Skip to content

fix: move error finalization after stream fields in stream_get_meta_data to prevent UAF - #23458

Open
shoemoney wants to merge 1 commit into
php:masterfrom
shoemoney:fix/stream-meta-uaf
Open

fix: move error finalization after stream fields in stream_get_meta_data to prevent UAF#23458
shoemoney wants to merge 1 commit into
php:masterfrom
shoemoney:fix/stream-meta-uaf

Conversation

@shoemoney

Copy link
Copy Markdown

Fixes heap-use-after-free in stream_get_meta_data.

php_stream_error_operation_end_for_stream invokes the error handler which may fclose the stream. In the previous order this ran before wrapperdata, wrapper type, stream type, mode and uri were copied into the return value, so those reads touched freed memory. Deferring finalization until after all stream fields are copied closes the UAF window.

The change is a one-line reorder within PHP_FUNCTION(stream_get_meta_data). It keeps begin, populate and eof handling unchanged and only moves the end call after the last stream field access. This matches the pattern needed for the sibling reports 23259 and 23264 which share the same root cause.

Written in conjunction with my pair programmer Claude.

…ata to prevent UAF

Fix verified RED->GREEN. stream_get_meta_data UAF at ext/standard/streamsfuncs.c:566 - php_stream_error_operation_end_for_stream calls error_handler which can fclose() stream, then reads wrapperdata/wops/label/mode/orig_path from freed memory => ASan heap-use-after-free
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant