Bug #77494 [Asn]: Disabling class causes segfault on member access

From: Date: Thu, 24 Jan 2019 03:27:54 +0000
Subject: Bug #77494 [Asn]: Disabling class causes segfault on member access
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-219159@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77494&edit=1 ID: 77494 Updated by: laruence@php.net Reported by: 64796c6e69 at gmail dot com Summary: Disabling class causes segfault on member access Status: Assigned Type: Bug Package: Scripting Engine problem Operating System: Linux PHP Version: 7.3Git-2019-01-20 (Git) Assigned To: dmitry Block user comment: N Private report: Y New Comment: I think it better to make all objects as Stdclass instances when it is initialized by disabled classes Previous Comments: ------------------------------------------------------------------------ [2019-01-21 01:14:44] stas@php.net Looks like the problem happens because disabled class ctor is not calling object_properties_init, thus properties remain un-initialized when disabling the class and access to them results in accessing uninitialized data. Not sure why cli and CGI differ here - may be how memory allocator works there? Or maybe some switch I've missed? Doesn't seem to be security issue since requires special user-side code. I am not super-familiar with new object code though so I think somebody like Nikita or Dmitry should take a look and see if my diagnosis is correct. ------------------------------------------------------------------------ [2019-01-20 23:00:17] 64796c6e69 at gmail dot com Description: ------------ When CURLFile is disabled using disable_classes, curl_file_create() and new CURLFile() only give warnings. The class is still constructed even when strict types are enabled. Worse, if the object was constructed with no arguments using either method, working with it further causes a segfault when the class is disabled. The segfault happens in interactive mode and CGI. I also tested CLI, which does not have the problem. Another strange problem is that some longer filenames do not cause a segfault. For example, name the file file123456789.php, and the var_dump() line outputs NULL. All of the described behavior happens in PHP 7.2 and the master branch from Git. Test script: --------------- CLI: php-cgi -ddisable_classes=CURLFile -ffile.php file.php: <?php $a = new CURLFile(); var_dump($a->name); Expected result: ---------------- An error about the class being disabled. Actual result: -------------- <br /> <b>Warning</b>: CURLFile() has been disabled for security reasons in <b>REDACTED/file.php</b> on line <b>2</b><br /> UNKNOWN:0 Segmentation fault (core dumped) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77494&edit=1

« previous php.bugs (#219159) next »