Bug #80927 [Opn->Ver]: Removing documentElement after creating attribute node: possible use-after-free
Edit report at https://bugs.php.net/bug.php?id=80927&edit=1
ID: 80927
Updated by: cmb@php.net
Reported by: jking at jkingweb dot ca
Summary: Removing documentElement after creating attribute
node: possible use-after-free
-Status: Open
+Status: Verified
Type: Bug
Package: DOM XML related
Operating System: any
-PHP Version: 8.0.3
+PHP Version: 7.4
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
I can confirm this for PHP-7.4 as well.
It looks related to bug #66783 (which has recently been fixed);
only in this case it is about removing instead of inserting
DOMDocuments.
The standard says[1]:
| If childâs parent is not parent, then throw a "NotFoundError"
| DOMException.
[1] <https://dom.spec.whatwg.org/#concept-node-pre-remove>
Previous Comments:
------------------------------------------------------------------------
[2021-04-02 13:39:10] jking at jkingweb dot ca
Description:
------------
See test script. While it is somewhat contrived, it is a situation I ran into setting up unit tests.
When removing the document element out from under an attribute node, the namespaceURI and prefix
properties of the DOMAttr will contain garbage bytes instead of the specified values. As the prefix
property is writeable it may be possible to corrupt memory this way, though I have not confirmed
this.
Test script:
---------------
$d = new \DOMDocument();
$d->appendChild($d->createElement("html"));
$a = $d->createAttributeNS("fake_ns", "test:test");
$d->removeChild($d->documentElement);
echo $a->namespaceURI;
echo $a->prefix;
Expected result:
----------------
Obviously I would expect the namespaceURI and prefix properties not to be corrupted. Given the
apparent underlying limitations of libxml I might expect an exception to be thrown when trying to
remove the document element.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80927&edit=1
Thread (5 messages)