Bug #79820 [Com]: double-free causing heap corruption
| From: | christopher dot broadbent at zencontrol dot com | Date: | Tue, 14 Jul 2020 23:27:12 +0000 |
| Subject: | Bug #79820 [Com]: double-free causing heap corruption | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-228046@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79820&edit=1
ID: 79820
Comment by: christopher dot broadbent at zencontrol dot com
Reported by: christopher dot broadbent at zencontrol dot com
Summary: double-free causing heap corruption
Status: Open
Type: Bug
Package: Reproducible crash
Operating System: linux debian buster
PHP Version: 7.4.7
Block user comment: N
Private report: N
New Comment:
Sorry, I meant to say bump the ref counters on
reference->prop.type
Previous Comments:
------------------------------------------------------------------------
[2020-07-14 23:22:18] christopher dot broadbent at zencontrol dot com
This is probably my inexperience with the code-base, but shouldn't the implementation for
ZEND_METHOD(reflection_property, __construct)
by increment the ref-count for the value copied by
reference->prop = *property_info;
when dynam_prop is false? It seems to be the thing keeping a reference around to the deallocated
string, causing the use-after-free, and I can't see anywhere in the code path where it bumps
the reference count.
------------------------------------------------------------------------
[2020-07-14 07:48:04] ondrej@php.net
> On which version/commit of PHP were the gdb backtraces gathered? I can't find > any
> version of PHP 7.4 that has a zend_string_release call in php_reflection.c:225. The valgrind trace
> looks more plausible.
If you look carefully, the backtrace matches the function with it's location and
zend_string_release is always inlined, so the php_reflection.c:225 is just a red herring as it just
got inlined (and the line number marks the location of the affected block where it is used).
The packages don't patch php_reflection.c at all.
------------------------------------------------------------------------
[2020-07-14 01:06:26] christopher dot broadbent at zencontrol dot com
Built php 7.4.8 with
software@debian-software:~/Documents/php-7.4.8$ ./configure --prefix=/home/software/php
--with-openssl --with-zlib --with-curl --enable-intl --enable-mbstring --with-pdo-mysql
--with-sodium --with-pear --enable-debug CFLAGS="-fsanitize=address"
CXXFLAGS="-fsanitize=address"
running then gives me the output
software@debian-software:~/Documents/zencontrol/gateway$ USE_ZEND_ALLOC=0 ~/php/bin/php
vendor/phpunit/phpunit/phpunit --group default --configuration phpunit.xml --filter
"/(Gateway\\\\Chris\\\\Heres\\\\Your\\\\Test\\\\Reproduction\\\\Of\\\\Segfault\\\\SeggyTest::testTesties)(
.*)?$/" --test-suffix SeggyTest.php tests/Chris/Heres/Your/Test/Reproduction/Of/Segfault
PHPUnit 8.4.1 by Sebastian Bergmann and contributors.
Runtime: PHP 7.4.8
Configuration: /home/software/Documents/zencontrol/gateway/phpunit.xml
=================================================================
==30325==ERROR: AddressSanitizer: heap-use-after-free on address 0x607000165804 at pc 0x5653a1555e1e
bp 0x7ffc99079730 sp 0x7ffc99079728
READ of size 4 at 0x607000165804 thread T0
#0 0x5653a1555e1d in zend_string_addref
/home/software/Documents/php-7.4.8/Zend/zend_string.h:117
#1 0x5653a156046d in reflection_type_factory
/home/software/Documents/php-7.4.8/ext/reflection/php_reflection.c:1165
#2 0x5653a158ae55 in zim_reflection_property_getType
/home/software/Documents/php-7.4.8/ext/reflection/php_reflection.c:5623
#3 0x5653a1c65114 in ZEND_DO_FCALL_SPEC_RETVAL_USED_HANDLER
/home/software/Documents/php-7.4.8/Zend/zend_vm_execute.h:1730
#4 0x5653a1d91a7b in execute_ex /home/software/Documents/php-7.4.8/Zend/zend_vm_execute.h:53828
#5 0x5653a1d9dc18 in zend_execute
/home/software/Documents/php-7.4.8/Zend/zend_vm_execute.h:57920
#6 0x5653a1b491ef in zend_execute_scripts /home/software/Documents/php-7.4.8/Zend/zend.c:1678
#7 0x5653a19e78a8 in php_execute_script /home/software/Documents/php-7.4.8/main/main.c:2621
#8 0x5653a1da426b in do_cli /home/software/Documents/php-7.4.8/sapi/cli/php_cli.c:964
#9 0x5653a1da6515 in main /home/software/Documents/php-7.4.8/sapi/cli/php_cli.c:1359
#10 0x7f017115a09a in __libc_start_main ../csu/libc-start.c:308
#11 0x5653a0f224c9 in _start (/home/software/php/bin/php+0x6064c9)
0x607000165804 is located 4 bytes inside of 80-byte region [0x607000165800,0x607000165850)
freed by thread T0 here:
#0 0x7f01740defb0 in __interceptor_free (/lib/x86_64-linux-gnu/libasan.so.5+0xe8fb0)
#1 0x5653a1ab64d6 in _efree_custom /home/software/Documents/php-7.4.8/Zend/zend_alloc.c:2426
#2 0x5653a1ab66f2 in _efree /home/software/Documents/php-7.4.8/Zend/zend_alloc.c:2546
#3 0x5653a1c36d5d in zend_string_release
/home/software/Documents/php-7.4.8/Zend/zend_string.h:277
#4 0x5653a1c3f7f9 in zend_resolve_class_type
/home/software/Documents/php-7.4.8/Zend/zend_execute.c:947
#5 0x5653a1c3f9e1 in i_zend_check_property_type
/home/software/Documents/php-7.4.8/Zend/zend_execute.c:961
#6 0x5653a1c3fcc1 in i_zend_verify_property_type
/home/software/Documents/php-7.4.8/Zend/zend_execute.c:984
#7 0x5653a1c3fd12 in zend_verify_property_type
/home/software/Documents/php-7.4.8/Zend/zend_execute.c:993
#8 0x5653a1c13073 in zend_std_write_property
/home/software/Documents/php-7.4.8/Zend/zend_object_handlers.c:897
#9 0x5653a1b7269b in zend_update_property_ex
/home/software/Documents/php-7.4.8/Zend/zend_API.c:4115
#10 0x5653a15898c5 in zim_reflection_property_setValue
/home/software/Documents/php-7.4.8/ext/reflection/php_reflection.c:5485
#11 0x5653a1c6433e in ZEND_DO_FCALL_SPEC_RETVAL_UNUSED_HANDLER
/home/software/Documents/php-7.4.8/Zend/zend_vm_execute.h:1618
#12 0x5653a1d91a4b in execute_ex /home/software/Documents/php-7.4.8/Zend/zend_vm_execute.h:53824
#13 0x5653a1d9dc18 in zend_execute
/home/software/Documents/php-7.4.8/Zend/zend_vm_execute.h:57920
#14 0x5653a1b491ef in zend_execute_scripts /home/software/Documents/php-7.4.8/Zend/zend.c:1678
#15 0x5653a19e78a8 in php_execute_script /home/software/Documents/php-7.4.8/main/main.c:2621
#16 0x5653a1da426b in do_cli /home/software/Documents/php-7.4.8/sapi/cli/php_cli.c:964
#17 0x5653a1da6515 in main /home/software/Documents/php-7.4.8/sapi/cli/php_cli.c:1359
#18 0x7f017115a09a in __libc_start_main ../csu/libc-start.c:308
previously allocated by thread T0 here:
#0 0x7f01740df330 in __interceptor_malloc (/lib/x86_64-linux-gnu/libasan.so.5+0xe9330)
#1 0x5653a1ab85ff in __zend_malloc /home/software/Documents/php-7.4.8/Zend/zend_alloc.c:2976
#2 0x5653a1ab63f6 in _malloc_custom /home/software/Documents/php-7.4.8/Zend/zend_alloc.c:2417
#3 0x5653a1ab6647 in _emalloc /home/software/Documents/php-7.4.8/Zend/zend_alloc.c:2536
#4 0x5653a1ab8c29 in zend_string_alloc Zend/zend_string.h:133
#5 0x5653a1abf605 in zend_concat3 /home/software/Documents/php-7.4.8/Zend/zend_compile.c:791
#6 0x5653a1abf70d in zend_concat_names
/home/software/Documents/php-7.4.8/Zend/zend_compile.c:802
#7 0x5653a1abf7bc in zend_prefix_with_ns
/home/software/Documents/php-7.4.8/Zend/zend_compile.c:808
#8 0x5653a1ac0136 in zend_resolve_class_name
/home/software/Documents/php-7.4.8/Zend/zend_compile.c:944
#9 0x5653a1ac01fc in zend_resolve_class_name_ast
/home/software/Documents/php-7.4.8/Zend/zend_compile.c:954
#10 0x5653a1ae09ee in zend_compile_typename
/home/software/Documents/php-7.4.8/Zend/zend_compile.c:5318
#11 0x5653a1ae68f1 in zend_compile_prop_decl
/home/software/Documents/php-7.4.8/Zend/zend_compile.c:6100
#12 0x5653a1ae6f25 in zend_compile_prop_group
/home/software/Documents/php-7.4.8/Zend/zend_compile.c:6178
#13 0x5653a1afa741 in zend_compile_stmt
/home/software/Documents/php-7.4.8/Zend/zend_compile.c:8538
#14 0x5653a1ae03c2 in zend_compile_stmt_list
/home/software/Documents/php-7.4.8/Zend/zend_compile.c:5262
#15 0x5653a1afa5bb in zend_compile_stmt
/home/software/Documents/php-7.4.8/Zend/zend_compile.c:8479
#16 0x5653a1ae91a1 in zend_compile_class_decl
/home/software/Documents/php-7.4.8/Zend/zend_compile.c:6467
#17 0x5653a1afa21a in zend_compile_top_stmt
/home/software/Documents/php-7.4.8/Zend/zend_compile.c:8454
#18 0x5653a1afa040 in zend_compile_top_stmt
/home/software/Documents/php-7.4.8/Zend/zend_compile.c:8443
#19 0x5653a1a7023a in zend_compile Zend/zend_language_scanner.l:614
#20 0x5653a1a706f4 in compile_file Zend/zend_language_scanner.l:650
#21 0x5653a150fff0 in phar_compile_file /home/software/Documents/php-7.4.8/ext/phar/phar.c:3299
#22 0x5653a1a709e4 in compile_filename Zend/zend_language_scanner.l:671
#23 0x5653a1c57fb1 in zend_include_or_eval
/home/software/Documents/php-7.4.8/Zend/zend_execute.c:4240
#24 0x5653a1d45006 in ZEND_INCLUDE_OR_EVAL_SPEC_CV_HANDLER
/home/software/Documents/php-7.4.8/Zend/zend_vm_execute.h:37728
#25 0x5653a1d9af48 in execute_ex /home/software/Documents/php-7.4.8/Zend/zend_vm_execute.h:56968
#26 0x5653a1b0a7f0 in zend_call_function
/home/software/Documents/php-7.4.8/Zend/zend_execute_API.c:813
#27 0x5653a15e8487 in zif_spl_autoload_call
/home/software/Documents/php-7.4.8/ext/spl/php_spl.c:452
#28 0x5653a1b0aa65 in zend_call_function
/home/software/Documents/php-7.4.8/Zend/zend_execute_API.c:826
#29 0x5653a1b0c0e1 in zend_lookup_class_ex
/home/software/Documents/php-7.4.8/Zend/zend_execute_API.c:995
SUMMARY: AddressSanitizer: heap-use-after-free
/home/software/Documents/php-7.4.8/Zend/zend_string.h:117 in zend_string_addref
Shadow bytes around the buggy address:
0x0c0e80024ab0: fd fd fd fd fd fa fa fa fa fa 00 00 00 00 00 00
0x0c0e80024ac0: 00 00 00 fa fa fa fa fa fd fd fd fd fd fd fd fd
0x0c0e80024ad0: fd fd fa fa fa fa fd fd fd fd fd fd fd fd fd fd
0x0c0e80024ae0: fa fa fa fa fd fd fd fd fd fd fd fd fd fa fa fa
0x0c0e80024af0: fa fa fd fd fd fd fd fd fd fd fd fa fa fa fa fa
=>0x0c0e80024b00:[fd]fd fd fd fd fd fd fd fd fd fa fa fa fa 00 00
0x0c0e80024b10: 00 00 00 00 00 00 00 fa fa fa fa fa fd fd fd fd
0x0c0e80024b20: fd fd fd fd fd fa fa fa fa fa 00 00 00 00 00 00
0x0c0e80024b30: 00 00 00 fa fa fa fa fa 00 00 00 00 00 00 00 00
0x0c0e80024b40: 00 00 fa fa fa fa 00 00 00 00 00 00 00 00 00 fa
0x0c0e80024b50: fa fa fa fa 00 00 00 00 00 00 00 00 00 00 fa fa
Shadow byte legend (one shadow byte represents 8 application bytes):
Addressable: 00
Partially addressable: 01 02 03 04 05 06 07
Heap left redzone: fa
Freed heap region: fd
Stack left redzone: f1
Stack mid redzone: f2
Stack right redzone: f3
Stack after return: f5
Stack use after scope: f8
Global redzone: f9
Global init order: f6
Poisoned by user: f7
Container overflow: fc
Array cookie: ac
Intra object redzone: bb
ASan internal: fe
Left alloca redzone: ca
Right alloca redzone: cb
==30325==ABORTING
I might be able to upload the reproduction case we have, but it looks like it's a fairly large
amount of code, and I'm not familiar with any of it.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=79820
--
Edit this bug report at https://bugs.php.net/bug.php?id=79820&edit=1