Sec Bug->Bug #79172 [Opn]: STRUCT_OFFSET() relies on undefined behavior
| From: | nikic@php.net | Date: | Mon, 27 Jan 2020 16:01:59 +0000 |
| Subject: | Sec Bug->Bug #79172 [Opn]: STRUCT_OFFSET() relies on undefined behavior | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-225155@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79172&edit=1
ID: 79172
Updated by: nikic@php.net
Reported by: cmb@php.net
Summary: STRUCT_OFFSET() relies on undefined behavior
Status: Open
-Type: Security
+Type: Bug
Package: MySQLi related
Operating System: *
PHP Version: 7.2.27
Block user comment: N
Private report: Y
New Comment:
Not a security issue, this is a pattern understood by compilers. Of course it should use XtOffsetOf
at least on 7.4.
Previous Comments:
------------------------------------------------------------------------
[2020-01-27 14:39:26] cmb@php.net
Suggested patch:
ext/mysqlnd/mysqlnd_portability.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/ext/mysqlnd/mysqlnd_portability.h b/ext/mysqlnd/mysqlnd_portability.h
index 873f49b0cd..2064906193 100644
--- a/ext/mysqlnd/mysqlnd_portability.h
+++ b/ext/mysqlnd/mysqlnd_portability.h
@@ -15,7 +15,7 @@ This file is public domain and comes with NO WARRANTY of any kind */
/* Comes from global.h as OFFSET, renamed to STRUCT_OFFSET */
-#define STRUCT_OFFSET(t, f) ((size_t)(char *)&((t *)0)->f)
+#define STRUCT_OFFSET(t, f) XtOffsetOf(t, f)
#ifndef __attribute
#if !defined(__GNUC__)
------------------------------------------------------------------------
[2020-01-27 14:39:03] cmb@php.net
Description:
------------
The STRUCT_OFFSET() macro[1] evaluates to an expression which
relies on undefined behavior (null pointer dereferencing). I'm
not sure if that qualifies as security issue, but it is certainly
a bug.
<https://github.com/php/php-src/blob/php-7.2.27/ext/mysqlnd/mysqlnd_portability.h#L18>
Test script:
---------------
mysqli_connect($host, $user, $password, $database);
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79172&edit=1