Bug #80966 [Fbk->Asn]: A potential use after free bug in ext/standard/browscap.c
| From: | lylgood at foxmail dot com | Date: | Tue, 20 Apr 2021 03:00:46 +0000 |
| Subject: | Bug #80966 [Fbk->Asn]: A potential use after free bug in ext/standard/browscap.c | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-233515@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80966&edit=1
ID: 80966
User updated by: lylgood at foxmail dot com
Reported by: lylgood at foxmail dot com
Summary: A potential use after free bug in
ext/standard/browscap.c
-Status: Feedback
+Status: Assigned
Type: Bug
Package: *Extensibility Functions
Operating System: All
PHP Version: master-Git-2021-04-18 (Git)
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
This bug is reported by a code analyzer. Did you mean the pattern return via
zend_new_interned_string() will hold ZSTR_IS_INTERNED(pattern) is true, and will not run into
zend_string_release(pattern) ?
Previous Comments:
------------------------------------------------------------------------
[2021-04-19 11:13:20] cmb@php.net
That code looks correct to me, since the pattern is copied, so
needs to be released if interning fails. Could you come up with a
reproduce script showing the use-after-free?
------------------------------------------------------------------------
[2021-04-18 07:32:45] lylgood at foxmail dot com
Description:
------------
File: ext/standard/browscap.c
Bug Function: php_browscap_parser_cb
In function php_browscap_parser_cb, pattern is re-assigned by pattern = zend_new_interned_string()
at line 368.
Then if ZSTR_IS_INTERNED(pattern) is false, pattern will be freed via zend_string_release(pattern)
at line 372.
But after that, pattern is still used at line 378 by zend_hash_update_ptr(bdata->htab, pattern,
entry), which is a use after free bug.
Test script:
---------------
if (persistent) {
368: pattern = zend_new_interned_string(zend_string_copy(pattern));
if (ZSTR_IS_INTERNED(pattern)) {
Z_TYPE_FLAGS_P(arg1) = 0;
} else {
372: zend_string_release(pattern); //pattern could be freed !
}
}
...
378: zend_hash_update_ptr(bdata->htab, pattern, entry);//freed pattern is used !
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80966&edit=1