Bug #75795 [Com]: Interned strings buffer overflow cause crash in Rouncdube webmail

From: Date: Wed, 24 Jan 2018 14:34:15 +0000
Subject: Bug #75795 [Com]: Interned strings buffer overflow cause crash in Rouncdube webmail
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-213689@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75795&edit=1 ID: 75795 Comment by: post at minhost dot no Reported by: post at minhost dot no Summary: Interned strings buffer overflow cause crash in Rouncdube webmail Status: Open Type: Bug Package: opcache Operating System: CentOS 7.4 PHP Version: 7.1.13 Block user comment: N Private report: N New Comment: It seems the bug was not in PHP. The problem described started after we 4 of january updated to new linux-firmware and microcode_ctl from CentOS/RedHat: linux-firmware security update (2018-01-03): https://access.redhat.com/errata/RHSA-2018:0014 microcode_ctl security update (2018-01-03): https://access.redhat.com/errata/RHSA-2018:0012 Then at 2018-01-16 RedHat reverted the linux-firmware and microcode_ctl update to the last known good version dated before 03 January 2018: linux-firmware security update (2018-01-16): https://access.redhat.com/errata/RHSA-2018:0094 microcode_ctl security update (2018-01-16): https://access.redhat.com/errata/RHSA-2018:0093 After I updated my systems to the reverted linux-firmware and microcode_ctl update from of 2018-01-16, then the bug disappeared! This is really crazy. I am not able to reproduce the bug after I updated to the reverted updates from RedHat. Because of this, I am closing this bug report. Previous Comments: ------------------------------------------------------------------------ [2018-01-13 11:58:27] post at minhost dot no Related To: Bug #75579 ------------------------------------------------------------------------ [2018-01-10 16:10:00] post at minhost dot no Description: ------------ (This bug is related to bug #75579 wich was fixed in PHP 7.1.13.) First some info about my setup: I am running Apache 2.4.29, PHP-FPM 7.1.13 with Opcache both in memory and with file cache on disk. Here is my Opcache .ini settings: opcache.memory_consumption=32768 opcache.interned_strings_buffer=64 opcache.max_accelerated_files=1000000 opcache.revalidate_freq=0 opcache.validate_timestamps=1 opcache.fast_shutdown=1 opcache.enable_cli=0 opcache.validate_permission=1 opcache.validate_root=1 opcache.use_cwd=1 opcache.revalidate_path=1 opcache.enable_file_override=1 opcache.file_cache=/var/www/tmp/.opcache opcache.file_cache_only=0 opcache.max_wasted_percentage=10 After upgrade from PHP 7.1.11 to PHP 7.1.13 the previous bug #75579 seems fixed except for Roundcube webmail wich still crash. All other PHP scripts seems to work correct. What happens is when interned_strings_buffer is empty and Roundcube webmail have not been visited before interned_strings_buffer became empty, so it is not in Opcache already, then it will crash when you visit the log in page to Roundcube webmail. At the same time, all other PHP scripts works correct except for Roundcube webmail. When it crash it will display this in a browser: Service Unavailable The server is temporarily unable to service your request due to maintenance downtime or capacity problems. Please try again later. Additionally, a 503 Service Unavailable error was encountered while trying to use an ErrorDocument to handle the request. And in Apche error log it will display this: [Wed Jan 10 11:07:10.167008 2018] [proxy_fcgi:error] [pid 26262:tid 139668105803520] (104)Connection reset by peer: [client 176.74.214.18:52064] AH01075: Error dispatching request to : If you reload PHP-FPM and visit Roundcube webmail log in page before interned_strings_buffer become empty, then it will work without crashing, and it will continue to work even when interned_strings_buffer become empty later on. So the crash will only happen when nobody have visited Roundcube webmail before interned_strings_buffer became empty, then it will crash on a visit to the page and continue to not work until next time PHP-FPM is reloaded. Here is how to quickly reproduce the bug. Configure Opcache with file_cache enabled and set interned_strings_buffer to 0: opcache.interned_strings_buffer=0 opcache.file_cache=/var/www/tmp/.opcache opcache.file_cache_only=0 Then install latest Roundcube webmail version 1.3.3 from roundcube.net and visit Roundcube login page, it will then crash as described above. If you then remove the .ini setting opcache.file_cache, it will work again without crashing. If your are patient enough, you could also set opcache.interned_strings_buffer very low to for example 1, and then visit other PHP pages on the server until the interned buffer strings is all used and empty, and then you can visit Roundcube webmail login page, and it will crash, but alle other PHP pages, except Roundcube, will continue to work. But remember to not visit Roundcube before interned_strings_buffer is empty. Please use this to figure out wich PHP scripts/code in Roundcube webmail that is triggering this bug in interned_strings_buffer. Please let me know if you need more information about my setup. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=75795&edit=1

« previous php.bugs (#213689) next »