Sec Bug->Bug #80284 [Fbk]: Potential issue in win32/signal.c: Return Value Not Checked from Function Call

From: Date: Mon, 26 Oct 2020 17:48:03 +0000
Subject: Sec Bug->Bug #80284 [Fbk]: Potential issue in win32/signal.c: Return Value Not Checked from Function Call
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-229930@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80284&edit=1 ID: 80284 Updated by: stas@php.net Reported by: sagpant at microsoft dot com Summary: Potential issue in win32/signal.c: Return Value Not Checked from Function Call Status: Feedback -Type: Security +Type: Bug Package: *General Issues PHP Version: 7.4.11 Block user comment: N Private report: Y Previous Comments: ------------------------------------------------------------------------ [2020-10-26 17:47:02] cmb@php.net call_user_function() calls _call_user_function_ex()[1] which in turn calls zend_call_function()[2]. The latter defines the return value (IS_UNDEF) before the function could fail. So if call_user_function() fails, the following zval_ptr_dtor() would practically be a NOP. As such I don't see a security issue here. I also don't see that there is any special code path that should be exercised if call_user_function() fails here, except maybe for asserting that retval is indeed IS_UNDEF. [1] <https://github.com/php/php-src/blob/php-7.4.11/Zend/zend_execute_API.c#L633> [2] <https://github.com/php/php-src/blob/php-7.4.11/Zend/zend_execute_API.c#L649> ------------------------------------------------------------------------ [2020-10-26 17:39:32] stas@php.net Could you please explain what is the security issue here? Code readability is not a security issue per se. ------------------------------------------------------------------------ [2020-10-26 15:06:46] sagpant at microsoft dot com Description: ------------ In this codebase, you often check the return value of the implicated function when calling it, but in this instance, it appears that you didn’t. Using a consistent return value checking and/or error handling approach can improve code robustness and readability. File: PHP-7.4.11/win32/signal.c Line Number: 39 Function: call_user_function Correct reference usage found in main/streams/userspace.c line: 940 Test script: --------------- Analyzer points out inconsistencies in the code. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=80284&edit=1

« previous php.bugs (#229930) next »