Bug #76067 [Com]: system() function call leaks php-fpm listening sockets
| From: | enyby at yandex dot ru | Date: | Wed, 29 Apr 2020 21:14:07 +0000 |
| Subject: | Bug #76067 [Com]: system() function call leaks php-fpm listening sockets | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-226837@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76067&edit=1
ID: 76067
Comment by: enyby at yandex dot ru
Reported by: jaco at uls dot co dot za
Summary: system() function call leaks php-fpm listening
sockets
Status: Assigned
Type: Bug
Package: FPM related
Operating System: Linux
PHP Version: 5.6.34
Assigned To: bukka
Block user comment: N
Private report: N
New Comment:
Same issue but with PHP 7.3.9.
As mentioned in #67383 this bug prevent restart php-fpm.
Previous Comments:
------------------------------------------------------------------------
[2018-10-14 15:54:21] bukka@php.net
Seems fine now and it's publicly visible.
------------------------------------------------------------------------
[2018-10-14 15:44:34] bukka@php.net
Seems like it's still set as private but I can't change it. Think it should be set as a
public. Can someone with the right permission do that?
------------------------------------------------------------------------
[2018-10-14 15:34:15] bukka@php.net
As discussed, I'm setting this as a not security issue for the reasons stated above. In
addition I have been looking through the similar bugs and the issue is already exposed in the FPM
related comment added on 2013-12-03 at 17:23 UTC to the bug about similar issue in Apache mod_php:
https://bugs.php.net/bug.php?id=38915 .
------------------------------------------------------------------------
[2018-03-22 20:55:41] bukka@php.net
I would be a bit careful about adding cloexec on stdin. At least I need to experiment with that
first to see what possible consequences are. The thing is that the fact that stdin is used causing
other issues as well (see https://bugs.php.net/bug.php?id=73342 ) so it might
be better to change that but it needs a bit more thinking and mainly testing first.
I agree that this is not really a security issue. If you can't trust a program that you run
using system function, then you have got bunch of other problems as well IMHO.
------------------------------------------------------------------------
[2018-03-18 21:37:27] stas@php.net
Looking at FPM code in fpm_stdio_init_child(), it looks like FD 0 (stdin) is always the listening
socket. This means there's no useful way for the forked process to make any legit use of it,
probably. Which means, it would probably be OK to not pass it? I am not sure though what CLOEXEC
there would result in.
@bukka, any opinion on adding CLOEXEC to listening socket somewhere in fpm_stdio_init_child() or
fpm_unix_init_child()?
That all said, since the child and the FPM process run within the same permissions framework, I am
not sure there can be a real security barrier between them. If you have full remote access to the
server, including system(), there's little you can't do (within the permissions of this
user).
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=76067
--
Edit this bug report at https://bugs.php.net/bug.php?id=76067&edit=1