Bug #75889 [Csd]: Overloading disk with temporary files

From: Date: Fri, 03 Feb 2023 14:14:14 +0000
Subject: Bug #75889 [Csd]: Overloading disk with temporary files
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-243631@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75889&edit=1 ID: 75889 Updated by: bukka@php.net Reported by: c dot r dot l dot f at yandex dot ru Summary: Overloading disk with temporary files Status: Closed Type: Bug Package: FPM related Operating System: Linux PHP Version: 7.1.13 Assigned To: bukka Block user comment: N Private report: N New Comment: I should also note that the fix is available from PHP 8.0.24 Previous Comments: ------------------------------------------------------------------------ [2023-02-03 14:11:35] bukka@php.net After some investigation of this I found another related private report that shed a bit more light on this issue. I was not actually able to use this reproducer even with some modifications as nginx was constantly returning 499. But managed to get a different one: touch evil_upload; curl -F 'test=@evil_upload' http://localhost:8080/index.php >/dev/null 2>&1 & CPID=$! && echo $CPID && sleep 10 && kill -9 $CPID; rm evil_upload The private report actually noted that it was due to bail out which I actually fixed as part of https://github.com/php/php-src/commit/3503b1daa265777588b3219b82219a0056675ca0 so the issue is fixed now. I should say that this was definitely a security issue in my eyes as it is not true that you can upload files until out of disk space because we have got a limit max_upload_files. Stas probably didn't realise that the issue is happening even with this limit in place which should never happen and disk exhaustion is definitely a problem that should be treated as a security issue. So if you still manage to recreate this or similar issue with file uploads somehow, please report it as a new security issue. ------------------------------------------------------------------------ [2018-02-01 02:21:53] c dot r dot l dot f at yandex dot ru Yep, I just checked it, it's not reproducible when file_uploads = Off. ------------------------------------------------------------------------ [2018-02-01 02:13:29] stas@php.net So do I understand correctly the problem does not exist when file uploads are disabled? ------------------------------------------------------------------------ [2018-02-01 02:06:42] c dot r dot l dot f at yandex dot ru In default installations files uploads is always on, so any host that satisfies the dependencies (PHP+NGINX) can be attacked. Please look video PoC: https://alt3r.eg0.ru/p0c5/12a636fcab5953233706dadacfff3ba8.avi ------------------------------------------------------------------------ [2018-02-01 01:36:58] stas@php.net Isn't that always the case when uploads are allowed - you can upload files until out of disk space, absent other limitations like quotas, etc.? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=75889 -- Edit this bug report at https://bugs.php.net/bug.php?id=75889&edit=1

« previous php.bugs (#243631) next »