Bug #78549 [Ver->Csd]: Stack overflow due to nested serialized input
| From: | nikic@php.net | Date: | Mon, 30 Sep 2019 08:32:59 +0000 |
| Subject: | Bug #78549 [Ver->Csd]: Stack overflow due to nested serialized input | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-222954@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78549&edit=1
ID: 78549
Updated by: nikic@php.net
Reported by: marc dot schoenefeld at gmx dot org
Summary: Stack overflow due to nested serialized input
-Status: Verified
+Status: Closed
Type: Bug
Package: Reproducible crash
Operating System: CentOS 7 / Generic
PHP Version: 7.3.9
-Assigned To:
+Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
Fixed by https://github.com/php/php-src/commit/1806ce9cb019ee74ddb540cbc07daf121dcb5537.
Previous Comments:
------------------------------------------------------------------------
[2019-09-24 10:18:50] nikic@php.net
The following pull request has been associated:
Patch Name: Add max_depth option to unserialize()
On GitHub: https://github.com/php/php-src/pull/4742
Patch: https://github.com/php/php-src/pull/4742.patch
------------------------------------------------------------------------
[2019-09-23 11:38:19] nikic@php.net
Fuzzing seems to hit this quite often, so we should probably do something about it.
Script to find the limit:
<?php
$str = 'i:0;';
for ($i = 0; $i < 10000; $i++) {
$str = 'a:1:{i:0;' . $str . '}';
if ($i % 10 == 0) {
echo "$i\n";
unserialize($str);
}
}
var_dump($str);
I get 5620 on a debug build and 7690 on a release/assert build.
Trying the same with O:8:"stdClass":1 I get 4630 and 7690.
We can add an unserialize option for the max_depth and default it to something like 4000.
------------------------------------------------------------------------
[2019-09-16 13:51:59] nikic@php.net
https://gist.githubusercontent.com/nikic/200240ca7830c6e5d587b3b4aad927eb/raw/d8b02e0bb1deca31025dbaf50a46ab4ab792bf68/php_7_3_9_stack_overflow.ser
I doubt we're going to rewriting the unserializer in a non-recursive fashion, so we can either
introduce an arbitrary depth limit, or just ignore this.
------------------------------------------------------------------------
[2019-09-16 13:27:35] marc dot schoenefeld at gmx dot org
The following patch has been added/updated:
Patch Name: php_7_3_9_stack_overflow.ser.zip.b64.patch
Revision: 1568640455
URL: https://bugs.php.net/patch-display.php?bug=78549&patch=php_7_3_9_stack_overflow.ser.zip.b64.patch&revision=1568640455
------------------------------------------------------------------------
[2019-09-16 12:52:31] nikic@php.net
What are the contents of php_7_3_9_stack_overflow.ser? I can imagine, but if you already have the
test case...
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=78549
--
Edit this bug report at https://bugs.php.net/bug.php?id=78549&edit=1