Bug #80964 [Opn]: A use after free bug in ext/phar/phar.c

From: Date: Mon, 26 Apr 2021 15:45:00 +0000
Subject: Bug #80964 [Opn]: A use after free bug in ext/phar/phar.c
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-233582@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80964&edit=1 ID: 80964 Updated by: cmb@php.net Reported by: lylgood at foxmail dot com Summary: A use after free bug in ext/phar/phar.c Status: Open Type: Bug Package: *Extensibility Functions Operating System: All PHP Version: master-Git-2021-04-18 (Git) Block user comment: N Private report: N New Comment: I think the scenario you're describing is never supposed to happen, due to the refcount check on line 421. However, that is about phar_archive_data->internal_file->fp_refcount and not phar_archive_data->refcount, so I'm not sure. Previous Comments: ------------------------------------------------------------------------ [2021-04-26 02:53:00] lylgood at foxmail dot com Hi, maintainers. Sorry to distrub you. Is the bug is a truth one? Thanks for your time. ------------------------------------------------------------------------ [2021-04-18 05:45:16] lylgood at foxmail dot com Description: ------------ File: ext/phar/phar.c Bug Function: phar_entry_remove In function phar_entry_remove, idata->phar is assigned to phar at line 419. The idata->phar could be freed at line 430 by calling phar_entry_delref(idata)->phar_archive_delref(idata->phar)->phar_destroy_phar_data(phar). Whereas the freed idata->phar is dereferenced via phar->donotflus at line 433, which causes a use after free bug. Test script: --------------- 419: phar = idata->phar; if (idata->internal_file->fp_refcount < 2) { if (idata->fp && idata->fp != idata->phar->fp && idata->fp != idata->phar->ufp && idata->fp != idata->internal_file->fp) { php_stream_close(idata->fp); } zend_hash_str_del(&idata->phar->manifest, idata->internal_file->filename, idata->internal_file->filename_len); idata->phar->refcount--; efree(idata); } else { idata->internal_file->is_deleted = 1; 430: phar_entry_delref(idata); // idata->phar freed here ! } 433: if (!phar->donotflush) { // use after free here! ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=80964&edit=1

« previous php.bugs (#233582) next »