Bug #75889 [Opn]: Overloading disk with temporary files

From: Date: Fri, 03 Feb 2023 14:11:35 +0000
Subject: Bug #75889 [Opn]: Overloading disk with temporary files
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-243629@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75889&edit=1 ID: 75889 Updated by: bukka@php.net Reported by: c dot r dot l dot f at yandex dot ru Summary: Overloading disk with temporary files Status: Open Type: Bug Package: FPM related Operating System: Linux PHP Version: 7.1.13 Block user comment: N Private report: N New Comment: After some investigation of this I found another related private report that shed a bit more light on this issue. I was not actually able to use this reproducer even with some modifications as nginx was constantly returning 499. But managed to get a different one: touch evil_upload; curl -F 'test=@evil_upload' http://localhost:8080/index.php >/dev/null 2>&1 & CPID=$! && echo $CPID && sleep 10 && kill -9 $CPID; rm evil_upload The private report actually noted that it was due to bail out which I actually fixed as part of https://github.com/php/php-src/commit/3503b1daa265777588b3219b82219a0056675ca0 so the issue is fixed now. I should say that this was definitely a security issue in my eyes as it is not true that you can upload files until out of disk space because we have got a limit max_upload_files. Stas probably didn't realise that the issue is happening even with this limit in place which should never happen and disk exhaustion is definitely a problem that should be treated as a security issue. So if you still manage to recreate this or similar issue with file uploads somehow, please report it as a new security issue. Previous Comments: ------------------------------------------------------------------------ [2018-02-01 02:21:53] c dot r dot l dot f at yandex dot ru Yep, I just checked it, it's not reproducible when file_uploads = Off. ------------------------------------------------------------------------ [2018-02-01 02:13:29] stas@php.net So do I understand correctly the problem does not exist when file uploads are disabled? ------------------------------------------------------------------------ [2018-02-01 02:06:42] c dot r dot l dot f at yandex dot ru In default installations files uploads is always on, so any host that satisfies the dependencies (PHP+NGINX) can be attacked. Please look video PoC: https://alt3r.eg0.ru/p0c5/12a636fcab5953233706dadacfff3ba8.avi ------------------------------------------------------------------------ [2018-02-01 01:36:58] stas@php.net Isn't that always the case when uploads are allowed - you can upload files until out of disk space, absent other limitations like quotas, etc.? ------------------------------------------------------------------------ [2018-02-01 01:01:32] c dot r dot l dot f at yandex dot ru The problem is that PHP does not delete created temporary files (rfc1867) after connection is closed. In the provided scenario, NGINX closes the connection before PHP writes something in it. Judging by the logs of strace, PHP gets SIGPIPE and for some reasons does not clear temporary files. Thus, the attacker can upload temporary files while disk space is available. Only reboot or manual deleting this files will help. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=75889 -- Edit this bug report at https://bugs.php.net/bug.php?id=75889&edit=1

« previous php.bugs (#243629) next »