Sec Bug->Bug #80284 [Fbk]: Potential issue in win32/signal.c: Return Value Not Checked from Function Call
| From: | stas@php.net | Date: | Mon, 26 Oct 2020 17:48:03 +0000 |
| Subject: | Sec Bug->Bug #80284 [Fbk]: Potential issue in win32/signal.c: Return Value Not Checked from Function Call | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-229930@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80284&edit=1
ID: 80284
Updated by: stas@php.net
Reported by: sagpant at microsoft dot com
Summary: Potential issue in win32/signal.c: Return Value Not
Checked from Function Call
Status: Feedback
-Type: Security
+Type: Bug
Package: *General Issues
PHP Version: 7.4.11
Block user comment: N
Private report: Y
Previous Comments:
------------------------------------------------------------------------
[2020-10-26 17:47:02] cmb@php.net
call_user_function() calls _call_user_function_ex()[1] which in
turn calls zend_call_function()[2]. The latter defines the return
value (IS_UNDEF) before the function could fail. So if
call_user_function() fails, the following zval_ptr_dtor() would
practically be a NOP. As such I don't see a security issue here.
I also don't see that there is any special code path that should
be exercised if call_user_function() fails here, except maybe for
asserting that retval is indeed IS_UNDEF.
[1] <https://github.com/php/php-src/blob/php-7.4.11/Zend/zend_execute_API.c#L633>
[2] <https://github.com/php/php-src/blob/php-7.4.11/Zend/zend_execute_API.c#L649>
------------------------------------------------------------------------
[2020-10-26 17:39:32] stas@php.net
Could you please explain what is the security issue here? Code readability is not a security issue
per se.
------------------------------------------------------------------------
[2020-10-26 15:06:46] sagpant at microsoft dot com
Description:
------------
In this codebase, you often check the return value of the implicated function when calling it, but
in this instance, it appears that you didnât. Using a consistent return value checking and/or
error handling approach can improve code robustness and readability.
File: PHP-7.4.11/win32/signal.c
Line Number: 39
Function: call_user_function
Correct reference usage found in main/streams/userspace.c line: 940
Test script:
---------------
Analyzer points out inconsistencies in the code.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80284&edit=1