Bug #80964 [Opn]: A use after free bug in ext/phar/phar.c

From: Date: Mon, 26 Apr 2021 02:53:00 +0000
Subject: Bug #80964 [Opn]: A use after free bug in ext/phar/phar.c
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-233569@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80964&edit=1 ID: 80964 User updated by: lylgood at foxmail dot com Reported by: lylgood at foxmail dot com Summary: A use after free bug in ext/phar/phar.c Status: Open Type: Bug Package: *Extensibility Functions Operating System: All PHP Version: master-Git-2021-04-18 (Git) Block user comment: N Private report: N New Comment: Hi, maintainers. Sorry to distrub you. Is the bug is a truth one? Thanks for your time. Previous Comments: ------------------------------------------------------------------------ [2021-04-18 05:45:16] lylgood at foxmail dot com Description: ------------ File: ext/phar/phar.c Bug Function: phar_entry_remove In function phar_entry_remove, idata->phar is assigned to phar at line 419. The idata->phar could be freed at line 430 by calling phar_entry_delref(idata)->phar_archive_delref(idata->phar)->phar_destroy_phar_data(phar). Whereas the freed idata->phar is dereferenced via phar->donotflus at line 433, which causes a use after free bug. Test script: --------------- 419: phar = idata->phar; if (idata->internal_file->fp_refcount < 2) { if (idata->fp && idata->fp != idata->phar->fp && idata->fp != idata->phar->ufp && idata->fp != idata->internal_file->fp) { php_stream_close(idata->fp); } zend_hash_str_del(&idata->phar->manifest, idata->internal_file->filename, idata->internal_file->filename_len); idata->phar->refcount--; efree(idata); } else { idata->internal_file->is_deleted = 1; 430: phar_entry_delref(idata); // idata->phar freed here ! } 433: if (!phar->donotflush) { // use after free here! ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=80964&edit=1

« previous php.bugs (#233569) next »