Bug #80964 [Opn->Fbk]: A use after free bug in ext/phar/phar.c

From: Date: Tue, 11 May 2021 06:39:22 +0000
Subject: Bug #80964 [Opn->Fbk]: A use after free bug in ext/phar/phar.c
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-233773@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80964&edit=1

 ID:                 80964
 Updated by:         krakjoe@php.net
 Reported by:        lylgood at foxmail dot com
 Summary:            A use after free bug in ext/phar/phar.c
-Status:             Open
+Status:             Feedback
 Type:               Bug
 Package:            *Extensibility Functions
 Operating System:   All
 PHP Version:        master-Git-2021-04-18 (Git)
 Block user comment: N
 Private report:     N

 New Comment:

Thank you for this bug report. To properly diagnose the problem, we
need a short but complete example script to be able to reproduce
this bug ourselves.

A proper reproducing script starts with <?php and ends with ?>,
is max. 10-20 lines long and does not require any external
resources such as databases, etc. If the script requires a
database to demonstrate the issue, please make sure it creates
all necessary tables, stored procedures etc.

Please avoid embedding huge scripts into the report.




Previous Comments:
------------------------------------------------------------------------
[2021-04-26 15:45:00] cmb@php.net

I think the scenario you're describing is never supposed to
happen, due to the refcount check on line 421.  However, that is
about phar_archive_data->internal_file->fp_refcount and not
phar_archive_data->refcount, so I'm not sure.

------------------------------------------------------------------------
[2021-04-26 02:53:00] lylgood at foxmail dot com

Hi, maintainers.

Sorry to distrub you. Is the bug is a truth one?
Thanks for your time.

------------------------------------------------------------------------
[2021-04-18 05:45:16] lylgood at foxmail dot com

Description:
------------
File: ext/phar/phar.c
Bug Function: phar_entry_remove

In function phar_entry_remove, idata->phar is assigned to phar at line 419.
The idata->phar could be freed at line 430 by calling
phar_entry_delref(idata)->phar_archive_delref(idata->phar)->phar_destroy_phar_data(phar).
Whereas the freed idata->phar is dereferenced via phar->donotflus at line 433,
which causes a use after free bug.




Test script:
---------------
419:	phar = idata->phar;

	if (idata->internal_file->fp_refcount < 2) {
		if (idata->fp && idata->fp != idata->phar->fp && idata->fp !=
idata->phar->ufp && idata->fp != idata->internal_file->fp) {
			php_stream_close(idata->fp);
		}
		zend_hash_str_del(&idata->phar->manifest, idata->internal_file->filename,
idata->internal_file->filename_len);
		idata->phar->refcount--;
		efree(idata);
	} else {
		idata->internal_file->is_deleted = 1;
430:		phar_entry_delref(idata); // idata->phar freed here !
	}

433:	if (!phar->donotflush) {  // use after free here!



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=80964&edit=1


Thread (5 messages)

« previous php.bugs (#233773) next »