Bug #80964 [Opn->Fbk]: A use after free bug in ext/phar/phar.c
Edit report at https://bugs.php.net/bug.php?id=80964&edit=1
ID: 80964
Updated by: krakjoe@php.net
Reported by: lylgood at foxmail dot com
Summary: A use after free bug in ext/phar/phar.c
-Status: Open
+Status: Feedback
Type: Bug
Package: *Extensibility Functions
Operating System: All
PHP Version: master-Git-2021-04-18 (Git)
Block user comment: N
Private report: N
New Comment:
Thank you for this bug report. To properly diagnose the problem, we
need a short but complete example script to be able to reproduce
this bug ourselves.
A proper reproducing script starts with <?php and ends with ?>,
is max. 10-20 lines long and does not require any external
resources such as databases, etc. If the script requires a
database to demonstrate the issue, please make sure it creates
all necessary tables, stored procedures etc.
Please avoid embedding huge scripts into the report.
Previous Comments:
------------------------------------------------------------------------
[2021-04-26 15:45:00] cmb@php.net
I think the scenario you're describing is never supposed to
happen, due to the refcount check on line 421. However, that is
about phar_archive_data->internal_file->fp_refcount and not
phar_archive_data->refcount, so I'm not sure.
------------------------------------------------------------------------
[2021-04-26 02:53:00] lylgood at foxmail dot com
Hi, maintainers.
Sorry to distrub you. Is the bug is a truth one?
Thanks for your time.
------------------------------------------------------------------------
[2021-04-18 05:45:16] lylgood at foxmail dot com
Description:
------------
File: ext/phar/phar.c
Bug Function: phar_entry_remove
In function phar_entry_remove, idata->phar is assigned to phar at line 419.
The idata->phar could be freed at line 430 by calling
phar_entry_delref(idata)->phar_archive_delref(idata->phar)->phar_destroy_phar_data(phar).
Whereas the freed idata->phar is dereferenced via phar->donotflus at line 433,
which causes a use after free bug.
Test script:
---------------
419: phar = idata->phar;
if (idata->internal_file->fp_refcount < 2) {
if (idata->fp && idata->fp != idata->phar->fp && idata->fp !=
idata->phar->ufp && idata->fp != idata->internal_file->fp) {
php_stream_close(idata->fp);
}
zend_hash_str_del(&idata->phar->manifest, idata->internal_file->filename,
idata->internal_file->filename_len);
idata->phar->refcount--;
efree(idata);
} else {
idata->internal_file->is_deleted = 1;
430: phar_entry_delref(idata); // idata->phar freed here !
}
433: if (!phar->donotflush) { // use after free here!
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80964&edit=1
Thread (5 messages)