Sec Bug->Doc #70952 [Nab]: GD massive memory consumption

From: Date: Sat, 28 Nov 2015 15:32:37 +0000
Subject: Sec Bug->Doc #70952 [Nab]: GD massive memory consumption
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-12888@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70952&edit=1 ID: 70952 Updated by: pajoye@php.net Reported by: s dot brunner at stephan-brunner dot net Summary: GD massive memory consumption Status: Not a bug -Type: Security +Type: Documentation Problem Package: GD related Operating System: Ubuntu 14.04.3 LTS PHP Version: 5.5.30 Block user comment: N Private report: Y New Comment: Moving to doc. If you use the bundled Gd library, the php memory management is used. For systen's GD, the system memory management is used (aka malloc VS emalloc) Previous Comments: ------------------------------------------------------------------------ [2015-11-26 15:56:30] johannes@php.net The memory_limit relates only to memory allocated by PHP itself, not extenal libraries. The purpose is to mitigate effects from accidents like recursion or unterminated loops. For stricter resource controls please use the operating system's facilities. ------------------------------------------------------------------------ [2015-11-21 20:42:36] s dot brunner at stephan-brunner dot net Description: ------------ Hello, GD-version: 5.5.9+dfsg-1ubuntu4.14 (official repo) We, Stephan Brunner and Tobias Sachs, discovered that the GD library bypasses any memory_limit setting, no matter whether it is forced as an php_admin_value in the fpm pool config or set in the php.ini. Letting gd import an image (131072 by 131072 pixels compressed to 5 MB), download: https://bug.boomer41.net/gd_memory/picture.png) will bypass any memory limit set. The memory limit is set to 32MB as a php_admin_value in the pool config of fpm as shown below: php_admin_value[memory_limit] = 32M The php.ini file of the fpm remains untouched, the memory_limit value of the cli is set to 128M. Exploitation of this bug renders the machine unusable because the machine starts to swap immediately and uses about 100% of the available cpu and memory resources as shown here: https://bug.boomer41.net/gd_memory/memory_usage.png Yours sincerely Stephan Brunner (GPG-Key: ACA501B0@pgp.mit.edu) Tobias Sachs (GPG-Key: EF14985E@pgp.mit.edu) Test script: --------------- <?php // Also available for download at https://bug.boomer41.net/gd_memory/test.php // Download link here: https://bug.boomer41.net/gd_memory/picture.png $picturepath = "picture.png"; imagecreatefromstring(file_get_contents($picturepath)); Expected result: ---------------- The GD library should respect the memory_limit. Actual result: -------------- The GD library uses all available resources and renders the machine unusable. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70952&edit=1

« previous php.doc.bugs (#12888) next »