Bug #80966 [Fbk->Asn]: A potential use after free bug in ext/standard/browscap.c

From: Date: Tue, 20 Apr 2021 03:00:46 +0000
Subject: Bug #80966 [Fbk->Asn]: A potential use after free bug in ext/standard/browscap.c
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-233515@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80966&edit=1 ID: 80966 User updated by: lylgood at foxmail dot com Reported by: lylgood at foxmail dot com Summary: A potential use after free bug in ext/standard/browscap.c -Status: Feedback +Status: Assigned Type: Bug Package: *Extensibility Functions Operating System: All PHP Version: master-Git-2021-04-18 (Git) Assigned To: cmb Block user comment: N Private report: N New Comment: This bug is reported by a code analyzer. Did you mean the pattern return via zend_new_interned_string() will hold ZSTR_IS_INTERNED(pattern) is true, and will not run into zend_string_release(pattern) ? Previous Comments: ------------------------------------------------------------------------ [2021-04-19 11:13:20] cmb@php.net That code looks correct to me, since the pattern is copied, so needs to be released if interning fails. Could you come up with a reproduce script showing the use-after-free? ------------------------------------------------------------------------ [2021-04-18 07:32:45] lylgood at foxmail dot com Description: ------------ File: ext/standard/browscap.c Bug Function: php_browscap_parser_cb In function php_browscap_parser_cb, pattern is re-assigned by pattern = zend_new_interned_string() at line 368. Then if ZSTR_IS_INTERNED(pattern) is false, pattern will be freed via zend_string_release(pattern) at line 372. But after that, pattern is still used at line 378 by zend_hash_update_ptr(bdata->htab, pattern, entry), which is a use after free bug. Test script: --------------- if (persistent) { 368: pattern = zend_new_interned_string(zend_string_copy(pattern)); if (ZSTR_IS_INTERNED(pattern)) { Z_TYPE_FLAGS_P(arg1) = 0; } else { 372: zend_string_release(pattern); //pattern could be freed ! } } ... 378: zend_hash_update_ptr(bdata->htab, pattern, entry);//freed pattern is used ! ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=80966&edit=1

« previous php.bugs (#233515) next »