Bug #75006 [Opn->Csd]: Memory Corruption in Extended SplFixedArray

From: Date: Wed, 10 Jun 2020 10:58:11 +0000
Subject: Bug #75006 [Opn->Csd]: Memory Corruption in Extended SplFixedArray
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-227402@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75006&edit=1 ID: 75006 Updated by: nikic@php.net Reported by: taoguangchen at icloud dot com Summary: Memory Corruption in Extended SplFixedArray -Status: Open +Status: Closed Type: Bug Package: SPL related Operating System: * PHP Version: 5.6.31 -Assigned To: +Assigned To: nikic Block user comment: N Private report: N New Comment: Can't reproduce any corruption on current PHP versions. I believe this got fixed when the delayed wakeup was introduced. Previous Comments: ------------------------------------------------------------------------ [2017-07-31 12:45:08] zeev@php.net Unserialize must not be used on untrusted input. We don't consider issues in unserialize as security vulnerabilities - removing Private flag... ------------------------------------------------------------------------ [2017-07-30 14:22:06] taoguangchen at icloud dot com Description: ------------ Memory Corruption in Extended SplFixedArray ``` SPL_METHOD(SplFixedArray, __wakeup) { spl_fixedarray_object *intern = (spl_fixedarray_object *) zend_object_store_get_object(getThis() TSRMLS_CC); HashPosition ptr; HashTable *intern_ht = zend_std_get_properties(getThis() TSRMLS_CC); ... zend_hash_clean(intern_ht); ``` An extended SplFixedArray can contains some properties. In during SplFixedArray deserialization, the deserialized properties will be cleaned. Then destructor call with uninitialized properties that result in memory corruption. PoC: ``` class obj extends SplFixedArray { var $prop; function __destruct() { if ($this->prop) { // doing whatever } } } unserialize('O:3:"obj":1:{s:4:"prop";i:1;}'); /* $wddx = <<<EOT <?xml version='1.0'?> <wddxPacket version='1.0'> <header/> <data> <struct> <var name='php_class_name'> <string>obj</string> </var> <var name='prop'> <number>1</number> </var> </struct> </data> </wddxPacket> EOT; wddx_deserialize($wddx); */ ``` ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=75006&edit=1

« previous php.bugs (#227402) next »