Bug #79078 [NEW]: Hypothetical use-after-free in curl_multi_add_handle()

From: Date: Wed, 08 Jan 2020 10:48:46 +0000
Subject: Bug #79078 [NEW]: Hypothetical use-after-free in curl_multi_add_handle()
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-224770@lists.php.net to get a copy of this message
From: cmb Operating system: * PHP version: 7.3Git-2020-01-08 (Git) Package: cURL related Bug Type: Bug Bug description:Hypothetical use-after-free in curl_multi_add_handle() Description: ------------ If a curl resource which has CURLOPT_VERBOSE enabled, and CURLOPT_STDERR set to a stream which has been prematurely closed is passed to curl_multi_add_handle(), depending on the libcurl version, there may be an use-after-free. Since this requires debugging features (CURLOPT_VERBOSE) and a rather serious programming error, this is not a security bug. Test script: --------------- php -i | grep cURL php run-tests.php -m ext/curl/tests/bug48203_multi.phpt > /dev/null 2>&1 cat ext/curl/tests/bug48203_multi.mem Expected result: ---------------- cURL support => enabled cURL Information => 7.64.0 cat: ext/curl/bug48203_multi.mem: No such file or directory Actual result: -------------- cURL support => enabled cURL Information => 7.64.0 ==30168== Invalid read of size 4 ==30168== at 0x6C0CF6E: fwrite (iofwrite.c:37) ==30168== by 0x5BC806C: Curl_debug (in /home/cmb/curl/lib/libcurl.so.4.5.0) ==30168== by 0x5BC81E5: Curl_infof (in /home/cmb/curl/lib/libcurl.so.4.5.0) ==30168== by 0x5BE04A1: Curl_expire (in /home/cmb/curl/lib/libcurl.so.4.5.0) ==30168== by 0x5BE07A9: curl_multi_add_handle (in /home/cmb/curl/lib/libcurl.so.4.5.0) ==30168== by 0x2812B5: zif_curl_multi_add_handle (multi.c:100) ==30168== by 0x426867: ZEND_DO_ICALL_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:649) ==30168== by 0x426867: execute_ex (zend_vm_execute.h:55503) ==30168== by 0x42EFBF: zend_execute (zend_vm_execute.h:60939) ==30168== by 0x3A529A: zend_execute_scripts (zend.c:1568) ==30168== by 0x344E1F: php_execute_script (main.c:2639) ==30168== by 0x43130D: do_cli (php_cli.c:997) ==30168== by 0x1E74CC: main (php_cli.c:1389) ==30168== Address 0x7990500 is 0 bytes inside a block of size 552 free'd ==30168== at 0x4C2CDDB: free (vg_replace_malloc.c:530) ==30168== by 0x6C0BC41: fclose@@GLIBC_2.2.5 (iofclose.c:84) ==30168== by 0x362197: php_stdiop_close (plain_wrapper.c:464) ==30168== by 0x35D277: _php_stream_free (streams.c:466) ==30168== by 0x2E74B0: zif_fclose (file.c:920) ==30168== by 0x426867: ZEND_DO_ICALL_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:649) ==30168== by 0x426867: execute_ex (zend_vm_execute.h:55503) ==30168== by 0x42EFBF: zend_execute (zend_vm_execute.h:60939) ==30168== by 0x3A529A: zend_execute_scripts (zend.c:1568) ==30168== by 0x344E1F: php_execute_script (main.c:2639) ==30168== by 0x43130D: do_cli (php_cli.c:997) ==30168== by 0x1E74CC: main (php_cli.c:1389) ==30168== Block was alloc'd at ==30168== at 0x4C2BBAF: malloc (vg_replace_malloc.c:299) ==30168== by 0x6C0BE52: fdopen@@GLIBC_2.2.5 (iofdopen.c:139) ==30168== by 0x362077: php_stdiop_cast (plain_wrapper.c:559) ==30168== by 0x35FB0F: _php_stream_cast (cast.c:220) ==30168== by 0x27C9E0: _php_curl_setopt (interface.c:2562) ==30168== by 0x27E04F: zif_curl_setopt_array (interface.c:3125) ==30168== by 0x42CDEC: ZEND_DO_FCALL_BY_NAME_SPEC_RETVAL_UNUSED_HANDLER (zend_vm_execute.h:819) ==30168== by 0x42CDEC: execute_ex (zend_vm_execute.h:55519) ==30168== by 0x42EFBF: zend_execute (zend_vm_execute.h:60939) ==30168== by 0x3A529A: zend_execute_scripts (zend.c:1568) ==30168== by 0x344E1F: php_execute_script (main.c:2639) ==30168== by 0x43130D: do_cli (php_cli.c:997) ==30168== by 0x1E74CC: main (php_cli.c:1389) <snip> -- Edit bug report at https://bugs.php.net/bug.php?id=79078&edit=1 -- Fix committed: https://bugs.php.net/fix.php?id=79078&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=79078&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=79078&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=79078&r=needscript Try newer version: https://bugs.php.net/fix.php?id=79078&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=79078&r=support Expected behavior: https://bugs.php.net/fix.php?id=79078&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=79078&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=79078&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=79078&r=globals PHP version support discontinued: https://bugs.php.net/fix.php?id=79078&r=phptooold Daylight Savings: https://bugs.php.net/fix.php?id=79078&r=dst IIS Stability: https://bugs.php.net/fix.php?id=79078&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=79078&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=79078&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=79078&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=79078&r=mysqlcfg

« previous php.bugs (#224770) next »