[php-src] PR #24176: use-after-free when an error handler removes a failing zlib.inflate filter
| From: | EdmondDantes | Date: | Wed, 07 Oct 2026 08:56:32 +0000 |
| Subject: | [php-src] PR #24176: use-after-free when an error handler removes a failing zlib.inflate filter | ||
| Groups: | php.git-pulls | ||
| Request: | Send a blank email to git-pulls+get-39234@lists.php.net to get a copy of this message | ||
Pull Request: https://github.com/php/php-src/pull/24176
Author: EdmondDantes
On a corrupt input
zlib.inflate raises E_NOTICE ("zlib: data
error") and then resets its input pointers. A user error handler that calls
stream_filter_remove() on that filter frees the filter's state first, so the reset
writes to freed memory (Valgrind: invalid writes in php_zlib_inflate_filter()). The fix
resets the state before raising the notice; nothing touches the filter after it.
Test: ext/zlib/tests/zlib_filter_inflate_error_handler_removes_filter.phpt, as a write
and as a read filter.
Not covered, same family: an error handler that closes the stream itself during any filter's
diagnostic (fclose() is only refused while a user filter runs), which would need
PHP_STREAM_FLAG_NO_FCLOSE around the whole filter chain walk.