[php-src] PR #24175: Fix use-after-free when pclose() closes a stream from its user filter
| From: | EdmondDantes | Date: | Wed, 07 Oct 2026 08:55:07 +0000 |
| Subject: | [php-src] PR #24175: Fix use-after-free when pclose() closes a stream from its user filter | ||
| Groups: | php.git-pulls | ||
| Request: | Send a blank email to git-pulls+get-39233@lists.php.net to get a copy of this message | ||
Pull Request: https://github.com/php/php-src/pull/24175
Author: EdmondDantes
While a user filter's
filter() runs, its stream carries
PHP_STREAM_FLAG_NO_FCLOSE, so fclose() from the callback fails with a
warning. pclose() did not check the flag: it freed the stream and the filter under the
running callback (use-after-free under Valgrind, no Fibers needed).
pclose() now refuses such a stream with the same warning as fclose() and
returns -1, its documented error value. One visible change: pclose() of an
opendir() handle, which also carries the flag, now fails the way fclose()
of it already does.
Test: ext/standard/tests/filters/pclose_in_filter.phpt.