Bug #76542 [Opn->Csd]: Memory leak during verify_peer_name validation of a SAN SSL certificate

From: Date: Thu, 27 Jun 2019 08:49:37 +0000
Subject: Bug #76542 [Opn->Csd]: Memory leak during verify_peer_name validation of a SAN SSL certificate
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-221510@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76542&edit=1 ID: 76542 Updated by: nikic@php.net Reported by: php at lvl dot fastmail dot com Summary: Memory leak during verify_peer_name validation of a SAN SSL certificate -Status: Open +Status: Closed Type: Bug Package: OpenSSL related Operating System: Ubuntu 18.04 PHP Version: 7.2.7 -Assigned To: +Assigned To: nikic Block user comment: N Private report: N New Comment: Should be fixed by https://github.com/php/php-src/commit/fea9f93166a31760679101269aee2326ee8185e9#diff-fba6f2ad888bf4d71a91b060dfee4522. Previous Comments: ------------------------------------------------------------------------ [2018-06-28 22:20:32] php at lvl dot fastmail dot com Description: ------------ Originally discovered here: https://github.com/reactphp/http-client/issues/134. Verified with version 7.2.7-1+ubuntu18.04.1+deb.sury.org+1 on Ubuntu 18.04, libssl 1.1.0g. There's a memory leak in PHP's validation of SSL certificates when that SSL certificate contains SAN entries. Since nearly every real world SSL certificate uses SAN, this means every long-running PHP script that acts as a HTTPS client will eventually run out of memory. To reproduce, first create a self-signed certificate with SAN: openssl req \ -newkey rsa:2048 \ -x509 \ -nodes \ -keyout server.key \ -new \ -out server.crt \ -subj /CN=127.0.0.1 \ -reqexts SAN \ -extensions SAN \ -config <(cat /etc/ssl/openssl.cnf \ <(printf '[SAN]\nsubjectAltName=DNS:127.0.0.1,DNS:127.0.0.2')) \ -sha256 \ -days 3650 Then configure for example nginx to use this certificate: server { listen 443 ssl; ssl_certificate /etc/nginx/server.crt; ssl_certificate_key /etc/nginx/server.key; return 201; } Finally run the test script below and observe using "top" that PHP's memory usage is quickly increasing. Calls to memory_get_usage() will *not* show signs of the leak though. Running this test with a SSL certificate without the subjectAltName entry will *not* trigger the memory leak. Add ['verify_peer_name' => false] to the ssl context options and there will *not* be a leak. Test script: --------------- <?php $options = [ 'ssl' => [ 'verify_peer' => false ] ]; while (true) { $response = file_get_contents('https://127.0.0.1', false, stream_context_create($options)); } ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=76542&edit=1

« previous php.bugs (#221510) next »