Bug #81707 [Opn->Wfx]: Heap address leak when PHP is configured with libmysql + mariadb

From: Date: Tue, 15 Feb 2022 14:25:15 +0000
Subject: Bug #81707 [Opn->Wfx]: Heap address leak when PHP is configured with libmysql + mariadb
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-239812@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81707&edit=1 ID: 81707 Updated by: dharman@php.net Reported by: ive_jihwan at zerocution dot com Summary: Heap address leak when PHP is configured with libmysql + mariadb -Status: Open +Status: Wont fix Type: Bug Package: MySQLi related Operating System: WSL PHP Version: Irrelevant -Assigned To: +Assigned To: dharman Block user comment: N Private report: N New Comment: I am marking this as won't fix, because PHP 8.2 will drop support for libmysql. The integration of mysqli with libmysql was leaking memory for a long time (if not from the very beginning) and fixing this isn't easy. It could certainly be fixed but there is not much demand for this. As we are dropping the support altogether, fixing ancient bugs like this makes very little sense. Thanks for the report though. Previous Comments: ------------------------------------------------------------------------ [2022-01-19 06:36:08] ive_jihwan at zerocution dot com Description: ------------ When PHP is configured with libmysql instead of mysqlnd, there is a possibility to leak emalloc()ed address via simple SQL query with bind_result and fetch. This only copies the lower 4 bytes of the address, but since the MSB is fixed as 0x7f, it's reasonable to find a full heap address. I tested this in WSL + MariaDB 10.5.13 + PHP 8.2.0-dev with libmysql build Test script: --------------- <?php $mysqli = new mysqli("127.0.0.1", "test", "%"); $stmt = $mysqli->prepare("select 1"); $stmt->bind_result($a); $stmt->prepare("select 1"); $stmt->execute(); $stmt->fetch(); echo "$a"; // the lowest 4 bytes of heap structure if (!($a & (int)0xffffffff00000000)) { printf("Failed, try again\n"); die(); } printf("Address in heap leaked: 0x7fff%x\n", $a & 0xffffffff); Expected result: ---------------- Should return 1 or 0 Actual result: -------------- the lower 4 bytes of (int *)stmt->result.buf[0].val ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=81707&edit=1

« previous php.bugs (#239812) next »