Bug #81190 [Com]: 2 crashes(heap-buffer-overflow,SEGV) 5 memory leaks
| From: | gutaotao1995 at qq dot com | Date: | Thu, 01 Jul 2021 14:07:49 +0000 |
| Subject: | Bug #81190 [Com]: 2 crashes(heap-buffer-overflow,SEGV) 5 memory leaks | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-234739@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81190&edit=1
ID: 81190
Comment by: gutaotao1995 at qq dot com
Reported by: gutaotao1995 at qq dot com
Summary: 2 crashes(heap-buffer-overflow,SEGV) 5 memory
leaks
Status: Open
Type: Bug
Package: *General Issues
Operating System: linux
PHP Version: 8.1.0alpha1
Block user comment: N
Private report: N
New Comment:
Thank you very much for your contribution to PHP .
Previous Comments:
------------------------------------------------------------------------
[2021-07-01 13:56:48] gutaotao1995 at qq dot com
Thank you again for your work, your efficiency is so high!
Can I assign a CVE number to the POC I reported?
------------------------------------------------------------------------
[2021-07-01 13:55:41] gutaotao1995 at qq dot com
Thanks for your work!
Hello, some leak vulnerabilities have been fixed, but they are indeed triggered on the latest
build of oss-fuzz.
Regarding other crashes, such as heap-UAF, have other leak vulnerabilities successfully
reproduced?
In your comment, what does the final "reduction" mean? Please explain to me, is it
impossible to reproduce? Or has it been confirmed as a vulnerability?
------------------------------------------------------------------------
[2021-07-01 13:54:34] nikic@php.net
leak-6b6a01c65b09e6170fa2c931a69bbd10b72dfa2d is fixed by https://github.com/php/php-src/commit/36f5d719f5ae005fe9ff47160a02cb57a189bc37.
------------------------------------------------------------------------
[2021-07-01 13:18:53] nikic@php.net
leak-d8ad2e3ddc6bd2dc1b8b90d888839a14c4fc3e0d leak-9cce506f49cdcb36e163eec33660d04c4584b62c
leak-6ffa0db8b44422f944c7cef615626d8700f03aba
leak-54763f12cb80a6568ee17f2b20a51aa539d4081f
leak-267580dd60d6d8d048a8e40eaa74d897efabd313
leak-2-php-execute
leak-1-php-execute
Fixed by https://github.com/php/php-src/commit/540fed1b3654339fc4683ed128f7a1c351e34c4f
just before I started looking at this bug, based on the report from https://oss-fuzz.com/testcase-detail/5794742387474432.
crash-15b5113dd0db60acc6b367b812c883f0e31c6258
Doesn't reproduce.
leak-6b6a01c65b09e6170fa2c931a69bbd10b72dfa2d
Reduction:
<?php
$obj = new stdClass;
foreach ([0] as &$obj->prop) {}
leak-570847a2eeae3e477d2ba8253adb1ca3f78feb26
Reduction:
<?php
null?->{[$x]};
crash-php-execute
Reduction:
<?php
set_error_handler(function(A $r){});
strlen($undef);
crash-eb98564ea8b9e5328defbc17269cfc2c6874d304
Reduction:
<?php
$o = new stdClass;
$o->p =& $o;
$o - $o->p="";
------------------------------------------------------------------------
[2021-07-01 12:01:21] gutaotao1995 at qq dot com
Hello,
No one has replied to me a few days ago.
Since the vulnerability has not been disclosed, I set up private access
permissions for safety reasons.
At this time, I reset everyone to be accessible.
Thanks for your reply.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=81190
--
Edit this bug report at https://bugs.php.net/bug.php?id=81190&edit=1