[php-src] Issue #24148: Regression in fix for GHSA-9f67-6fw4-hpfp: bare device name "NUL" can not be opened if open_basedir is set.
| From: | jbaron-gingco | Date: | Mon, 05 Oct 2026 21:35:23 +0000 |
| Subject: | [php-src] Issue #24148: Regression in fix for GHSA-9f67-6fw4-hpfp: bare device name "NUL" can not be opened if open_basedir is set. | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-252908@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/24148
Author: jbaron-gingco
### Description
The following code:
```php
<?php
echo PHP_VERSION . "\n";
function run()
{
echo 'open_basedir=', var_export(ini_get('open_basedir'), true) .
"\n";
error_clear_last();
var_dump(@fopen('NUL', 'w'), error_get_last()['message'] ?? null);
error_clear_last();
$result = @proc_open('cmd /c ver', [['pipe', 'r'], ['file',
'NUL', 'w'], ['file', 'NUL', 'w']], $pipes);
var_dump($result, error_get_last()['message'] ?? null);
}
run();
ini_set('open_basedir', '\\;NUL');
run();
ini_set('open_basedir', '\\');
run();
```
Resulted in this output:
```
8.5.11
open_basedir=''
resource(5) of type (stream)
NULL
resource(9) of type (process)
NULL
open_basedir='\\;NUL'
resource(10) of type (stream)
NULL
resource(14) of type (process)
NULL
open_basedir='\\'
bool(false)
string(58) "fopen(NUL): Failed to open stream: Operation not permitted"
bool(false)
string(62) "proc_open(NUL): Failed to open stream: Operation not permitted"
```
But I expected this output instead:
```
8.5.11
open_basedir=''
resource(5) of type (stream)
NULL
resource(9) of type (process)
NULL
open_basedir='\\;NUL'
resource(10) of type (stream)
NULL
resource(14) of type (process)
NULL
open_basedir='\\'
resource(15) of type (stream)
NULL
resource(19) of type (process)
NULL
```
Adding
'NUL' to the open_basedir makes it work again.
This happens in PHP 8.3.35, 8.4.26 and 8.5.11. In PHP 8.3.33, 8.4.25 and 8.5.10 the output is as
expected. I have not checked PHP 8.6.
This breaks symfony/process because [they pass the NUL device to processes
on Windows](https://github.com/symfony/process/blob/8.2/Pipes/WindowsPipes.php#L120).
### PHP Version
```plain
PHP 8.5.11 (cli) (built: Sep 22 2026 13:51:38) (NTS Visual C++ 2022 x64)
Copyright (c) The PHP Group
Built by The PHP Group
Zend Engine v4.5.11, Copyright (c) Zend Technologies
with Zend OPcache v8.5.11, Copyright (c), by Zend Technologies
PHP 8.4.26 (cli) (built: Sep 22 2026 15:11:32) (NTS Visual C++ 2022 x64)
Copyright (c) The PHP Group
Built by The PHP Group
Zend Engine v4.4.26, Copyright (c) Zend Technologies
PHP 8.3.35 (cli) (built: Sep 22 2026 11:14:27) (NTS Visual C++ 2019 x64)
Copyright (c) The PHP Group
Zend Engine v4.3.35, Copyright (c) Zend Technologies
```
### Operating System
Windows Server 2022