Bug #74540 [NEW]: use-after-free bug

From: Date: Thu, 04 May 2017 07:49:18 +0000
Subject: Bug #74540 [NEW]: use-after-free bug
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-208949@lists.php.net to get a copy of this message
From:             yanhuacs at gmail dot com
Operating system: Ubuntu14.04
PHP version:      5.6.30
Package:          opcache
Bug Type:         Bug
Bug description:use-after-free bug

Description:
------------
I'd like to report potential a use-after-free bug in PHP-5.6.30 as
follows.

Step 1, in ext/opcache/zend_persist.c,
function zend_ast *zend_persist_ast calls function _zend_shared_memdup
in line 153.
Step 2, in ext/opcache/zend_shared_alloc.c,
function _zend_shared_memdup frees "source", which is a pointer aliased
with "ast" (due to parameter passing) in line 153 in
ext/opcache/zend_persist.c.
Step 3, _zend_shared_memdup returns to its call site in line 153 in
ext/opcache/zend_persist.c.
Step 4, in line 154, "ast" is dereferenced, which is a use-after-free.


/*--- ext/opcache/zend_persist.c ---*/
143 static zend_ast *zend_persist_ast(zend_ast *ast TSRMLS_DC)
144 {
145         int i;
146         zend_ast *node;
147
148         if (ast->kind == ZEND_CONST) {
149                 node = zend_accel_memdup(ast, sizeof(zend_ast) +
sizeof(zval));
150                 node->u.val = (zval*)(node + 1);
151                 zend_persist_zval(node->u.val TSRMLS_CC);
152         } else {
153                 node = zend_accel_memdup(ast, sizeof(zend_ast) +
sizeof(zend_ast*) * (ast->children - 1));
154                 for (i = 0; i < ast->children; i++) {
155                         if ((&node->u.child)[i]) {
156                                 (&node->u.child)[i] =
zend_persist_ast((&node->u.child)[i] TSRMLS_CC);
157                         }
158                 }
159         }
160         efree(ast);
161         return node;
162 }


/*--- ext/opcache/zend_shared_alloc.c ---*/
338 void *_zend_shared_memdup(void *source, size_t size, zend_bool
free_source TSRMLS_DC)
339 {
340         void **old_p, *retval;
341
342         if (zend_hash_index_find(&xlat_table, (ulong)source, (void
**)&old_p) == SUCCESS) {
343                 /* we already duplicated this pointer */
344                 return *old_p;
345         }
346         retval = ZCG(mem);;
347         ZCG(mem) = (void*)(((char*)ZCG(mem)) +
ZEND_ALIGNED_SIZE(size));
348         memcpy(retval, source, size);
349         zend_shared_alloc_register_xlat_entry(source, retval);
350         if (free_source) {
351                 interned_efree((char*)source);
352         }
353         return retval;
354 }



-- 
Edit bug report at https://bugs.php.net/bug.php?id=74540&edit=1
-- 
Try a snapshot (PHP 5.4):   https://bugs.php.net/fix.php?id=74540&r=trysnapshot54
Try a snapshot (PHP 5.5):   https://bugs.php.net/fix.php?id=74540&r=trysnapshot55
Try a snapshot (trunk):     https://bugs.php.net/fix.php?id=74540&r=trysnapshottrunk
Fixed in SVN:               https://bugs.php.net/fix.php?id=74540&r=fixed
Fixed in release:           https://bugs.php.net/fix.php?id=74540&r=alreadyfixed
Need backtrace:             https://bugs.php.net/fix.php?id=74540&r=needtrace
Need Reproduce Script:      https://bugs.php.net/fix.php?id=74540&r=needscript
Try newer version:          https://bugs.php.net/fix.php?id=74540&r=oldversion
Not developer issue:        https://bugs.php.net/fix.php?id=74540&r=support
Expected behavior:          https://bugs.php.net/fix.php?id=74540&r=notwrong
Not enough info:            https://bugs.php.net/fix.php?id=74540&r=notenoughinfo
Submitted twice:            https://bugs.php.net/fix.php?id=74540&r=submittedtwice
register_globals:           https://bugs.php.net/fix.php?id=74540&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=74540&r=php4
Daylight Savings:           https://bugs.php.net/fix.php?id=74540&r=dst
IIS Stability:              https://bugs.php.net/fix.php?id=74540&r=isapi
Install GNU Sed:            https://bugs.php.net/fix.php?id=74540&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=74540&r=float
No Zend Extensions:         https://bugs.php.net/fix.php?id=74540&r=nozend
MySQL Configuration Error:  https://bugs.php.net/fix.php?id=74540&r=mysqlcfg



Thread (2 messages)

« previous php.bugs (#208949) next »