Bug #73342 [Com]: Vulnerability in php-fpm by changing stdin to non-blocking
| From: | alex at sirensclef dot com | Date: | Mon, 11 Jun 2018 12:39:27 +0000 |
| Subject: | Bug #73342 [Com]: Vulnerability in php-fpm by changing stdin to non-blocking | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-215617@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73342&edit=1
ID: 73342
Comment by: alex at sirensclef dot com
Reported by: xuavis at gmail dot com
Summary: Vulnerability in php-fpm by changing stdin to
non-blocking
Status: Verified
Type: Bug
Package: FPM related
Operating System: Ubuntu 16.04
PHP Version: 7.0Git-2016-10-18 (Git)
Assigned To: bukka
Block user comment: N
Private report: N
New Comment:
I'm under some pressure to put together a production PHP 7.2 + FPM setup, but then I ran head
first into this bug. I don't know what's worse... that a critical subset of PHP
functionality is incompatible with PHP-FPM, or that this has been known for so long and nothing has
been done.
Is anyone aware of a workaround (other than this patch being evaluated)? I've got more of a
mod_php background so I'm only just developing an understanding of the options here, but
I've had no luck making adjustments to neutralize the issue. I've tested an option, for a
dev server, that uses a cron to check the php-fpm log every minute and restart the service whenever
the issue arises, but I can't put that into production. Worried this setup is simply a
non-starter.
Previous Comments:
------------------------------------------------------------------------
[2018-04-24 06:10:05] gksalil at gmail dot com
Hello
Is the patch working and fix the issue ? Can I apply this patch safely ?
Thanks
~S
------------------------------------------------------------------------
[2018-03-07 09:22:28] kenny at kennynet dot co dot uk
We've deployed the suggested patch removing the use of STDIN internally (currently in testing
pending production deployment). I'll update this bug report if we see any problems caused by
it.
------------------------------------------------------------------------
[2018-02-25 19:21:00] bukka@php.net
@nikic I think that the reason why FPM cares about STDIN is to conform FastCGI spec - namely section
2.2 ( http://www.mit.edu/~yandros/doc/specs/fcgi-spec.html#S2.2
) that states "FCGI_LISTENSOCK_FILENO equals STDIN_FILENO".
I guess it's because maybe some FastCGI application could access the data directly from the
record but not really sure why. I can't really see the reason for that in the PHP case. I
don't see any side effects of the patch at the moment but it might need a bit more thinking and
testing.
------------------------------------------------------------------------
[2018-02-23 21:10:52] nikic@php.net
Related To: Bug #67796
------------------------------------------------------------------------
[2018-02-23 20:48:52] nikic@php.net
Related To: Bug #73056
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=73342
--
Edit this bug report at https://bugs.php.net/bug.php?id=73342&edit=1