Bug #74540 [NEW]: use-after-free bug
From: yanhuacs at gmail dot com
Operating system: Ubuntu14.04
PHP version: 5.6.30
Package: opcache
Bug Type: Bug
Bug description:use-after-free bug
Description:
------------
I'd like to report potential a use-after-free bug in PHP-5.6.30 as
follows.
Step 1, in ext/opcache/zend_persist.c,
function zend_ast *zend_persist_ast calls function _zend_shared_memdup
in line 153.
Step 2, in ext/opcache/zend_shared_alloc.c,
function _zend_shared_memdup frees "source", which is a pointer aliased
with "ast" (due to parameter passing) in line 153 in
ext/opcache/zend_persist.c.
Step 3, _zend_shared_memdup returns to its call site in line 153 in
ext/opcache/zend_persist.c.
Step 4, in line 154, "ast" is dereferenced, which is a use-after-free.
/*--- ext/opcache/zend_persist.c ---*/
143 static zend_ast *zend_persist_ast(zend_ast *ast TSRMLS_DC)
144 {
145 int i;
146 zend_ast *node;
147
148 if (ast->kind == ZEND_CONST) {
149 node = zend_accel_memdup(ast, sizeof(zend_ast) +
sizeof(zval));
150 node->u.val = (zval*)(node + 1);
151 zend_persist_zval(node->u.val TSRMLS_CC);
152 } else {
153 node = zend_accel_memdup(ast, sizeof(zend_ast) +
sizeof(zend_ast*) * (ast->children - 1));
154 for (i = 0; i < ast->children; i++) {
155 if ((&node->u.child)[i]) {
156 (&node->u.child)[i] =
zend_persist_ast((&node->u.child)[i] TSRMLS_CC);
157 }
158 }
159 }
160 efree(ast);
161 return node;
162 }
/*--- ext/opcache/zend_shared_alloc.c ---*/
338 void *_zend_shared_memdup(void *source, size_t size, zend_bool
free_source TSRMLS_DC)
339 {
340 void **old_p, *retval;
341
342 if (zend_hash_index_find(&xlat_table, (ulong)source, (void
**)&old_p) == SUCCESS) {
343 /* we already duplicated this pointer */
344 return *old_p;
345 }
346 retval = ZCG(mem);;
347 ZCG(mem) = (void*)(((char*)ZCG(mem)) +
ZEND_ALIGNED_SIZE(size));
348 memcpy(retval, source, size);
349 zend_shared_alloc_register_xlat_entry(source, retval);
350 if (free_source) {
351 interned_efree((char*)source);
352 }
353 return retval;
354 }
--
Edit bug report at https://bugs.php.net/bug.php?id=74540&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=74540&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=74540&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=74540&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=74540&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=74540&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=74540&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=74540&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=74540&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=74540&r=support
Expected behavior: https://bugs.php.net/fix.php?id=74540&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=74540&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=74540&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=74540&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=74540&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=74540&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=74540&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=74540&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=74540&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=74540&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=74540&r=mysqlcfg
Thread (2 messages)
- yanhuacs at gmail dot com