Bug #75795 [NEW]: Interned strings buffer overflow cause crash in Rouncdube webmail

From: Date: Wed, 10 Jan 2018 16:10:04 +0000
Subject: Bug #75795 [NEW]: Interned strings buffer overflow cause crash in Rouncdube webmail
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-213460@lists.php.net to get a copy of this message
From: post at minhost dot no Operating system: CentOS 7.4 PHP version: 7.1.13 Package: opcache Bug Type: Bug Bug description:Interned strings buffer overflow cause crash in Rouncdube webmail Description: ------------ (This bug is related to bug #75579 wich was fixed in PHP 7.1.13.) First some info about my setup: I am running Apache 2.4.29, PHP-FPM 7.1.13 with Opcache both in memory and with file cache on disk. Here is my Opcache .ini settings: opcache.memory_consumption=32768 opcache.interned_strings_buffer=64 opcache.max_accelerated_files=1000000 opcache.revalidate_freq=0 opcache.validate_timestamps=1 opcache.fast_shutdown=1 opcache.enable_cli=0 opcache.validate_permission=1 opcache.validate_root=1 opcache.use_cwd=1 opcache.revalidate_path=1 opcache.enable_file_override=1 opcache.file_cache=/var/www/tmp/.opcache opcache.file_cache_only=0 opcache.max_wasted_percentage=10 After upgrade from PHP 7.1.11 to PHP 7.1.13 the previous bug #75579 seems fixed except for Roundcube webmail wich still crash. All other PHP scripts seems to work correct. What happens is when interned_strings_buffer is empty and Roundcube webmail have not been visited before interned_strings_buffer became empty, so it is not in Opcache already, then it will crash when you visit the log in page to Roundcube webmail. At the same time, all other PHP scripts works correct except for Roundcube webmail. When it crash it will display this in a browser: Service Unavailable The server is temporarily unable to service your request due to maintenance downtime or capacity problems. Please try again later. Additionally, a 503 Service Unavailable error was encountered while trying to use an ErrorDocument to handle the request. And in Apche error log it will display this: [Wed Jan 10 11:07:10.167008 2018] [proxy_fcgi:error] [pid 26262:tid 139668105803520] (104)Connection reset by peer: [client 176.74.214.18:52064] AH01075: Error dispatching request to : If you reload PHP-FPM and visit Roundcube webmail log in page before interned_strings_buffer become empty, then it will work without crashing, and it will continue to work even when interned_strings_buffer become empty later on. So the crash will only happen when nobody have visited Roundcube webmail before interned_strings_buffer became empty, then it will crash on a visit to the page and continue to not work until next time PHP-FPM is reloaded. Here is how to quickly reproduce the bug. Configure Opcache with file_cache enabled and set interned_strings_buffer to 0: opcache.interned_strings_buffer=0 opcache.file_cache=/var/www/tmp/.opcache opcache.file_cache_only=0 Then install latest Roundcube webmail version 1.3.3 from roundcube.net and visit Roundcube login page, it will then crash as described above. If you then remove the .ini setting opcache.file_cache, it will work again without crashing. If your are patient enough, you could also set opcache.interned_strings_buffer very low to for example 1, and then visit other PHP pages on the server until the interned buffer strings is all used and empty, and then you can visit Roundcube webmail login page, and it will crash, but alle other PHP pages, except Roundcube, will continue to work. But remember to not visit Roundcube before interned_strings_buffer is empty. Please use this to figure out wich PHP scripts/code in Roundcube webmail that is triggering this bug in interned_strings_buffer. Please let me know if you need more information about my setup. -- Edit bug report at https://bugs.php.net/bug.php?id=75795&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=75795&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=75795&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=75795&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=75795&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=75795&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=75795&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=75795&r=needscript Try newer version: https://bugs.php.net/fix.php?id=75795&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=75795&r=support Expected behavior: https://bugs.php.net/fix.php?id=75795&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=75795&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=75795&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=75795&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=75795&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=75795&r=dst IIS Stability: https://bugs.php.net/fix.php?id=75795&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=75795&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=75795&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=75795&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=75795&r=mysqlcfg

« previous php.bugs (#213460) next »