[php-src] PR #24166: phar: Fix double-free in webPhar() without PATH_INFO
| From: | bukka | Date: | Tue, 06 Oct 2026 16:45:45 +0000 |
| Subject: | [php-src] PR #24166: phar: Fix double-free in webPhar() without PATH_INFO | ||
| Groups: | php.git-pulls | ||
| Request: | Send a blank email to git-pulls+get-39215@lists.php.net to get a copy of this message | ||
Pull Request: https://github.com/php/php-src/pull/24166
Author: bukka
In the CGI/FastCGI branch of webPhar(), when SCRIPT_NAME is present but PATH_INFO is absent,
path_info was aliased to the testit buffer and free_pathinfo was set. Since commit 3ee2f442d20 added
an unconditional efree(testit) after that branch, path_info became a dangling pointer. This causes a
use-after-free when path_info is read later and a double-free at the cleanup_skip_entry label where
free_pathinfo triggers efree(path_info).
This only affects PHP-8.6 as earlier branches do not free testit there.
Allocate a dedicated copy for path_info so its lifetime outlives the efree(testit).
Reported by RigelYoung.