 7 of 10 ==18251== at 0x402D1AE: malloc (vg_replace_malloc.c:299) ==18251== by 0x43444B6: ??? (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x4344A8E: CRYPTO_malloc (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x434622A: ??? (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x4346486: CRYPTO_get_ex_new_index (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x42D6BE9: SSL_get_ex_new_index (in /lib/i386-linux-gnu/libssl.so.1.0.0) ==18251== by 0x80B6D14: zm_startup_openssl (openssl.c:1153) ==18251== by 0x841DF6A: zend_startup_module_ex (zend_API.c:1797) ==18251== by 0x841DFCF: zend_startup_module_int (zend_API.c:1810) ==18251== by 0x8426FA3: zend_hash_apply (zend_hash.c:641) ==18251== by 0x841E3FC: zend_startup_modules (zend_API.c:1930) ==18251== by 0x839C3ED: php_module_startup (main.c:2323) ==18251== ==18251== 64 bytes in 1 blocks are still reachable in loss record 8 of 10 ==18251== at 0x402D1AE: malloc (vg_replace_malloc.c:299) ==18251== by 0x43444B6: ??? (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x4344A8E: CRYPTO_malloc (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x43C2ACF: lh_new (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x4345FF5: ??? (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x43460A4: ??? (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x434620A: ??? (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x4346486: CRYPTO_get_ex_new_index (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x42D6BE9: SSL_get_ex_new_index (in /lib/i386-linux-gnu/libssl.so.1.0.0) ==18251== by 0x80B6D14: zm_startup_openssl (openssl.c:1153) ==18251== by 0x841DF6A: zend_startup_module_ex (zend_API.c:1797) ==18251== by 0x841DFCF: zend_startup_module_int (zend_API.c:1810) ==18251== ==18251== 96 bytes in 1 blocks are still reachable in loss record 9 of 10 ==18251== at 0x402D1AE: malloc (vg_replace_malloc.c:299) ==18251== by 0x43444B6: ??? (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x4344A8E: CRYPTO_malloc (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x43C2AB5: lh_new (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x4345FF5: ??? (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x43460A4: ??? (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x434620A: ??? (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x4346486: CRYPTO_get_ex_new_index (in /lib/i386-linux-gnu/libcrypto.so.1.0.0) ==18251== by 0x42D6BE9: SSL_get_ex_new_index (in /lib/i386-linux-gnu/libssl.so.1.0.0) ==18251== by 0x80B6D14: zm_startup_openssl (openssl.c:1153) ==18251== by 0x841DF6A: zend_startup_module_ex (zend_API.c:1797) ==18251== by 0x841DFCF: zend_startup_module_int (zend_API.c:1810) ==18251== ==18251== 18,944 bytes in 1 blocks are still reachable in loss record 10 of 10 ==18251== at 0x402D1AE: malloc (vg_replace_malloc.c:299) ==18251== by 0x61A95BA: ??? (in /usr/lib/i386-linux-gnu/libstdc++.so.6.0.21) ==18251== by 0x400F364: call_init.part.0 (dl-init.c:72) ==18251== by 0x400F48D: call_init (dl-init.c:30) ==18251== by 0x400F48D: _dl_init (dl-init.c:120) ==18251== by 0x4000AFE: ??? (in /lib/i386-linux-gnu/ld-2.23.so) ==18251== ==18251== LEAK SUMMARY: ==18251== definitely lost: 0 bytes in 0 blocks ==18251== indirectly lost: 0 bytes in 0 blocks ==18251== possibly lost: 0 bytes in 0 blocks ==18251== still reachable: 19,220 bytes in 10 blocks ==18251== suppressed: 0 bytes in 0 blocks ==18251== ==18251== ERROR SUMMARY: 0 errors from 0 contexts (suppressed: 0 from 0) ==18251== ERROR SUMMARY: 0 errors from 0 contexts (suppressed: 0 from 0) ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=73361 -- Edit this bug report at https://bugs.php.net/bug.php?id=73361&edit=1

« previous php.bugs (#204998) next »