Bug #81153 [Dup->Opn]: unserialize error calls __destruct before __wakeup

From: Date: Thu, 17 Jun 2021 09:18:55 +0000
Subject: Bug #81153 [Dup->Opn]: unserialize error calls __destruct before __wakeup
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234453@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81153&edit=1 ID: 81153 Updated by: requinix@php.net Reported by: j7ur8 at qq dot com -Summary: bypass __wakeup +Summary: unserialize error calls __destruct before __wakeup -Status: Duplicate +Status: Open Type: Bug Package: Class/Object related Operating System: ALL PHP Version: 7.3.28 Block user comment: N Private report: N New Comment: Yes, this is different. Please try to give a correct bug summary next time. https://3v4l.org/0YvfT > Notice: unserialize(): Error at offset 31 of 33 bytes in /in/0YvfT on line 22 > C::__destruct > D::__get(b) > D::__wakeup > D::__destruct Feels like the order of operations should have been > D::__wakeup - because the object was successfully created > C::__destruct - unserialization failed, begin destruction > C::__get(b) - because of the code > D::__destruct - cleaning up after C was destroyed Previous Comments: ------------------------------------------------------------------------ [2021-06-17 09:00:45] j7ur8 at qq dot com this is another one! ------------------------------------------------------------------------ [2021-06-17 08:59:51] requinix@php.net You already reported this. ------------------------------------------------------------------------ [2021-06-17 08:49:21] j7ur8 at qq dot com Description: ------------ bad unserialize string makes __wakeup ineffective. Success: 7.0.15 - 7.0.33, 7.1.1 - 7.1.33, 7.2.0 - 7.2.34, 7.3.0 - 7.3.28, 7.4.0 - 7.4.16, 8.0.0 - 8.0.3 Fail: 5.0.0 - 5.0.5, 5.1.0 - 5.1.6, 5.2.0 - 5.2.17, 5.3.0 - 5.3.29, 5.4.0 - 5.4.45, 5.5.0 - 5.5.38, 5.6.0 - 5.6.40, 7.0.0 - 7.0.14, 7.1.0 Test script: --------------- // https://3v4l.org/4nZUm <?php class D{ public $flag=True; public function __get($a){ if($this->flag){ echo 'flag'; }else{ echo 'hint'; } } public function __wakeup(){ $this->flag = False; } } class C{ public function __destruct(){ echo $this->c->b; } } @unserialize('O:1:"C":1:{s:1:"c";O:1:"D":0:{};N;}'); Expected result: ---------------- hint Actual result: -------------- flag ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=81153&edit=1

« previous php.bugs (#234453) next »