Bug #74951 [Ver->Csd]: Null pointer dereference in add_property_resource_ex()
| From: | pollita@php.net | Date: | Wed, 19 Jul 2017 18:06:18 +0000 |
| Subject: | Bug #74951 [Ver->Csd]: Null pointer dereference in add_property_resource_ex() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-210142@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=74951&edit=1
ID: 74951
Updated by: pollita@php.net
Reported by: fumfi dot 255 at gmail dot com
Summary: Null pointer dereference in
add_property_resource_ex()
-Status: Verified
+Status: Closed
Type: Bug
Package: *General Issues
Operating System: Linux x64
PHP Version: 7.1.7
Assigned To: pollita
Block user comment: N
Private report: N
New Comment:
https://github.com/php/php-src/commit/c9fd093127e1386a4cd768749d42fe148a87e9e2
This fix should be in the next releases of 7.[012] AFTER the releases scheduled for tomorrow as
they've already been cut.
Previous Comments:
------------------------------------------------------------------------
[2017-07-19 16:30:42] pollita@php.net
Verified. Should be easy fix.
------------------------------------------------------------------------
[2017-07-19 11:00:45] fumfi dot 255 at gmail dot com
Description:
------------
After some fuzz testing I found a crashing test case.
PHP 7.1.6 compiled from source with ASAN.
To reproduce: /php-7.1.6/sapi/cli/php php_null_ptr_add_property_resource_ex.php
ASAN report:
==21705==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000018 (pc 0x0000017f43a9 bp
0x7ffff9782530 sp 0x7ffff9782460 T0)
==21705==The signal is caused by a READ memory access.
==21705==Hint: address points to the zero page.
#0 0x17f43a8 in add_property_resource_ex XYZ/php-7.1.6/Zend/zend_API.c:1722:2
#1 0x16167d7 in user_stream_create_object XYZ/php-7.1.6/main/streams/userspace.c:290:3
#2 0x1611afd in user_wrapper_opener XYZ/php-7.1.6/main/streams/userspace.c:357:2
#3 0x15f2121 in _php_stream_open_wrapper_ex XYZ/php-7.1.6/main/streams/streams.c:2055:13
#4 0x1391f60 in php_if_fopen XYZ/php-7.1.6/ext/standard/file.c:870:11
#5 0x10db629 in phar_fopen XYZ/php-7.1.6/ext/phar/func_interceptors.c:427:2
#6 0x1b0c5e2 in ZEND_DO_ICALL_SPEC_RETVAL_USED_HANDLER
XYZ/php-7.1.6/Zend/zend_vm_execute.h:675:2
#7 0x19752fd in execute_ex XYZ/php-7.1.6/Zend/zend_vm_execute.h:432:7
#8 0x19762db in zend_execute XYZ/php-7.1.6/Zend/zend_vm_execute.h:474:2
#9 0x17d7f09 in zend_execute_scripts XYZ/php-7.1.6/Zend/zend.c:1476:4
#10 0x1570102 in php_execute_script XYZ/php-7.1.6/main/main.c:2537:14
#11 0x1c4b05d in do_cli XYZ/php-7.1.6/sapi/cli/php_cli.c:993:5
#12 0x1c478d5 in main XYZ/php-7.1.6/sapi/cli/php_cli.c:1381:18
#13 0x7f85bd76c82f in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x2082f)
#14 0x43abf8 in _start (XYZ/php-7.1.6/sapi/cli/php+0x43abf8)
AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV XYZ/php-7.1.6/Zend/zend_API.c:1722:2 in add_property_resource_ex
==21705==ABORTING
Test script:
---------------
<?php
trait Stream00ploiter{public function s(){}public function
n($_){}}var_dump();stream_wrapper_register('e0ploit','Stream00ploiter');$s=fopen('e0ploit://',0);
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74951&edit=1