Bug #80965 [NEW]: A use after free bug in ext/spl/spl_dllist.c
| From: | lylgood at foxmail dot com | Date: | Sun, 18 Apr 2021 07:03:14 +0000 |
| Subject: | Bug #80965 [NEW]: A use after free bug in ext/spl/spl_dllist.c | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-233489@lists.php.net to get a copy of this message | ||
From: lylgood at foxmail dot com
Operating system: All
PHP version: master-Git-2021-04-18 (Git)
Package: *Extensibility Functions
Bug Type: Bug
Bug description:A use after free bug in ext/spl/spl_dllist.c
Description:
------------
File: ext/spl/spl_dllist.c
Bug Function: PHP_METHOD(SplDoublyLinkedList, offsetUnset)
In this function, element is obtained via spl_ptr_llist_offset() at line
834.
At line 863, the ref of element is decreased by one via
SPL_LLIST_DELREF(element), if the refcount of element is 0 now, the
element will be freed.
But the freed element is still used at line 869 by
SPL_LLIST_DELREF(element) which is a macro of "if (!--
((element)->data).u2.extra) { _efree((element)); }". It is a use after
free.
If the freed memory of element is allocated by other objects before line
869,
then it is possible to fake structures to modify the refcount of element
and cause an additional double free.
Test script:
---------------
834: element = spl_ptr_llist_offset(intern->llist, index, intern->flags
& SPL_DLLIST_IT_LIFO);
...
if (intern->traverse_pointer == element) {
863: SPL_LLIST_DELREF(element); // element First freed here!
intern->traverse_pointer = NULL;
}
zval_ptr_dtor(&element->data);
ZVAL_UNDEF(&element->data);
869: SPL_LLIST_DELREF(element) // Freed element is used and could be
freed again!
--
Edit bug report at https://bugs.php.net/bug.php?id=80965&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=80965&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=80965&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=80965&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=80965&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=80965&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=80965&r=support
Expected behavior: https://bugs.php.net/fix.php?id=80965&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=80965&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=80965&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=80965&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=80965&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=80965&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=80965&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=80965&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=80965&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=80965&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=80965&r=mysqlcfg