Bug #77124 [Opn->Ver]: FTP with SSL memory leak

From: Date: Thu, 08 Nov 2018 16:34:00 +0000
Subject: Bug #77124 [Opn->Ver]: FTP with SSL memory leak
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-217873@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77124&edit=1

 ID:                 77124
 Updated by:         cmb@php.net
 Reported by:        antoine dot guenard+php at gmail dot com
 Summary:            FTP with SSL memory leak
-Status:             Open
+Status:             Verified
 Type:               Bug
 Package:            FTP related
 Operating System:   Debian GNU/Linux 9 (stretch)
 PHP Version:        7.2.12
 Block user comment: N
 Private report:     N

 New Comment:

It seems that we're leaking the SSL_CTX object[1] which is used to
initialize an SSL structure[2], but will only be freed[3] if the
latter fails.  Moving the SSL_free() out of the if statement
(always-free-context.path) should solve the memory leak, and
doesn't appear to introduce any regression.  Since I don't have
any experience with libopenssl, I'm not sure whether freeing the
context unconditionally here is okay, though.

[1] <https://github.com/php/php-src/blob/php-7.3.0RC5/ext/ftp/ftp.c#L275>
[2] <https://github.com/php/php-src/blob/php-7.3.0RC5/ext/ftp/ftp.c#L289>
[3] <https://github.com/php/php-src/blob/php-7.3.0RC5/ext/ftp/ftp.c#L292>


Previous Comments:
------------------------------------------------------------------------
[2018-11-08 16:33:57] cmb@php.net

The following patch has been added/updated:

Patch Name: always-free-context
Revision:   1541694836
URL:        https://bugs.php.net/patch-display.php?bug=77124&patch=always-free-context&revision=1541694836

------------------------------------------------------------------------
[2018-11-08 14:20:29] antoine dot guenard+php at gmail dot com

Description:
------------
Tested on PHP 7.2.10, there might be memory leak while using ftp_login function and maybe other
functions with FTPS (FTP over SSL).

To reproduce the memory leak, you should open a connection to a FTP server with SSL and then try to
login with ftp_login. The test script uses a public FTP that supports SSL for testing but I could
reproduce with other FTP servers with valid or invalid credentials.

I also provided another test script (for Unix/Linux) that uses an infinite loop to have a better
view of the memory increasing at every turn just after ftp_login is called, see:

https://gist.githubusercontent.com/guenard/6fca07e5c99f959de42dbed67628acf9/raw/b1c97d732a3e8acf249cf415e067b7f0e94075ae/lopp-ftp-with-ssl-login-memory-leak.php

The closest issue I found was https://bugs.php.net/bug.php?id=65228 but it looks
like the patch has made it from PHP 5.5.x to PHP 7.2.x.

Test script:
---------------
<?php
$conn = @ftp_ssl_connect('test.rebex.net', 21);
@ftp_login($conn, '', '');
@ftp_close($conn);

Expected result:
----------------
No memory leak.

Actual result:
--------------
==9752== LEAK SUMMARY:
==9752==    definitely lost: 947 bytes in 6 blocks
==9752==    indirectly lost: 15,057 bytes in 219 blocks
==9752==      possibly lost: 0 bytes in 0 blocks
==9752==    still reachable: 4,267 bytes in 26 blocks
==9752==         suppressed: 0 bytes in 0 blocks


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=77124&edit=1


Thread (4 messages)

« previous php.bugs (#217873) next »