Sec Bug->Bug #81992 [Opn]: SplFixedArray::setSize() causes use-after-free

From: Date: Thu, 25 May 2023 22:36:49 +0000
Subject: Sec Bug->Bug #81992 [Opn]: SplFixedArray::setSize() causes use-after-free
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-244541@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81992&edit=1 ID: 81992 Updated by: stas@php.net Reported by: cyberguru007 at yandex dot ru Summary: SplFixedArray::setSize() causes use-after-free Status: Open -Type: Security +Type: Bug Package: SPL related Operating System: Linux PHP Version: 8.2.6RC1 Block user comment: N Private report: Y Previous Comments: ------------------------------------------------------------------------ [2023-05-10 11:39:12] cyberguru007 at yandex dot ru Description: ------------ The root cause of this bug is similar to bug #80663. There is a problem when __destruct called in the middle of SplFixedArray resizing. There is no check that size of internal storage was changed. In function static void spl_fixedarray_resize(spl_fixedarray *array, zend_long size) the case when size = 0 was fixed in #80663, but similar case when size < array->size was not fixed. It causes use-after-free. The bug can be triggered locally, or remotely, for example using unserialize(), and cause code execution. The bug exists in PHP versions from End of life 7.4.* to latest 8.2.* Test script: --------------- <?php class InvalidDestructor { public function __destruct() { global $obj; $a = str_repeat('A', 100); var_dump($obj[2]); } } $obj = new SplFixedArray(5); $obj[2] = str_repeat('B', 100); $obj[3] = new InvalidDestructor(); $obj->setSize(2); Expected result: ---------------- string(100) "BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB" Actual result: -------------- string(100) "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA" ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=81992&edit=1

« previous php.bugs (#244541) next »