Bug #76067 [Com]: system() function call leaks php-fpm listening sockets

From: Date: Wed, 29 Apr 2020 22:00:50 +0000
Subject: Bug #76067 [Com]: system() function call leaks php-fpm listening sockets
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-226838@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76067&edit=1 ID: 76067 Comment by: enyby at yandex dot ru Reported by: jaco at uls dot co dot za Summary: system() function call leaks php-fpm listening sockets Status: Assigned Type: Bug Package: FPM related Operating System: Linux PHP Version: 5.6.34 Assigned To: bukka Block user comment: N Private report: N New Comment: Workaround for run $command in exec: exec $command 3>&- 4>&- 5>&- 6>&- 7>&- 8>&- 9>&- 10>&- 11>&- 12>&- 13>&- 14>&- 15>&- 16>&- 17>&- 18>&- 19>&- 20>&- 21>&- 22>&- 23>&- 24>&- 25>&- 26>&- 27>&- 28>&- 29>&- 30>&- In code it is look like: $command = 'exec '.$command.' '.implode('>&- ', range(3, 30)).'>&-'; Now original command will use only fds 0, 1 and 2. With defined explicit on exec. Require bash which understand syntax 'fd>&-' for close fd. Previous Comments: ------------------------------------------------------------------------ [2020-04-29 21:14:07] enyby at yandex dot ru Same issue but with PHP 7.3.9. As mentioned in #67383 this bug prevent restart php-fpm. ------------------------------------------------------------------------ [2018-10-14 15:54:21] bukka@php.net Seems fine now and it's publicly visible. ------------------------------------------------------------------------ [2018-10-14 15:44:34] bukka@php.net Seems like it's still set as private but I can't change it. Think it should be set as a public. Can someone with the right permission do that? ------------------------------------------------------------------------ [2018-10-14 15:34:15] bukka@php.net As discussed, I'm setting this as a not security issue for the reasons stated above. In addition I have been looking through the similar bugs and the issue is already exposed in the FPM related comment added on 2013-12-03 at 17:23 UTC to the bug about similar issue in Apache mod_php: https://bugs.php.net/bug.php?id=38915 . ------------------------------------------------------------------------ [2018-03-22 20:55:41] bukka@php.net I would be a bit careful about adding cloexec on stdin. At least I need to experiment with that first to see what possible consequences are. The thing is that the fact that stdin is used causing other issues as well (see https://bugs.php.net/bug.php?id=73342 ) so it might be better to change that but it needs a bit more thinking and mainly testing first. I agree that this is not really a security issue. If you can't trust a program that you run using system function, then you have got bunch of other problems as well IMHO. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=76067 -- Edit this bug report at https://bugs.php.net/bug.php?id=76067&edit=1

« previous php.bugs (#226838) next »