Bug #81714 [Ver->Csd]: segfault (use-after-free) serializing finalized HashContext
| From: | git@php.net | Date: | Tue, 05 Apr 2022 11:37:55 +0000 |
| Subject: | Bug #81714 [Ver->Csd]: segfault (use-after-free) serializing finalized HashContext | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-240662@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81714&edit=1
ID: 81714
Updated by: git@php.net
Reported by: mail at lucaswerkmeister dot de
Summary: segfault (use-after-free) serializing finalized
HashContext
-Status: Verified
+Status: Closed
Type: Bug
Package: hash related
Operating System: Linux
PHP Version: 8.1.4
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of cmb69
Revision: https://github.com/php/php-src/commit/c2eafc29f5ecf49c86e5a3cb5ba9d6beda6c5ba9
Log: Fix #81714: segfault when serializing finalized HashContext
Previous Comments:
------------------------------------------------------------------------
[2022-03-29 09:51:09] cmb@php.net
The following pull request has been associated:
Patch Name: Fix #81714: segfault when serializing finalized HashContext
On GitHub: https://github.com/php/php-src/pull/8265
Patch: https://github.com/php/php-src/pull/8265.patch
------------------------------------------------------------------------
[2022-03-28 09:16:52] mail at lucaswerkmeister dot de
Description:
------------
Attempting to serialize a finalized HashContext segfaults. Looking at the php-src code, I suspect
this is a use-after-free (so a potential security vulnerability): php_hash_serialize_spec() uses
hash->context after it was efree()d in PHP_FUNCTION(hash_final).
I found the issue in PHP 8.0.8 (Ubuntu 21.10 Impish Indri). 3v4l DOT org SLASH dnXnr claims the
issue is present in all PHP 8 versions, including master. (In PHP 7, HashContext is not
serializable.)
Tested with 'sha256' and 'md5' algos (MD5 used in test script for brevity). I
assume the actual hash algorithm is irrelevant.
Test script:
---------------
<?php
$h = hash_init('md5');
hash_final($h);
serialize($h);
OR:
php -r '$h=hash_init("md5");hash_final($h);serialize($h);'
Expected result:
----------------
Some kind of error, probably. I donât think itâs necessary for a finalized HashContext to
have a valid serialization, it just shouldnât crash.
Actual result:
--------------
Top of internal stack trace (coredumpctl gdb; memory addresses redacted):
Stack trace of thread 918674:
#0 0x php_hash_serialize_spec (php8.0 + 0x)
#1 0x n/a (php8.0 + 0x)
#2 0x xdebug_execute_internal (xdebug.so + 0x)
#3 0x zend_call_function (php8.0 + 0x)
#4 0x zend_call_known_function (php8.0 + 0x)
#5 0x n/a (php8.0 + 0x)
#6 0x php_var_serialize (php8.0 + 0x)
Without xdebug enabled:
Stack trace of thread 919029:
#0 0x php_hash_serialize_spec (php8.0 + 0x)
#1 0x n/a (php8.0 + 0x)
#2 0x zend_call_function (php8.0 + 0x)
#3 0x zend_call_known_function (php8.0 + 0x)
#4 0x n/a (php8.0 + 0x)
#5 0x php_var_serialize (php8.0 + 0x)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=81714&edit=1