[php-src] Issue #8989: [Bug] Potential buffer overflow in php_cli_server_startup_workers
| From: | yiyuaner | Date: | Wed, 13 Jul 2022 06:50:02 +0000 |
| Subject: | [php-src] Issue #8989: [Bug] Potential buffer overflow in php_cli_server_startup_workers | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-241916@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/8989
Author: yiyuaner
### Description
In the file
sapi/cli/php_cli_server.c, the function
php_cli_server_startup_workers has the following
[code](https://github.com/php/php-src/blob/56804e32216574c66cf71359a8a8830e7badc757/sapi/cli/php_cli_server.c#L2413):
```
void php_cli_server_startup_workers(void) {
char *workers = getenv("PHP_CLI_SERVER_WORKERS");
if (!workers) {
return;
}
php_cli_server_workers_max = ZEND_ATOL(workers);
if (php_cli_server_workers_max > 1) {
php_cli_server_workers = calloc(
php_cli_server_workers_max, sizeof(pid_t));
...
}
}
```
The variable php_cli_server_workers_max is parsed from environment variable and thus is
controlled. When setting php_cli_server_workers_max to a large value (e.g.,
INT64_MAX), the multiplication php_cli_server_workers_max * sizeof(pid_t)
could wrap to a small value. A buffer smaller than expected will be allocated and this can lead to
subsequent buffer overflow.
Notice that the C standard does not clearly states that calloc will check for
multiplication overflow itself (see
[here](https://wiki.sei.cmu.edu/confluence/display/c/MEM07-C.+Ensure+that+the+arguments+to+calloc%28%29%2C+when+multiplied%2C+do+not+wrap)).
It will be better to also restrict the maximum value for php_cli_server_workers_max in
the code.
### PHP Version
github master
### Operating System
_No response_