Sec Bug->Bug #81992 [Opn]: SplFixedArray::setSize() causes use-after-free
| From: | stas@php.net | Date: | Thu, 25 May 2023 22:36:49 +0000 |
| Subject: | Sec Bug->Bug #81992 [Opn]: SplFixedArray::setSize() causes use-after-free | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-244541@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81992&edit=1
ID: 81992
Updated by: stas@php.net
Reported by: cyberguru007 at yandex dot ru
Summary: SplFixedArray::setSize() causes use-after-free
Status: Open
-Type: Security
+Type: Bug
Package: SPL related
Operating System: Linux
PHP Version: 8.2.6RC1
Block user comment: N
Private report: Y
Previous Comments:
------------------------------------------------------------------------
[2023-05-10 11:39:12] cyberguru007 at yandex dot ru
Description:
------------
The root cause of this bug is similar to bug #80663.
There is a problem when __destruct called in the middle of SplFixedArray resizing. There is no check
that size of internal storage was changed.
In function static void spl_fixedarray_resize(spl_fixedarray *array, zend_long size) the case when
size = 0 was fixed in #80663, but similar case when size < array->size was not fixed. It
causes use-after-free.
The bug can be triggered locally, or remotely, for example using unserialize(), and cause code
execution.
The bug exists in PHP versions from End of life 7.4.* to latest 8.2.*
Test script:
---------------
<?php
class InvalidDestructor {
public function __destruct() {
global $obj;
$a = str_repeat('A', 100);
var_dump($obj[2]);
}
}
$obj = new SplFixedArray(5);
$obj[2] = str_repeat('B', 100);
$obj[3] = new InvalidDestructor();
$obj->setSize(2);
Expected result:
----------------
string(100)
"BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB"
Actual result:
--------------
string(100)
"AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA"
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=81992&edit=1