Sec Bug->Bug #81700 [Opn]: Memory Corruption vulnerability on zen_vm_execute

From: Date: Fri, 17 Dec 2021 18:09:43 +0000
Subject: Sec Bug->Bug #81700 [Opn]: Memory Corruption vulnerability on zen_vm_execute
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-238467@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81700&edit=1 ID: 81700 Updated by: stas@php.net Reported by: 3ntr0py1337 at gmail dot com Summary: Memory Corruption vulnerability on zen_vm_execute Status: Open -Type: Security +Type: Bug Package: Reproducible crash Operating System: Ubuntu 20.04.3 LTS PHP Version: master-Git-2021-12-17 (Git) Block user comment: N Private report: Y Previous Comments: ------------------------------------------------------------------------ [2021-12-17 12:53:16] 3ntr0py1337 at gmail dot com Description: ------------ error while unwinding the stack and/or the stack contained return addresses that were not mapped in the inferior's process address space and/or the stack pointer is pointing to a location outside the default stack region. These conditions likely indicate stack corruption, which is generally considered exploitable. Test script: --------------- --TEST-- Operatoerloadedproperty reWerence --FILE-- <?php class C { private $bar; function __construct() { $this->ber = str_repeat("1", 2); } function &__get($x) { return $this->ar; } function __set($x, $v) { $this->bar = $v= new C; va; } } $x = new C; var_dump(++$x->foo); $x = ($x->foo++); $x = new C; var_dumphhhhhhhhhhhhhhh ?> -EXPECT-- int(12) string(2) "11" int(13) Expected result: ---------------- EFLAGS: 0x10206 (carry PARITY adjust zero sign trap INTERRUPT direction overflow) [-------------------------------------code-------------------------------------] 0x555556666403 <execute_ex+99>: test rdi,rdi 0x555556666406 <execute_ex+102>: je 0x55555666668b <execute_ex+747> 0x55555666640c <execute_ex+108>: lea rsp,[rsp-0x98] => 0x555556666414 <execute_ex+116>: mov QWORD PTR [rsp],rdx 0x555556666418 <execute_ex+120>: mov QWORD PTR [rsp+0x8],rcx 0x55555666641d <execute_ex+125>: mov QWORD PTR [rsp+0x10],rax 0x555556666422 <execute_ex+130>: mov rcx,0x9103 0x555556666429 <execute_ex+137>: call 0x5555566b0628 <__afl_maybe_log> [------------------------------------stack-------------------------------------] Invalid $SP address: 0x7fffff7fefb8 [------------------------------------------------------------------------------] Legend: code, data, rodata, value Stopped reason: SIGSEGV 0x0000555556666414 in execute_ex (ex=0x7ffff50b4c00) at /home/ubuntu/victims/php-src/Zend/zend_vm_execute.h:51997 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=81700&edit=1

« previous php.bugs (#238467) next »