Edit report at https://bugs.php.net/bug.php?id=80817&edit=1
ID: 80817
Updated by: stas@php.net
Reported by: cmb@php.net
Summary: dba_popen() may cause segfault during RSHUTDOWN
Status: Assigned
-Type: Security
+Type: Bug
Package: DBM/DBA related
Operating System: Windows
PHP Version: 7.4Git-2021-03-01 (Git)
-Assigned To: stas
+Assigned To: cmb
Block user comment: N
Private report: Y
New Comment:
I think we can merge the fix.
Previous Comments:
------------------------------------------------------------------------
[2021-03-15 10:58:49] cmb@php.net
If this is not a security issue, it would be good to merge the
patch today, or early tomorrow, so it can be rolled out with the
RCs.
------------------------------------------------------------------------
[2021-03-02 10:24:56] cmb@php.net
A simple dba_popen() call followed by dba_close() is enough to
*sometimes* cause this misbehavior. The mentioned test fails on
AppVeyor occassionally:
<https://ci.appveyor.com/project/php/php-src/history>.
------------------------------------------------------------------------
[2021-03-02 01:32:24] stas@php.net
I'm not sure how this can be triggered - can you only trigger it with specific code or it could
be triggered by the outside user somehow? From the look of it it seems like it requires very
specific code to trigger, so it seems not to fit the security issue profile, unless there's a
way outside user action can trigger it in proper code too.
------------------------------------------------------------------------
[2021-03-01 17:28:00] cmb@php.net
Suggested fix: <https://gist.github.com/cmb69/82c0511b5cee0ea12b9507e61d5bba4a>.
------------------------------------------------------------------------
[2021-03-01 17:11:45] cmb@php.net
Description:
------------
On Windows, for the flatfile, inifile, cdb and cdb_make handlers,
dba_popen() opens a persistent stream. Afterwards, it tries to
cast that stream to a file descriptor; if that fails, it closes
the stream, but fails to properly distinguish between persistent
and non-persistent streams, so the handle isn't preserved. When
the persistent streams are freed during request shutdown,
accessing the stream can cause a segfault.
Obviously, this is a use-after-free scenario, but I am not sure
whether this should be regarded as a security issue, since DBA
especially with these drivers is likely rarely used in production.
Furthermore, it seems that issue hasn't been reported already,
although it is likely there for a very long time.
Stas, what do you think?
Test script:
---------------
nmake test TESTS=ext\dba\tests\bug65708.phpt
Expected result:
----------------
test succeeds
Actual result:
--------------
test fails with
========DIFF========
005+
006+ Termsig=-1073741819
========DONE========
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80817&edit=1