[php-src] Issue #8989: [Bug] Potential buffer overflow in php_cli_server_startup_workers

From: Date: Wed, 13 Jul 2022 06:50:02 +0000
Subject: [php-src] Issue #8989: [Bug] Potential buffer overflow in php_cli_server_startup_workers
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-241916@lists.php.net to get a copy of this message
Issue: https://github.com/php/php-src/issues/8989 Author: yiyuaner ### Description In the file sapi/cli/php_cli_server.c, the function php_cli_server_startup_workers has the following [code](https://github.com/php/php-src/blob/56804e32216574c66cf71359a8a8830e7badc757/sapi/cli/php_cli_server.c#L2413): ``` void php_cli_server_startup_workers(void) { char *workers = getenv("PHP_CLI_SERVER_WORKERS"); if (!workers) { return; } php_cli_server_workers_max = ZEND_ATOL(workers); if (php_cli_server_workers_max > 1) { php_cli_server_workers = calloc( php_cli_server_workers_max, sizeof(pid_t)); ... } } ``` The variable php_cli_server_workers_max is parsed from environment variable and thus is controlled. When setting php_cli_server_workers_max to a large value (e.g., INT64_MAX), the multiplication php_cli_server_workers_max * sizeof(pid_t) could wrap to a small value. A buffer smaller than expected will be allocated and this can lead to subsequent buffer overflow. Notice that the C standard does not clearly states that calloc will check for multiplication overflow itself (see [here](https://wiki.sei.cmu.edu/confluence/display/c/MEM07-C.+Ensure+that+the+arguments+to+calloc%28%29%2C+when+multiplied%2C+do+not+wrap)). It will be better to also restrict the maximum value for php_cli_server_workers_max in the code. ### PHP Version github master ### Operating System _No response_

« previous php.bugs (#241916) next »