Sec Bug->Bug #80817 [Asn]: dba_popen() may cause segfault during RSHUTDOWN

From: Date: Mon, 15 Mar 2021 17:17:43 +0000
Subject: Sec Bug->Bug #80817 [Asn]: dba_popen() may cause segfault during RSHUTDOWN
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-232746@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80817&edit=1

 ID:                 80817
 Updated by:         stas@php.net
 Reported by:        cmb@php.net
 Summary:            dba_popen() may cause segfault during RSHUTDOWN
 Status:             Assigned
-Type:               Security
+Type:               Bug
 Package:            DBM/DBA related
 Operating System:   Windows
 PHP Version:        7.4Git-2021-03-01 (Git)
-Assigned To:        stas
+Assigned To:        cmb
 Block user comment: N
 Private report:     Y

 New Comment:

I think we can merge the fix.


Previous Comments:
------------------------------------------------------------------------
[2021-03-15 10:58:49] cmb@php.net

If this is not a security issue, it would be good to merge the
patch today, or early tomorrow, so it can be rolled out with the
RCs.

------------------------------------------------------------------------
[2021-03-02 10:24:56] cmb@php.net

A simple dba_popen() call followed by dba_close() is enough to
*sometimes* cause this misbehavior.  The mentioned test fails on
AppVeyor occassionally:
<https://ci.appveyor.com/project/php/php-src/history>.

------------------------------------------------------------------------
[2021-03-02 01:32:24] stas@php.net

I'm not sure how this can be triggered - can you only trigger it with specific code or it could
be triggered by the outside user somehow? From the look of it it seems like it requires very
specific code to trigger, so it seems not to fit the security issue profile, unless there's a
way outside user action can trigger it in proper code too.

------------------------------------------------------------------------
[2021-03-01 17:28:00] cmb@php.net

Suggested fix: <https://gist.github.com/cmb69/82c0511b5cee0ea12b9507e61d5bba4a>.

------------------------------------------------------------------------
[2021-03-01 17:11:45] cmb@php.net

Description:
------------
On Windows, for the flatfile, inifile, cdb and cdb_make handlers,
dba_popen() opens a persistent stream.  Afterwards, it tries to
cast that stream to a file descriptor; if that fails, it closes
the stream, but fails to properly distinguish between persistent
and non-persistent streams, so the handle isn't preserved.  When
the persistent streams are freed during request shutdown,
accessing the stream can cause a segfault.

Obviously, this is a use-after-free scenario, but I am not sure
whether this should be regarded as a security issue, since DBA
especially with these drivers is likely rarely used in production.
Furthermore, it seems that issue hasn't been reported already,
although it is likely there for a very long time.

Stas, what do you think?


Test script:
---------------
nmake test TESTS=ext\dba\tests\bug65708.phpt

Expected result:
----------------
test succeeds

Actual result:
--------------
test fails with

========DIFF========
005+ 
006+ Termsig=-1073741819
========DONE========



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=80817&edit=1


Thread (1 message)

  • stas@php.net
  • Unknown Message
    • stas@php.net
« previous php.bugs (#232746) next »