Bug #78549 [Ver->Csd]: Stack overflow due to nested serialized input

From: Date: Mon, 30 Sep 2019 08:32:59 +0000
Subject: Bug #78549 [Ver->Csd]: Stack overflow due to nested serialized input
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-222954@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78549&edit=1 ID: 78549 Updated by: nikic@php.net Reported by: marc dot schoenefeld at gmx dot org Summary: Stack overflow due to nested serialized input -Status: Verified +Status: Closed Type: Bug Package: Reproducible crash Operating System: CentOS 7 / Generic PHP Version: 7.3.9 -Assigned To: +Assigned To: nikic Block user comment: N Private report: N New Comment: Fixed by https://github.com/php/php-src/commit/1806ce9cb019ee74ddb540cbc07daf121dcb5537. Previous Comments: ------------------------------------------------------------------------ [2019-09-24 10:18:50] nikic@php.net The following pull request has been associated: Patch Name: Add max_depth option to unserialize() On GitHub: https://github.com/php/php-src/pull/4742 Patch: https://github.com/php/php-src/pull/4742.patch ------------------------------------------------------------------------ [2019-09-23 11:38:19] nikic@php.net Fuzzing seems to hit this quite often, so we should probably do something about it. Script to find the limit: <?php $str = 'i:0;'; for ($i = 0; $i < 10000; $i++) { $str = 'a:1:{i:0;' . $str . '}'; if ($i % 10 == 0) { echo "$i\n"; unserialize($str); } } var_dump($str); I get 5620 on a debug build and 7690 on a release/assert build. Trying the same with O:8:"stdClass":1 I get 4630 and 7690. We can add an unserialize option for the max_depth and default it to something like 4000. ------------------------------------------------------------------------ [2019-09-16 13:51:59] nikic@php.net https://gist.githubusercontent.com/nikic/200240ca7830c6e5d587b3b4aad927eb/raw/d8b02e0bb1deca31025dbaf50a46ab4ab792bf68/php_7_3_9_stack_overflow.ser I doubt we're going to rewriting the unserializer in a non-recursive fashion, so we can either introduce an arbitrary depth limit, or just ignore this. ------------------------------------------------------------------------ [2019-09-16 13:27:35] marc dot schoenefeld at gmx dot org The following patch has been added/updated: Patch Name: php_7_3_9_stack_overflow.ser.zip.b64.patch Revision: 1568640455 URL: https://bugs.php.net/patch-display.php?bug=78549&patch=php_7_3_9_stack_overflow.ser.zip.b64.patch&revision=1568640455 ------------------------------------------------------------------------ [2019-09-16 12:52:31] nikic@php.net What are the contents of php_7_3_9_stack_overflow.ser? I can imagine, but if you already have the test case... ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=78549 -- Edit this bug report at https://bugs.php.net/bug.php?id=78549&edit=1

« previous php.bugs (#222954) next »