Bug #81707 [Opn->Wfx]: Heap address leak when PHP is configured with libmysql + mariadb
| From: | dharman@php.net | Date: | Tue, 15 Feb 2022 14:25:15 +0000 |
| Subject: | Bug #81707 [Opn->Wfx]: Heap address leak when PHP is configured with libmysql + mariadb | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-239812@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81707&edit=1
ID: 81707
Updated by: dharman@php.net
Reported by: ive_jihwan at zerocution dot com
Summary: Heap address leak when PHP is configured with
libmysql + mariadb
-Status: Open
+Status: Wont fix
Type: Bug
Package: MySQLi related
Operating System: WSL
PHP Version: Irrelevant
-Assigned To:
+Assigned To: dharman
Block user comment: N
Private report: N
New Comment:
I am marking this as won't fix, because PHP 8.2 will drop support for libmysql. The integration
of mysqli with libmysql was leaking memory for a long time (if not from the very beginning) and
fixing this isn't easy. It could certainly be fixed but there is not much demand for this. As
we are dropping the support altogether, fixing ancient bugs like this makes very little sense.
Thanks for the report though.
Previous Comments:
------------------------------------------------------------------------
[2022-01-19 06:36:08] ive_jihwan at zerocution dot com
Description:
------------
When PHP is configured with libmysql instead of mysqlnd, there is a possibility to leak emalloc()ed
address via simple SQL query with bind_result and fetch.
This only copies the lower 4 bytes of the address, but since the MSB is fixed as 0x7f, it's
reasonable to find a full heap address.
I tested this in WSL + MariaDB 10.5.13 + PHP 8.2.0-dev with libmysql build
Test script:
---------------
<?php
$mysqli = new mysqli("127.0.0.1", "test", "%");
$stmt = $mysqli->prepare("select 1");
$stmt->bind_result($a);
$stmt->prepare("select 1");
$stmt->execute();
$stmt->fetch();
echo "$a"; // the lowest 4 bytes of heap structure
if (!($a & (int)0xffffffff00000000)) {
printf("Failed, try again\n");
die();
}
printf("Address in heap leaked: 0x7fff%x\n", $a & 0xffffffff);
Expected result:
----------------
Should return 1 or 0
Actual result:
--------------
the lower 4 bytes of (int *)stmt->result.buf[0].val
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=81707&edit=1