Bug #80965 [NEW]: A use after free bug in ext/spl/spl_dllist.c

From: Date: Sun, 18 Apr 2021 07:03:14 +0000
Subject: Bug #80965 [NEW]: A use after free bug in ext/spl/spl_dllist.c
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-233489@lists.php.net to get a copy of this message
From: lylgood at foxmail dot com Operating system: All PHP version: master-Git-2021-04-18 (Git) Package: *Extensibility Functions Bug Type: Bug Bug description:A use after free bug in ext/spl/spl_dllist.c Description: ------------ File: ext/spl/spl_dllist.c Bug Function: PHP_METHOD(SplDoublyLinkedList, offsetUnset) In this function, element is obtained via spl_ptr_llist_offset() at line 834. At line 863, the ref of element is decreased by one via SPL_LLIST_DELREF(element), if the refcount of element is 0 now, the element will be freed. But the freed element is still used at line 869 by SPL_LLIST_DELREF(element) which is a macro of "if (!-- ((element)->data).u2.extra) { _efree((element)); }". It is a use after free. If the freed memory of element is allocated by other objects before line 869, then it is possible to fake structures to modify the refcount of element and cause an additional double free. Test script: --------------- 834: element = spl_ptr_llist_offset(intern->llist, index, intern->flags & SPL_DLLIST_IT_LIFO); ... if (intern->traverse_pointer == element) { 863: SPL_LLIST_DELREF(element); // element First freed here! intern->traverse_pointer = NULL; } zval_ptr_dtor(&element->data); ZVAL_UNDEF(&element->data); 869: SPL_LLIST_DELREF(element) // Freed element is used and could be freed again! -- Edit bug report at https://bugs.php.net/bug.php?id=80965&edit=1 -- Fix committed: https://bugs.php.net/fix.php?id=80965&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=80965&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=80965&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=80965&r=needscript Try newer version: https://bugs.php.net/fix.php?id=80965&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=80965&r=support Expected behavior: https://bugs.php.net/fix.php?id=80965&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=80965&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=80965&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=80965&r=globals PHP version support discontinued: https://bugs.php.net/fix.php?id=80965&r=phptooold Daylight Savings: https://bugs.php.net/fix.php?id=80965&r=dst IIS Stability: https://bugs.php.net/fix.php?id=80965&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=80965&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=80965&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=80965&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=80965&r=mysqlcfg

« previous php.bugs (#233489) next »