Bug #75006 [Opn->Csd]: Memory Corruption in Extended SplFixedArray
| From: | nikic@php.net | Date: | Wed, 10 Jun 2020 10:58:11 +0000 |
| Subject: | Bug #75006 [Opn->Csd]: Memory Corruption in Extended SplFixedArray | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-227402@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75006&edit=1
ID: 75006
Updated by: nikic@php.net
Reported by: taoguangchen at icloud dot com
Summary: Memory Corruption in Extended SplFixedArray
-Status: Open
+Status: Closed
Type: Bug
Package: SPL related
Operating System: *
PHP Version: 5.6.31
-Assigned To:
+Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
Can't reproduce any corruption on current PHP versions. I believe this got fixed when the
delayed wakeup was introduced.
Previous Comments:
------------------------------------------------------------------------
[2017-07-31 12:45:08] zeev@php.net
Unserialize must not be used on untrusted input.
We don't consider issues in unserialize as security vulnerabilities - removing Private flag...
------------------------------------------------------------------------
[2017-07-30 14:22:06] taoguangchen at icloud dot com
Description:
------------
Memory Corruption in Extended SplFixedArray
```
SPL_METHOD(SplFixedArray, __wakeup)
{
spl_fixedarray_object *intern = (spl_fixedarray_object *) zend_object_store_get_object(getThis()
TSRMLS_CC);
HashPosition ptr;
HashTable *intern_ht = zend_std_get_properties(getThis() TSRMLS_CC);
...
zend_hash_clean(intern_ht);
```
An extended SplFixedArray can contains some properties. In during SplFixedArray deserialization, the
deserialized properties will be cleaned. Then destructor call with uninitialized properties that
result in memory corruption.
PoC:
```
class obj extends SplFixedArray {
var $prop;
function __destruct() {
if ($this->prop) {
// doing whatever
}
}
}
unserialize('O:3:"obj":1:{s:4:"prop";i:1;}');
/*
$wddx = <<<EOT
<?xml version='1.0'?>
<wddxPacket version='1.0'>
<header/>
<data>
<struct>
<var name='php_class_name'>
<string>obj</string>
</var>
<var name='prop'>
<number>1</number>
</var>
</struct>
</data>
</wddxPacket>
EOT;
wddx_deserialize($wddx);
*/
```
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75006&edit=1