Bug #77283 [Opn->Csd]: memory exhausted when unserialize data

From: Date: Mon, 11 May 2020 10:52:37 +0000
Subject: Bug #77283 [Opn->Csd]: memory exhausted when unserialize data
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-226991@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77283&edit=1

 ID:                 77283
 Updated by:         nikic@php.net
 Reported by:        jasonxiale at mail dot ru
 Summary:            memory exhausted when unserialize data
-Status:             Open
+Status:             Closed
 Type:               Bug
 Package:            Class/Object related
 Operating System:   Linux(4.15.0-42-generic)
 PHP Version:        master-Git-2018-12-11 (Git)
-Assigned To:        
+Assigned To:        nikic
 Block user comment: N
 Private report:     N

 New Comment:

This has been addressed in the meantime, unserialize() no longer allows allocations larger than the
payload size.


Previous Comments:
------------------------------------------------------------------------
[2018-12-11 16:16:43] jasonxiale at mail dot ru

Description:
------------
when fuzzing php unserialize function using command as:
./sapi/cli/php  -r 'unserialize(file_get_contents("php://stdin"));' <
basic_fuzz/fuzzer11/crashes/id\:000000\,sig\:06\,src\:000158+000528\,op\:splice\,rep\:2

I got an error:
Fatal error: Allowed memory size of 134217728 bytes exhausted (tried to allocate 42949672960 bytes)
in Command line code on line 1


Test script:
---------------
the base64-ed input is like
base64 basic_fuzz/fuzzer11/crashes/id\:000000\,sig\:06\,src\:000158+000528\,op\:splice\,rep\:2 
YTozOntpOjA7YToyOntpOjA7TzoxOiIxIjowNzc3Nzc3Nzc3Ojc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3
Nzc3Nzc3Nzc3Nzc7ASkxOip//yI3Nzc3NzQiO31pOkk7YToyOntpOjA7aVwxO2k3N6UXMSNpAAAA
AX0=



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=77283&edit=1


Thread (2 messages)

« previous php.bugs (#226991) next »