Bug #81714 [PATCH]: segfault (use-after-free) serializing finalized HashContext

From: Date: Tue, 29 Mar 2022 09:51:09 +0000
Subject: Bug #81714 [PATCH]: segfault (use-after-free) serializing finalized HashContext
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-240550@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81714&edit=1

 ID:                 81714
 Patch added by:     cmb@php.net
 Reported by:        mail at lucaswerkmeister dot de
 Summary:            segfault (use-after-free) serializing finalized
                     HashContext
 Status:             Verified
 Type:               Bug
 Package:            hash related
 Operating System:   Linux
 PHP Version:        8.1.4
 Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

The following pull request has been associated:

Patch Name: Fix #81714: segfault when serializing finalized HashContext
On GitHub:  https://github.com/php/php-src/pull/8265
Patch:      https://github.com/php/php-src/pull/8265.patch


Previous Comments:
------------------------------------------------------------------------
[2022-03-28 09:16:52] mail at lucaswerkmeister dot de

Description:
------------
Attempting to serialize a finalized HashContext segfaults. Looking at the php-src code, I suspect
this is a use-after-free (so a potential security vulnerability): php_hash_serialize_spec() uses
hash->context after it was efree()d in PHP_FUNCTION(hash_final).

I found the issue in PHP 8.0.8 (Ubuntu 21.10 Impish Indri). 3v4l DOT org SLASH dnXnr claims the
issue is present in all PHP 8 versions, including master. (In PHP 7, HashContext is not
serializable.)

Tested with 'sha256' and 'md5' algos (MD5 used in test script for brevity). I
assume the actual hash algorithm is irrelevant.

Test script:
---------------
<?php

$h = hash_init('md5');
hash_final($h);
serialize($h);

OR:

php -r '$h=hash_init("md5");hash_final($h);serialize($h);'

Expected result:
----------------
Some kind of error, probably. I don’t think it’s necessary for a finalized HashContext to
have a valid serialization, it just shouldn’t crash.

Actual result:
--------------
Top of internal stack trace (coredumpctl gdb; memory addresses redacted):

                Stack trace of thread 918674:
                #0  0x php_hash_serialize_spec (php8.0 + 0x)
                #1  0x n/a (php8.0 + 0x)
                #2  0x xdebug_execute_internal (xdebug.so + 0x)
                #3  0x zend_call_function (php8.0 + 0x)
                #4  0x zend_call_known_function (php8.0 + 0x)
                #5  0x n/a (php8.0 + 0x)
                #6  0x php_var_serialize (php8.0 + 0x)

Without xdebug enabled:

                Stack trace of thread 919029:
                #0  0x php_hash_serialize_spec (php8.0 + 0x)
                #1  0x n/a (php8.0 + 0x)
                #2  0x zend_call_function (php8.0 + 0x)
                #3  0x zend_call_known_function (php8.0 + 0x)
                #4  0x n/a (php8.0 + 0x)
                #5  0x php_var_serialize (php8.0 + 0x)



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=81714&edit=1


Thread (1 message)

  • cmb@php.net
  • Unknown Message
    • cmb@php.net
« previous php.bugs (#240550) next »