Sec Bug->Bug #81700 [Opn]: Memory Corruption vulnerability on zen_vm_execute
| From: | stas@php.net | Date: | Fri, 17 Dec 2021 18:09:43 +0000 |
| Subject: | Sec Bug->Bug #81700 [Opn]: Memory Corruption vulnerability on zen_vm_execute | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-238467@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81700&edit=1
ID: 81700
Updated by: stas@php.net
Reported by: 3ntr0py1337 at gmail dot com
Summary: Memory Corruption vulnerability on zen_vm_execute
Status: Open
-Type: Security
+Type: Bug
Package: Reproducible crash
Operating System: Ubuntu 20.04.3 LTS
PHP Version: master-Git-2021-12-17 (Git)
Block user comment: N
Private report: Y
Previous Comments:
------------------------------------------------------------------------
[2021-12-17 12:53:16] 3ntr0py1337 at gmail dot com
Description:
------------
error while unwinding the stack and/or the stack contained return addresses that were not mapped in
the inferior's process address space and/or the stack pointer is pointing to a location outside
the default stack region. These conditions likely indicate stack corruption, which is generally
considered exploitable.
Test script:
---------------
--TEST--
Operatoerloadedproperty reWerence
--FILE--
<?php
class C {
private $bar;
function __construct() { $this->ber = str_repeat("1", 2); }
function &__get($x) { return $this->ar; }
function __set($x, $v) { $this->bar = $v= new C;
va; }
}
$x = new C;
var_dump(++$x->foo);
$x = ($x->foo++);
$x = new C;
var_dumphhhhhhhhhhhhhhh
?>
-EXPECT--
int(12)
string(2) "11"
int(13)
Expected result:
----------------
EFLAGS: 0x10206 (carry PARITY adjust zero sign trap INTERRUPT direction overflow)
[-------------------------------------code-------------------------------------]
0x555556666403 <execute_ex+99>: test rdi,rdi
0x555556666406 <execute_ex+102>: je 0x55555666668b <execute_ex+747>
0x55555666640c <execute_ex+108>: lea rsp,[rsp-0x98]
=> 0x555556666414 <execute_ex+116>: mov QWORD PTR [rsp],rdx
0x555556666418 <execute_ex+120>: mov QWORD PTR [rsp+0x8],rcx
0x55555666641d <execute_ex+125>: mov QWORD PTR [rsp+0x10],rax
0x555556666422 <execute_ex+130>: mov rcx,0x9103
0x555556666429 <execute_ex+137>: call 0x5555566b0628 <__afl_maybe_log>
[------------------------------------stack-------------------------------------]
Invalid $SP address: 0x7fffff7fefb8
[------------------------------------------------------------------------------]
Legend: code, data, rodata, value
Stopped reason: SIGSEGV
0x0000555556666414 in execute_ex (ex=0x7ffff50b4c00) at
/home/ubuntu/victims/php-src/Zend/zend_vm_execute.h:51997
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=81700&edit=1