Bug #75795 [NEW]: Interned strings buffer overflow cause crash in Rouncdube webmail
| From: | post at minhost dot no | Date: | Wed, 10 Jan 2018 16:10:04 +0000 |
| Subject: | Bug #75795 [NEW]: Interned strings buffer overflow cause crash in Rouncdube webmail | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-213460@lists.php.net to get a copy of this message | ||
From: post at minhost dot no
Operating system: CentOS 7.4
PHP version: 7.1.13
Package: opcache
Bug Type: Bug
Bug description:Interned strings buffer overflow cause crash in Rouncdube webmail
Description:
------------
(This bug is related to bug #75579 wich was fixed in PHP 7.1.13.)
First some info about my setup: I am running Apache 2.4.29, PHP-FPM
7.1.13 with Opcache both in memory and with file cache on disk. Here is
my Opcache .ini settings:
opcache.memory_consumption=32768
opcache.interned_strings_buffer=64
opcache.max_accelerated_files=1000000
opcache.revalidate_freq=0
opcache.validate_timestamps=1
opcache.fast_shutdown=1
opcache.enable_cli=0
opcache.validate_permission=1
opcache.validate_root=1
opcache.use_cwd=1
opcache.revalidate_path=1
opcache.enable_file_override=1
opcache.file_cache=/var/www/tmp/.opcache
opcache.file_cache_only=0
opcache.max_wasted_percentage=10
After upgrade from PHP 7.1.11 to PHP 7.1.13 the previous bug #75579
seems fixed except for Roundcube webmail wich still crash. All other PHP
scripts seems to work correct.
What happens is when interned_strings_buffer is empty and Roundcube
webmail have not been visited before interned_strings_buffer became
empty, so it is not in Opcache already, then it will crash when you
visit the log in page to Roundcube webmail. At the same time, all other
PHP scripts works correct except for Roundcube webmail. When it crash it
will display this in a browser:
Service Unavailable
The server is temporarily unable to service your request due to
maintenance downtime or capacity problems. Please try again later.
Additionally, a 503 Service Unavailable error was encountered while
trying to use an ErrorDocument to handle the request.
And in Apche error log it will display this:
[Wed Jan 10 11:07:10.167008 2018] [proxy_fcgi:error] [pid 26262:tid
139668105803520] (104)Connection reset by peer: [client
176.74.214.18:52064] AH01075: Error dispatching request to :
If you reload PHP-FPM and visit Roundcube webmail log in page before
interned_strings_buffer become empty, then it will work without
crashing, and it will continue to work even when interned_strings_buffer
become empty later on. So the crash will only happen when nobody have
visited Roundcube webmail before interned_strings_buffer became empty,
then it will crash on a visit to the page and continue to not work until
next time PHP-FPM is reloaded.
Here is how to quickly reproduce the bug. Configure Opcache with
file_cache enabled and set interned_strings_buffer to 0:
opcache.interned_strings_buffer=0
opcache.file_cache=/var/www/tmp/.opcache
opcache.file_cache_only=0
Then install latest Roundcube webmail version 1.3.3 from roundcube.net
and visit Roundcube login page, it will then crash as described above.
If you then remove the .ini setting opcache.file_cache, it will work
again without crashing.
If your are patient enough, you could also set
opcache.interned_strings_buffer very low to for example 1, and then
visit other PHP pages on the server until the interned buffer strings is
all used and empty, and then you can visit Roundcube webmail login page,
and it will crash, but alle other PHP pages, except Roundcube, will
continue to work. But remember to not visit Roundcube before
interned_strings_buffer is empty.
Please use this to figure out wich PHP scripts/code in Roundcube webmail
that is triggering this bug in interned_strings_buffer. Please let me
know if you need more information about my setup.
--
Edit bug report at https://bugs.php.net/bug.php?id=75795&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=75795&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=75795&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=75795&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=75795&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=75795&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=75795&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=75795&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=75795&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=75795&r=support
Expected behavior: https://bugs.php.net/fix.php?id=75795&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=75795&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=75795&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=75795&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=75795&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=75795&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=75795&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=75795&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=75795&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=75795&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=75795&r=mysqlcfg