[php-src] PR #24136: Fix stale read buffer length in stream filter flush
| From: | bukka | Date: | Mon, 05 Oct 2026 14:34:33 +0000 |
| Subject: | [php-src] PR #24136: Fix stale read buffer length in stream filter flush | ||
| Groups: | php.git-pulls | ||
| Request: | Send a blank email to git-pulls+get-39167@lists.php.net to get a copy of this message | ||
Pull Request: https://github.com/php/php-src/pull/24136
Author: bukka
When a read filter is flushed (e.g. via stream_filter_remove()) and the flushed data exceeds the
remaining read buffer capacity, _php_stream_filter_flush() reallocates stream->readbuf but leaves
stream->readbuflen at its old value. Once writepos exceeds the stale readbuflen, the next refill
in _php_stream_fill_read_buffer() computes readbuflen - writepos as a wrapped size_t and passes it
to the read op, causing EFAULT on plain files and out-of-bounds writes on memory streams.
Keep readbuflen in sync with the reallocation, as streams.c does.